Settlement fraud: why conveyancing is the top target
Of all the payments a business makes, a property settlement is the one criminals most want to redirect. It is large, it happens once, everyone involved is under time pressure, and once the money moves it is very rarely recovered.
This is written for conveyancers, property lawyers and their staff. It assumes you already know the transaction; the useful part is what the attack looks like from your side of it, and which controls survive contact with a real settlement week.
Why this transaction, specifically
- The amount is unusually large — often more than the business's entire monthly outgoings, in one transfer.
- It is a one-off, so there is no previous payment to compare the account against.
- The date is fixed and public, so the attacker knows exactly when to strike and that delay is expensive.
- Several organisations are involved, so an unfamiliar email address is not itself suspicious.
- Everyone expects banking details to arrive by email at short notice. The fraudulent message is doing the same thing the genuine one does.
Every other payment your firm makes has a history to check against. A settlement has none — which removes the single most reliable fraud check there is.
The shape it usually takes
The strongest version does not involve a fake domain at all. Someone gains access to a mailbox belonging to one of the parties — often the least protected participant, which is frequently the buyer or a small agency rather than the law firm — and reads the thread until settlement approaches.
Then a message arrives from the genuine address, in the genuine thread, with correct file references and correct amounts, revising the trust account details. Nothing about it fails a technical check, because nothing about it is technically forged.
The weaker version registers a domain a character or two from a real one and joins the thread from outside. Both end the same way.
The controls that hold under settlement pressure
Advice that assumes a calm week is useless here. These survive a Friday settlement.
- Exchange account details at the start of the matter, by phone, and record them then. Establishing the account when nobody is under pressure removes the moment the attacker is waiting for.
- Treat any change to those details as fraudulent until a phone call proves otherwise — on the number you recorded at the start, never one in the email requesting the change.
- Have a second person authorise any payment where the account differs from what was recorded. The person reading the email should not be the person releasing the funds.
- Warn clients in writing, early, that you will never email them changed account details. Then they have a rule to apply when a criminal emails them pretending to be you.
- Never accept a change on settlement day itself without a call. Attackers choose that day because they know a delay costs everyone money.
The client side, which you cannot control but can arm
Much of this fraud targets the buyer rather than the firm — they receive an email that appears to come from you, with your letterhead and your matter reference, giving different trust account details.
You cannot secure their mailbox. You can make sure they were told, in writing and early, exactly one thing: that your account details will never change by email, and that they must call a number from your website or their engagement letter before transferring anything.
A client who has been told that once will usually remember it at the moment it counts.
Call the supplier on a number you already had — from an earlier invoice, their website that you navigated to yourself, or your own records. Never a number written in the email or invoice you are checking. The person who wrote that document chose that number.
If it has already happened
Speed dominates every other factor. Call the bank's fraud line immediately and ask for a recall attempt — the first hours matter more than anything else you will do that day.
Then preserve the original email with full headers intact, report to ReportCyber at cyber.gov.au and to Scamwatch, and notify your professional indemnity insurer promptly, since late notification is a common reason claims fail.
Also tell the other parties. If the compromised mailbox belongs to someone else in the matter, their other transactions are exposed too.
Common questions
Doesn't PEXA or electronic settlement remove this risk?
It removes some of it, by moving the settlement itself onto a controlled platform. It does not remove the surrounding payments — deposits, adjustments, disbursements and client-to-firm transfers still travel by ordinary bank transfer on details communicated by email, and that is where the redirects happen.
Who bears the loss if a client sends funds to a fraudster impersonating us?
It depends on the facts and it is frequently disputed, which is exactly why written early warnings and records of verification calls matter. A firm that can show it warned the client in writing and verified details by phone is in a very different position from one that cannot. Take proper advice on your own circumstances.
Is this covered by our professional indemnity policy?
Do not assume so. Many policies exclude losses where someone was deceived into transferring funds voluntarily unless a specific social engineering or crime endorsement has been added. Ask your broker directly and get the answer in writing.
Related guides
- Is this invoice a scam? Seven checks before you pay
The seven things worth checking on an invoice that doesn't feel right, and the one check that actually settles it.
- A supplier emailed new bank details. What should you do?
The single most common way businesses lose large sums — and a short, repeatable process that stops it.
- You've paid a scammer. What to do in the first hour
If money has already gone, speed decides the outcome. The order of operations that gives you the best chance.