Conveyancing fraud is one of the most lucrative categories of cybercrime in the UK. The Solicitors Regulation Authority and UK Finance report hundreds of millions of pounds lost annually to property fraud — much of it enabled by compromised email accounts at the agencies and law firms involved in transactions.
Estate agents sit at the centre of property transactions: they hold buyer and seller contact details, coordinate with solicitors and mortgage brokers, communicate bank details for deposits and completion funds, and manage access to properties. This makes them attractive targets and, when compromised, a pivot point for attacking everyone else in the transaction chain.
Why Estate Agents Are Targeted
The conveyancing process involves large transfers of money to new bank accounts under time pressure. Buyers and sellers are often already anxious. An email that arrives at the right moment — purportedly from a solicitor saying “our bank details have changed” — can be convincing enough to redirect a deposit or completion payment if the recipient isn’t alert to the risk.
If an attacker compromises an estate agent’s email account, they gain:
- The contact details and transaction status of every active buyer and seller
- The ability to send emails from a trusted address at a critical moment
- Visibility into which transactions are about to complete, when to strike
Personal data at volume is also valuable. An active estate agency holds passport copies, proof of address, mortgage in principle documents, and financial information for every buyer undergoing anti-money laundering checks. This data is worth money on its own, and the ICO treats inappropriate handling of AML documentation seriously.
Property portal credentials — your Rightmove, Zoopla, and OnTheMarket logins — allow an attacker to alter property listings, redirect enquiries, or access lead data from your portals. Account takeover at these portals is more common than you’d think.
Mandate Fraud: The Biggest Immediate Risk
Mandate fraud — redirecting a payment by impersonating a trusted party — is the threat that should keep estate agency owners up at night.
The typical pattern: an attacker monitors a compromised email account or intercepts email in transit, waits for a transaction approaching completion, then sends an email to the buyer (from a spoofed or compromised address) claiming the solicitor’s bank details have changed. The buyer, under pressure to complete, transfers their funds to the fraudster’s account.
Your defences:
Train your staff and put the warning in every email footer. Every email your agency sends about a property transaction should carry a line saying something like: “We will never change our bank details by email. If you receive any communication asking you to change payment details, call us on [number] immediately to verify.” This is now standard practice at many agencies and solicitors.
Enforce a phone verification rule internally. No staff member should action a request to change bank details or payment instructions without confirming verbally with a known contact at the solicitor or conveyancer, using a phone number you already have on file — not a number provided in the email.
Implement DMARC on your domain. If your email domain doesn’t have a DMARC policy set to p=reject, attackers can send emails that appear to come from your domain without accessing your accounts. Your IT provider or email platform (Microsoft 365 or Google Workspace) can configure this for you.
Email Account Security
Email is your primary attack surface. Most estate agency compromise starts here.
Multi-factor authentication on all email accounts is the single most important technical control. This is non-negotiable. An attacker with your password but without access to your phone or authenticator app cannot access your account.
Review your Microsoft 365 or Google Workspace security settings. Both platforms have security dashboards that show you recent logins, third-party apps with access to your email, and suspicious activity. Check them. Look for any apps you don’t recognise that have access to email or calendar — these are common persistence mechanisms after an account has been compromised and recovered.
Manage shared inboxes carefully. The generic sales@, lettings@, and enquiries@ inboxes at many agencies have weak passwords, multiple people with access, and rarely have MFA enabled. These are prime targets. Treat them the same as individual accounts.
Client Data and AML Compliance
Estate agents are regulated under the Money Laundering Regulations 2017 and must carry out AML checks on buyers and sellers. This means holding passport copies, proof of address, and other personal documents — creating significant data protection obligations.
Under GDPR you must:
- Hold this data only as long as necessary (the Financial Conduct Authority guidance suggests five years after a transaction completes)
- Protect it with appropriate technical measures (encryption at rest, access controls, not sharing via unencrypted email)
- Report data breaches to the ICO within 72 hours if the breach is likely to result in risk to individuals
- Maintain records of your processing activities
Many agencies store AML documents in email attachments and unsecured shared drives. This is inadequate. Use a client portal or document management system that encrypts documents at rest and controls who can access which client’s data.
Your professional body — NAEA Propertymark or ARLA — will have guidance on AML compliance and data protection that goes beyond generic ICO guidance. It’s worth reading.
Portal Account Security
Rightmove, Zoopla, and OnTheMarket accounts deserve the same treatment as your email: strong unique passwords, MFA where available, and regular review of who has access.
Be particularly careful about the credentials shared with franchise branches, self-employed negotiators, or third-party suppliers. When someone leaves the business, remove their access immediately — including portal accounts.
Verify that your listing data and enquiry data is being handled appropriately by any third-party CRM or lead management tools connected to your portals. These integrations often have broad access and aren’t reviewed regularly.
Practical Starting Points
- Turn on MFA for all email accounts — start with Microsoft 365 or Google Workspace admin settings
- Add a bank details warning to every outgoing email template used in transactions
- Implement a verbal verification rule for any request to change payment details
- Check your domain for DMARC configuration — your IT provider can do this in 30 minutes
- Review who has access to your portal accounts and remove anyone who no longer needs it
- Set up a data retention schedule for AML documents so you’re not holding passport copies indefinitely
The NCSC’s Small Business Guide is a good starting point for baseline security hygiene. Propertymark publishes AML and data protection guidance specifically for estate agents, and the HMRC estate agent supervision team has resources on AML compliance requirements.
Client trust in property transactions is already fragile — buyers and sellers are handling the largest financial transaction of their lives. Protecting that trust means protecting the process from attack.