IronSights
All insights

threat intelligence

Settlement payment fraud: how conveyancers lose buyers' money

Settlement payment fraud is the dominant cyber threat facing Australian conveyancers. Attackers insert themselves into the email thread, change the bank details, and the buyer's funds disappear days before settlement. This article explains how the fraud works and the controls that stop it.

By IronSights Editorial, Practitioner team10 June 20264 min read
ByIronSights Editorial10 June 20264 min read

If you act on property settlements, the biggest cyber threat you face is not or a data breach. It is a single email that quietly changes a BSB and account number, sent to a buyer who is about to transfer hundreds of thousands of dollars. The buyer pays the criminal instead of you, the funds are gone within hours, and they are almost never recovered. The and the Australian Banking Association have both recognised this as a settled pattern, not a rare event.

How attackers get into the thread

Settlement fraud works because the criminal is reading the real conversation. They are not guessing. There are three common ways they get there.

  • A compromised conveyancer account. The attacker has the login for your email, often through a page or a password reused from another breach. They can read every matter you are running and reply as you.
  • A spoofed or lookalike domain. The attacker registers a domain that reads almost the same as yours, swapping a letter or adding a word, then sends mail that looks like it came from your firm.
  • A compromised client mailbox. The buyer's own email is the weak point. The attacker watches their inbox, learns the settlement is coming, and steps in at the right moment.

In each case the criminal sees the genuine details: the property address, the settlement date, the names of the parties, the amounts. That knowledge is what makes the fraud convincing.

The timing and the message

The fraudulent email usually lands three to seven days before settlement, which is exactly when the buyer expects to receive payment instructions. By then the buyer is primed to act and unlikely to question a message that quotes the correct property and the correct settlement date.

The message reads like every other email in the thread. It refers to the right matter. It often apologises for a late change or mentions a new trust account. The only thing that has changed is the BSB and account number. The buyer transfers the money, and it goes to the criminal's account.

The scale of the loss

A typical residential settlement in Australia runs between $500,000 and $1.5 million. That is the sum at risk in a single email. Once the buyer authorises the transfer, the funds move quickly through one or more mule accounts and are withdrawn or sent offshore. By the time anyone notices, the money is rarely recoverable. The buyer is out of pocket, the settlement collapses, and your firm is left dealing with the fallout and the question of who was responsible.

The technical controls and their limits

Two email controls matter here, and it helps to be honest about what each one does and does not do.

in enforcement mode, backed by and , stops criminals sending mail that claims to come from your exact domain. It is worth setting up properly and moving to a reject policy. But DMARC has limits. It does nothing against a lookalike domain, because that is a different domain the attacker controls and authenticates legitimately. It also does nothing when the attacker is logged into a genuine account, because that mail really did come from you.

on every email account is the control that closes the most common door. If a stolen password no longer grants access on its own, the attacker cannot sit inside your mailbox reading matters and replying as you. MFA should be on every account in the firm, with no exceptions for principals or long-serving staff.

The process control that matters most

Technology alone will not stop this fraud, because the lookalike domain and the compromised client mailbox both slip past it. The control that works every time is a process one. Verify any change of bank details by phone, on a number you have sourced independently, before any money moves. Do not call the number in the email. Use a number from your file or your own records.

Tell clients this at the start of the matter, in plain terms: our bank details will not change, and if you receive an email saying they have, treat it as fraud and call us on the number we gave you. A client who has been warned is far harder to deceive than one who is surprised by a last-minute change.

There is also a regulatory current worth noting. From 1 July 2026, AML/CTF Tranche 2 brings many legal and conveyancing services under AUSTRAC's reporting regime. Knowing your client and confirming where funds are coming from and going to will become part of the job, and tighter verification habits sit comfortably alongside that change.

Closing the gap

Settlement fraud sits at the meeting point of email security and everyday process. It rewards the firm that has locked down its accounts and that verifies bank details the same way every time. IronSights works with Australian legal practices and conveyancers to configure DMARC and MFA correctly, harden , and build the verification steps into how settlements are run. A short security review will show where your current process could be exploited and what to fix first.

Keep reading

More from the IronSights team.