Industries · Legal · Conveyancers
Cyber security for Australian conveyancers.
Settlement payment fraud is the biggest cyber threat conveyancers face. Attackers watch the email thread and swap in their own bank details days before settlement. A typical residential transaction is $500,000 to $1.5 million, and the money rarely comes back.
IronSights helps you stop it, and gets your practice ready for AML/CTF Tranche 2 from 1 July 2026. ISO 27001 certified, Sydney-based.
Threat context
Why conveyancers are targeted.
Conveyancers handle the largest single payments most Australians ever make, on a tight timeline, over email. Attackers have worked out how to exploit that. The fraud is not sophisticated and needs no advanced skill, just access to a conveyancing email thread and patience.
The pattern is the same every time. An attacker gets into the correspondence around a property deal, through a compromised conveyancer account, a spoofed domain or a compromised client inbox. They wait three to seven days before settlement, when the buyer is expecting payment instructions, then send new BSB and account numbers. The email looks like it came from a familiar sender and quotes the right property and settlement details.
AUSTRAC and the Australian Cyber Security Centre both flag conveyancing as a sector with high business email compromise exposure, and the Australian Banking Association has published guidance on it. The controls that stop it are well known: DMARC in enforcement mode, MFA on every email account, and a phone-call check on any change of bank details before you transfer.
From 1 July 2026, AML/CTF Tranche 2 brings conveyancers providing designated services into AUSTRAC's regime as reporting entities. You will need an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. Building all of that takes longer than most practices expect, so the time to start is now.
Common risks
What we see when we work with conveyancers.
Settlement payment fraud via email interception
The most damaging attack in Australian conveyancing. An attacker in the email thread sends the client new BSB and account numbers in the days before settlement. Clients expecting instructions at that point often pay without calling to check. A typical residential transaction is $500,000 to $1.5 million.
Domain spoofing
Attackers register lookalike domains. conveyancers.com.au and conveyancers-au.com.au are hard to tell apart in a header when a client is mid-transaction. DMARC protects your own domain but not these, so client and staff awareness is what closes the gap.
Conveyancing software credential theft
Conveyancing platforms are hit with phishing and reused passwords from earlier breaches. One stolen login exposes matter records, settlement dates and correspondence, which is exactly what makes a fake payment instruction look credible. Turn on MFA wherever the platform offers it.
AML/CTF compliance gaps ahead of Tranche 2
From 1 July 2026, conveyancing becomes a designated service under the AML/CTF Act. Without documented customer due diligence, transaction monitoring and an AML/CTF program, you are non-compliant from that date. Building one takes longer than most practices plan for, so start early.
Inadequate client communication protocols
Most conveyancing fraud works because no one phones to confirm payment details first. If you send instructions by email without a rule that bank details are verified by phone on an independent number, the gap stays open no matter how good your technical controls are.
How we help
Services for conveyancing practices.
The controls that stop settlement payment fraud are well understood, and so is the path to AML/CTF Tranche 2 readiness. We help you put both in place.
Microsoft 365 security
Your email is configured to shut down the attacks that hit conveyancers: DMARC, DKIM and SPF in enforcement mode, on every account, and to block sign-in from unknown locations and devices. Clients stop receiving spoofed instructions from your domain.
Penetration testing and phishing simulation
You find out how your staff respond to the DocuSign, court notice and payment lures used against conveyancers, before a real one lands. We test your external-facing services for known weaknesses and include a free retest within 30 days.
Audit and assurance
You get a clear read on where your practice stands: an maturity rating and a against AML/CTF Tranche 2. You walk away with a prioritised roadmap for what to fix before 1 July 2026, not a checklist.
Incident response
If a settlement payment fraud event hits, you reach us any hour of the day. We handle containment, forensic investigation, assessment and PI insurer notification, and we work to the settlement clock you are running against.
Compliance
Regulatory obligations for conveyancers.
Tranche 2 from 1 July 2026
From 1 July 2026, the AML/CTF Amendment Act 2024 brings conveyancing in. If you provide designated services you become a reporting entity and need an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping in place from day one. Miss it and you are non-compliant with AUSTRAC. Privacy Act duties apply to the information you collect for it regardless of turnover.
APP obligations and the NDB scheme
Above $3 million turnover you must comply with the 13 Australian Privacy Principles. From 1 July 2026 the AML/CTF reforms add Privacy Act duties for the information you collect for them regardless of turnover. A breach of settlement correspondence, identity documents or financial records will almost always cross the NDB serious harm threshold and require notification to the OAIC.
State-based licensing and conduct obligations
You hold a state-based licence with conduct obligations attached, set in NSW by the Conveyancers Licensing Act 2003. PI insurance is required in every state. A payment fraud event that costs a client money puts your licence, your PI cover and your conduct standing at risk all at once.
Common questions
Asked by conveyancers like you.
Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.
What is settlement payment fraud and how does it specifically target conveyancers?
Attackers get into a conveyancing email thread, then send the client new bank details from what looks like your address in the days before settlement. They reference the right property and settlement date, so it reads as genuine. A typical residential settlement is $500,000 to $1.5 million, and the money rarely comes back. Verifying any change of bank details by phone, on a number from an earlier trusted source, is what stops it.
Will conveyancers be covered by the AML/CTF reforms from 1 July 2026?
Yes. Conveyancing is a designated service under the AML/CTF Amendment Act 2024. From 1 July 2026 you become a reporting entity under AUSTRAC, which means an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. The Privacy Act also applies to the personal information you collect for it, whatever your turnover. If you are not covered today, review your position before that date.
Does DMARC actually stop settlement payment fraud?
It stops one part of it. DMARC in enforcement mode blocks email that spoofs your exact domain, so a client never receives a fake instruction sent from your address. It does not stop an attacker sending from an account they have genuinely compromised, or from a lookalike domain like conveyancer-au.com. You need DMARC, MFA on every email account, and a phone-call check on every change of bank details before payment.
Are conveyancers covered by the Privacy Act?
If your turnover is above $3 million, yes, and you must follow the 13 Australian Privacy Principles. Below that, most standard conveyancing falls outside the Act unless you hold a Commonwealth contract or handle services tied to a Commonwealth program. From 1 July 2026, the AML/CTF reforms apply Privacy Act duties to the information you collect for AML/CTF purposes regardless of turnover.
What should a conveyancer's payment verification process look like?
Verify any change of bank details by phone before you pay, using a number from an earlier trusted source or a public listing, never the number in the email. Document the call. Tell clients at the outset that your bank details will never change and to ring you straight away if they receive new instructions. This is the control that catches the fraud DMARC and MFA cannot.
Further reading
Related insights.
Settlement fraud in Australian conveyancing
How attackers intercept conveyancing email threads and substitute payment details, and the controls that stop it.
Read more →ComplianceCyber security obligations for Australian legal practices
Privacy Act, Legal Profession Uniform Law and AML/CTF Tranche 2 reforms. What each framework requires and who it applies to.
Read more →TechnicalThe Essential Eight for Australian legal practices
No mandatory cyber framework applies to conveyancers, but the Essential Eight is the relevant benchmark for PI insurers and professional conduct purposes.
Read more →ComplianceAML/CTF Tranche 2: what conveyancers need to do before 1 July 2026
The designated services that bring conveyancers into AUSTRAC's regime, and what a compliant AML/CTF program looks like.
Read more →Also in legal
IronSights works across the legal sector.
Start with a review
A structured security review tells you exactly where your practice stands.
We check your email security, identity controls, payment verification process and AML/CTF Tranche 2 readiness. You get a prioritised roadmap you can act on before 1 July 2026.
ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.