TL;DR:
- Letting agents are high-value targets for mandate fraud because they handle predictable, recurring, high-value payment flows — rent collection, deposit returns, and contractor invoices — all coordinated primarily over email
- Email account takeover is the enabling step for most attacks on the sector: once an attacker has access to a letting agent’s inbox, they can intercept landlord and tenant correspondence and redirect payments
- Multi-factor authentication on all email accounts, a phone-based verification policy for any bank detail changes, and dual authorisation on client money transfers are the three controls that prevent the majority of financial losses
UK letting agents sit at an unusual intersection of risk. They manage client money (funds belonging to landlords, held in trust), handle extensive personal data (tenant identity documents, credit reports, employment references, bank details), and coordinate significant payment flows over email. The email-centric nature of the business — instruction requests, tenancy renewals, maintenance authorisations, rent statements — creates multiple points where an attacker who gains email access can cause financial harm.
The sector has its own regulatory framework that intersects with cybersecurity. Client Money Protection (CMP) schemes, mandatory since 2019, require membership with approved providers like Client Money Protect, Propertymark, or RICS. Some CMP schemes now have cyber incident reporting requirements, and a cyber-enabled theft of client funds is both a business crisis and a regulatory reporting event.
The Specific Threats
Mandate fraud is the primary financial risk. This is where an attacker impersonates a landlord, tenant, or contractor by email and requests a bank account change. The email looks like it comes from a known contact; the story is plausible (new bank account following a switch, CHAPS instead of Bacs this month). The funds that arrive in the compromised account are transferred out within hours.
What makes letting agents particularly exposed is the volume of legitimate bank detail changes they process. Landlords do switch banks. New contractors are paid at new bank numbers. The business justification for a bank detail change is almost always plausible, which is why the verify-by-phone rule needs to be a firm, no-exceptions policy. The phone call must be to a number already on record — not one provided in the email.
Email account takeover is the enabling attack. Attackers gain access to a letting agent’s email account either through phishing (a convincing “Microsoft 365 sign-in” page), through credential stuffing (testing username/password combinations from previous data breaches), or through MFA fatigue attacks (flooding the account holder with approval requests until they accidentally approve one).
Once inside the inbox, attackers have access to ongoing correspondence with landlords and tenants, can monitor when rent payments or deposit returns are due, and can intercept and modify email threads to insert fraudulent bank details. The attacker doesn’t need to be fast — they can read mail silently for weeks before acting, timing their intervention to a moment when a large payment is expected.
Ransomware on property management software is a growing risk. Letting agencies hold years of tenancy records, landlord details, inspection reports, compliance documents, and financial history. Property management software databases — whether hosted locally or in the cloud — represent high-value ransomware targets. Recovery without backups can mean complete loss of tenancy history, outstanding maintenance records, and deposit accounting.
Tenant and landlord data theft for fraud. Identity documents (passports, driving licences) collected for Right to Rent checks, bank statements, employment letters, and references represent a comprehensive identity package for any individual tenant. Data held in breach of UK GDPR — retained longer than necessary, inadequately secured — creates ICO enforcement risk in addition to the risk of that data being stolen and used for identity fraud.
Controls That Matter
Multi-factor authentication. Every email account in the business, without exception. This is the single most impactful control for preventing account takeover. Microsoft 365 and Google Workspace both provide MFA at no additional cost; the implementation takes an afternoon. Use authenticator app-based MFA rather than SMS where possible — SIM-swapping attacks can defeat SMS MFA.
Bank detail change policy. Implement a written policy that no bank detail change will be processed without a phone verification call to the contact at a number already in your system (not from the email requesting the change). This should apply to landlord bank details, contractor payment details, and any supplier account changes. Train every member of staff. Make it a condition that applies to all instructions, regardless of how credible the email appears.
Dual authorisation for client money transfers. Any transfer from client accounts above a threshold (many firms use £1,000 or their average monthly payment) should require two people to approve. This is a standard control in most CMP scheme guidelines and provides a second check before funds leave.
Separate client and business accounts. Client money must be held separately from business funds under CMP requirements. The separation also limits the blast radius of account compromise — if business email is compromised, the client accounts require separate authorisation paths.
DMARC authentication. Configure DMARC, DKIM, and SPF for your email domain. This prevents attackers from sending emails that appear to come from your domain to your landlords and tenants — a common attack where the attacker emails a landlord appearing to be from the agent to redirect rent payments. The setup is a one-time technical configuration.
Backups for property management software. Test that backups of your property management database (Jupix, Alto, Reapit, Goodlord, or whatever system you use) are working, recent, and can actually be restored. Ransomware recovery without a working backup is extremely costly in both money and time. Backups should be stored separately from the primary system — cloud backups that ransomware can also encrypt are not effective protection.
Right to Rent data retention. UK GDPR requires that personal data is not retained longer than necessary. Right to Rent documents — passport copies, biometric residence permits — should be deleted after the statutory retention period (end of tenancy plus one year, or as updated by guidance). Holding years of ID documents that are no longer needed creates unnecessary regulatory exposure and expands the data at risk in a breach.
Regulatory Obligations
Beyond the CMP requirements, letting agents processing personal data are required to register with the ICO under UK GDPR if they have more than a certain number of employees or process data in certain ways. The ICO data protection fee is tiered — most small letting agents will pay the Tier 1 fee (£52 per year). More significant is the practical obligation to have appropriate security for the personal data you hold and to report eligible data breaches to the ICO within 72 hours.
ARLA Propertymark membership (and some other trade body memberships) carries requirements that map onto cybersecurity practice — client money handling rules, data protection obligations, and increasingly, cyber incident response expectations.
The NCSC has specific guidance for small businesses that applies directly to letting agents: the Cyber Essentials scheme, if certified, provides baseline protection against the most common attack vectors and satisfies some insurance underwriting requirements. Cyber Essentials certification has become a factor in professional indemnity and cyber insurance quotes for property businesses.
For firms handling significant client money volumes — particularly those managing hundreds of properties with corresponding rent flows — the investment in basic cyber protection is small relative to the potential exposure. Most of what protects letting agents is not expensive technology; it’s policy, training, and the discipline to verify before paying.