The Fisher Fraud report – the 5 points to note

Key points to note from Jonathan Fisher KC’s report on 'Fraud in the Digital Age' published on 14 July 2026.

27 July 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

Finally published in July 2026, 7 months after its completion, Jonathan Fisher KC’s report on Fraud in the Digital Age presents a wide-ranging assessment of an offence which he notes “may soon constitute half of all crime, with an estimated 4.1 million offences in the year to June 2025”.

The fraud crisis

The overall tenor of the report is one of frustration that an offence which is so prevalent and damaging has been afforded so little priority for so long. Previous reviews of fraud in the UK have focussed on the difficulties of prosecuting the most complex and cleverly executed frauds, but the problem, Fisher suggests, is now different. It is the sheer quantity of fraud which now needs addressing, much of it not terribly complex or sophisticated, but cumulatively of huge impact to individuals and businesses. One in four businesses is a victim of fraud each year and there is a conspicuous lack of success in convicting those responsible. As the report puts it, “emerging technologies, artificial intelligence (AI), deepfakes and crypto-assets are accelerating the fraud epidemic, equipping criminals to deceive at scale and to launder proceeds with unprecedented ease, frequently from overseas”.

One of the drivers for the commissioning of the report was the concern, noted in the 2023 Government Fraud Strategy, that the quantity of digital material involved in complex fraud cases was beyond the capabilities of enforcement agencies to deal with and did not sit comfortably within the existing criminal disclosure rules. The report makes various suggestions to address this, but these are primarily directed at law enforcement agencies and courts. For businesses, the interest lies elsewhere in the report.

The key recommendations

Legislation to create new criminal offences is often the politician’s first response to social ills, but the Fisher report suggests that the Fraud Act 2006 is broadly fit for purpose. It is wide-ranging and flexible in scope and adequately covers the vast majority of new forms of fraud. Most fraud trials will still come down to the question of whether someone was dishonest with the intention of making a gain or causing a victim a loss, whatever form the fraudulent conduct took. There are suggestions for some new offences here, including a specific offence of identity-based impersonation, but only one of the most significant recommendations is for a new criminal offence.

1. Information-sharing

The report suggests a statutory framework is needed for public-private information sharing to detect and combat fraud. Citing the Joint Money Laundering Intelligence Taskforce as an example of operational partnership between the public and private sectors, the emphasis would be on confronting fraud threats from first visibility, rather than responding to reports of fraud having occurred.

The Home Office, working with the National Crime Agency (NCA) and the Information Commissioner’s Office (ICO), should provide guidance on voluntary and compelled data-sharing for public and private sector organisations, covering information sharing between private sector organisations and setting out the legal basis and safeguards. The government should clarify the scope of the tipping-off and prejudicing-of-investigation provisions in sections 333 and 342 of the Proceeds of Crime Act 2002, with NCA assurance that lawful sharing within the guidance will not engage those provisions.

This recommendation, based on existing structures in the money-laundering and sanctions spheres, is perhaps one of the most likely to be adopted. There are advantages for both the government and business in sharing information on customer risk profiles and identifying fraud risks at an early stage. A statutory framework with clear gateways and safe harbours would assist in this.

2. Extending the failure to prevent fraud offence

The major recommendation for new legislation comes in the form of a new corporate criminal offence for providers of regulated user-to-user services, as defined in the Online Safety Act 2023 (OSA), who fail to prevent fraud on their platforms. The report notes that “Online platforms host significant scam content, yet bear limited legal liability, while banks shoulder the cost of reimbursing victims”.

This is presented as an extension of the failure to prevent fraud offence for large organisations introduced under the Economic Crime and Corporate Transparency Act 2023 (ECCTA) but, in reality, would share only the name. The existing offence is committed by an organisation which fails to prevent fraud by an associated person (commonly an employee or agent) for the benefit of the organisation. The proposed new offence would seem to lack the requirement that the offence be committed for the organisation’s benefit and would not require the acts of an associated person.

The purpose of the ECCTA offence was to drive heightened compliance measures to prevent fraud. The government may feel that this aim has already been addressed by the significant duties under OSA to assess and mitigate the risks of fraud, including fraudulent user content (in force now) and paid-for fraudulent advertising (coming into force next year). Very significant penalties may be imposed by Ofcom for breaches of these measures and, if those are enforced, that should be incentive enough to drive fraud prevention within the online services sector.

3. An anti-fraud levy

As a means to fund enforcement activity and promote improvements in fraud prevention, an anti-fraud levy is recommended on digital and communications infrastructure providers, including social media platforms, online service providers, and other intermediaries that may host or facilitate fraudulent activity. This would be administered by Ofcom, with a sunset clause allowing reduction or removal if measurable improvements in fraud prevention are demonstrated.

Politically, this may be difficult for the government to deliver. The most important providers who would be liable for this levy are based in the US and have significant support from their own government in resisting restraints on their business model imposed by foreign states. There is also likely to be overlap with the providers who are subject to a requirement to pay Ofcom’s operating costs for the online safety regime, already the subject of challenge before the courts.

4. Sanctions and visa bans for foreign fraud actors

The report proposes that foreign nationals orchestrating transnational fraud should be designated under sanctions, and made subject to asset freezes, travel bans and other penalties. UK visas should also be denied to foreign nationals linked to fraud against UK victims.

This would create a new basis for international restrictions, based on existing models such as those developed by the Financial Action Task Force to combat money-laundering and terrorist financing. Reflecting an acknowledgement that enforcing anti-fraud laws is made more difficult by the international, internet-enabled forms it now takes, and the lack of co-operation from some states that benefit from their nationals’ fraudulent activity, this proposal offers a way of disrupting overseas fraudsters’ activities. For financial institutions with cross-border operations, this would add another layer of designations to their sanctions screening frameworks.

5. Incentivising whistleblowing

The Serious Fraud Office (SFO) has long argued that legislative provision should be made for it to financially reward whistleblowers and the idea receives strong backing from Jonathan Fisher KC, not just in relation to fraud but for all economic crime. He argues that UK agencies face “a drain of information” as whistleblowers choose to report to US authorities offering incentives, with 744 UK nationals giving tips to US programmes between 2012 and 2023.

To address concerns of false or malicious reporting being incentivised, the report suggests the creation of a new criminal offence of knowingly making a false report to enforcement agencies under the incentivisation scheme. The report proposes that levels of reward be set by the SFO, with a government consultation to inform the design of a suitable scheme. Finally, it recommends that an independent arbitration panel be established to review appeals or complaints from whistleblowers.

Many organisations have invested in their own internal speak-up programmes in light of government guidance in relation to “failure to prevent” offences such as those under section 7 of the Bribery Act 2010 or section 199 of ECCTA. An external incentives scheme obviously increases the likelihood of reports being made externally rather than internally, but if this recommendation is adopted, organisations will want to review their internal programmes to maximise effectiveness.

What this means for you

The delay in publication of this report has provoked theories as to why it was not published in December 2025. It may be that much of what is presented here will fall into the “too difficult” government tray, particularly those requiring a multi-departmental and multi-agency approach. However, the report reflects the growing sense that the proliferation of fraud cannot continue unchecked and that far more needs to be done.

We expect some of these recommendations to gain traction and the results could require changes of approach in compliance and monitoring within a broad range of businesses, as well as potentially new interactions with law enforcement agencies.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.