IronSights

Industries · Legal · Conveyancers

Cyber security for Australian conveyancers.

Settlement payment fraud is the biggest cyber threat conveyancers face. Attackers watch the email thread and swap in their own bank details days before settlement. A typical residential transaction is $500,000 to $1.5 million, and the money rarely comes back.

IronSights helps you stop it, and gets your practice ready for AML/CTF Tranche 2 from 1 July 2026. ISO 27001 certified, Sydney-based.

Threat context

Why conveyancers are targeted.

Conveyancers handle the largest single payments most Australians ever make, on a tight timeline, over email. Attackers have worked out how to exploit that. The fraud is not sophisticated and needs no advanced skill, just access to a conveyancing email thread and patience.

The pattern is the same every time. An attacker gets into the correspondence around a property deal, through a compromised conveyancer account, a spoofed domain or a compromised client inbox. They wait three to seven days before settlement, when the buyer is expecting payment instructions, then send new BSB and account numbers. The email looks like it came from a familiar sender and quotes the right property and settlement details.

AUSTRAC and the Australian Cyber Security Centre both flag conveyancing as a sector with high business email compromise exposure, and the Australian Banking Association has published guidance on it. The controls that stop it are well known: DMARC in enforcement mode, MFA on every email account, and a phone-call check on any change of bank details before you transfer.

From 1 July 2026, AML/CTF Tranche 2 brings conveyancers providing designated services into AUSTRAC's regime as reporting entities. You will need an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. Building all of that takes longer than most practices expect, so the time to start is now.

Common risks

What we see when we work with conveyancers.

Settlement payment fraud via email interception

The most damaging attack in Australian conveyancing. An attacker in the email thread sends the client new BSB and account numbers in the days before settlement. Clients expecting instructions at that point often pay without calling to check. A typical residential transaction is $500,000 to $1.5 million.

Domain spoofing

Attackers register lookalike domains. conveyancers.com.au and conveyancers-au.com.au are hard to tell apart in a header when a client is mid-transaction. DMARC protects your own domain but not these, so client and staff awareness is what closes the gap.

Conveyancing software credential theft

Conveyancing platforms are hit with phishing and reused passwords from earlier breaches. One stolen login exposes matter records, settlement dates and correspondence, which is exactly what makes a fake payment instruction look credible. Turn on MFA wherever the platform offers it.

AML/CTF compliance gaps ahead of Tranche 2

From 1 July 2026, conveyancing becomes a designated service under the AML/CTF Act. Without documented customer due diligence, transaction monitoring and an AML/CTF program, you are non-compliant from that date. Building one takes longer than most practices plan for, so start early.

Inadequate client communication protocols

Most conveyancing fraud works because no one phones to confirm payment details first. If you send instructions by email without a rule that bank details are verified by phone on an independent number, the gap stays open no matter how good your technical controls are.

Compliance

Regulatory obligations for conveyancers.

AML/CTF

Tranche 2 from 1 July 2026

From 1 July 2026, the AML/CTF Amendment Act 2024 brings conveyancing in. If you provide designated services you become a reporting entity and need an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping in place from day one. Miss it and you are non-compliant with AUSTRAC. Privacy Act duties apply to the information you collect for it regardless of turnover.

Privacy Act

APP obligations and the NDB scheme

Above $3 million turnover you must comply with the 13 Australian Privacy Principles. From 1 July 2026 the AML/CTF reforms add Privacy Act duties for the information you collect for them regardless of turnover. A breach of settlement correspondence, identity documents or financial records will almost always cross the NDB serious harm threshold and require notification to the OAIC.

Professional Standards

State-based licensing and conduct obligations

You hold a state-based licence with conduct obligations attached, set in NSW by the Conveyancers Licensing Act 2003. PI insurance is required in every state. A payment fraud event that costs a client money puts your licence, your PI cover and your conduct standing at risk all at once.

Common questions

Asked by conveyancers like you.

Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.

  1. What is settlement payment fraud and how does it specifically target conveyancers?

    Attackers get into a conveyancing email thread, then send the client new bank details from what looks like your address in the days before settlement. They reference the right property and settlement date, so it reads as genuine. A typical residential settlement is $500,000 to $1.5 million, and the money rarely comes back. Verifying any change of bank details by phone, on a number from an earlier trusted source, is what stops it.

  2. Will conveyancers be covered by the AML/CTF reforms from 1 July 2026?

    Yes. Conveyancing is a designated service under the AML/CTF Amendment Act 2024. From 1 July 2026 you become a reporting entity under AUSTRAC, which means an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. The Privacy Act also applies to the personal information you collect for it, whatever your turnover. If you are not covered today, review your position before that date.

  3. Does DMARC actually stop settlement payment fraud?

    It stops one part of it. DMARC in enforcement mode blocks email that spoofs your exact domain, so a client never receives a fake instruction sent from your address. It does not stop an attacker sending from an account they have genuinely compromised, or from a lookalike domain like conveyancer-au.com. You need DMARC, MFA on every email account, and a phone-call check on every change of bank details before payment.

  4. Are conveyancers covered by the Privacy Act?

    If your turnover is above $3 million, yes, and you must follow the 13 Australian Privacy Principles. Below that, most standard conveyancing falls outside the Act unless you hold a Commonwealth contract or handle services tied to a Commonwealth program. From 1 July 2026, the AML/CTF reforms apply Privacy Act duties to the information you collect for AML/CTF purposes regardless of turnover.

  5. What should a conveyancer's payment verification process look like?

    Verify any change of bank details by phone before you pay, using a number from an earlier trusted source or a public listing, never the number in the email. Document the call. Tell clients at the outset that your bank details will never change and to ring you straight away if they receive new instructions. This is the control that catches the fraud DMARC and MFA cannot.

Start with a review

A structured security review tells you exactly where your practice stands.

We check your email security, identity controls, payment verification process and AML/CTF Tranche 2 readiness. You get a prioritised roadmap you can act on before 1 July 2026.

ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.