Four conveyancing scams every firm should watch for   - triSearch

Four conveyancing scams every firm should watch for  

Conveyancing scams target the money and the identity data moving through a property settlement. The four most common are payment redirection, phishing and credential theft, business impersonation, and client or seller impersonation. Verbal verification, multi-factor authentication, and early identity checks stop most of them before any funds move. 

Property transactions bring together high-value payments, sensitive personal information, multiple parties, and time-sensitive communication. For scammers, that creates multiple opportunities to impersonate someone involved in a matter, compromise an account, or redirect funds. 

The scale of the problem is significant. In 2025, the National Anti-Scam Centre’s Targeting Scams Report recorded $166.8 million in payment redirection losses, making it the second-highest scam category by loss.  

Scams Awareness Week runs from 24 to 28 August 2026, and this year’s theme, “No one’s just a number,” is a reminder that behind every scam report is a real person whose money, time, or trust has been taken. It’s a timely prompt for conveyancers and property lawyers to review where scams can enter a matter and whether the right controls are in place. 

Why do scammers target conveyancers?

There are four reasons they draw so much attention:

  • High-value transactions: Conveyancers handle large sums of client money through every settlements. 
  • Predictable deadlines: Property settlements follow strict, time-sensitive dates, creating a high-pressure environment where hurried clients are more likely to miss red flags. 
  • Valuable personal data: Your files hold passports, driver’s licenceslicenses, and tax documents – everything a criminals needs for lucrative identity theft. 
  • Multiple network links: Conveyancers are in constant contact with buyers, sellers, banks, and real estate agents, giving criminals many different entry points to exploit. 

 

Four conveyancing scam tactics to watch for

Scammers use both technical and psychological tactics to target conveyancers and property law practices.

1. Payment redirection

Criminals infiltrate an email thread or impersonate an involved party to swap legitimate bank details with their own. They wait until just before settlement day to send “updated” bank details. This tricks buyers or legal teams into sending settlement funds directly to the fraudster’s account. 

2. Phishing and credential theft  

Fraudsters use deceptive emails, malicious links, or fake login portals to trick staff into revealing passwords. These emails often mimic urgent bank alerts or electronic settlement platforms. Once stolen, these credentials give criminals access to internal email systems and highly sensitive transaction files. 

3. Business impersonation  

Scammers use lookalike web domains and create email addresses that perfectly mimic a legitimate legal practice. Because fake emails look entirely authentic, clients follow fraudulent payment instructions in good faith. 

4. Client or seller impersonation 

Criminals compromise a vendor’s or buyer’s personal account to message the conveyancer directly. Posing as the true client, they issue sudden, high-pressure requests to change settlement instructions or redirect sale proceeds. Without independent phone verification, your firm risks sending the settlement proceeds straight to a criminal.

Measures you can take to prevent cybercriminals

Conveyancing firms can shutdown most of these attempts by implementing a few practical, everyday operational rules : 

  • Verbal verification: Always call the client on a number you already hold on file — never one supplied in the email — to confirm bank details before any funds move.
  • No bank details via regular email: Don’t send or accept trust account details through open, standard email communication.  
  • Early identity checks: Complete the official Verification of Identity (VOI) standard as soon as a new client signs on, rather than waiting until right before settlement.
  • Strict “change of details” protocol: Treat any sudden email request from a client or vendor to change bank account information as highly suspicious until verified over the phone or in person. 
  • Enforce multi-factor authentication (MFA): Turn on MFA across all staff email accounts, software tools, and property platforms to block unauthorised login attempts.  
  • Deploy email authentication tools: Implement security protocols through your IT provider to prevent scammers from spoofing your exact firm domain name.  
  • Continuous staff training: Run regular, practical training sessions to educate your employees on how to spot lookalike email domains and sophisticated phishing links.
  • Use secure conveyancing software: Keep matters, documents, communications, and invoicing inside one secure system rather than spread across email and local drives.  

What should you do if you suspect a scam?

Speed matters more than certainty. If a payment or an instruction looks wrong, act on the suspicion before you confirm it. 

  • Call your bank’s fraud team immediately and ask them to attempt a recall. The window for recovering a redirected payment is often hours, not days. 
  • Report it to ReportCyber at cyber.gov.au and to Scamwatch, so the incident is on record with both agencies. 
  • Contact IDCARE if client identity documents may have been exposed. They provide specialist support for identity compromise at no cost to the individual. 
  • Tell everyone in the transaction chain, including the client, the practitioner on the other side, and the incoming or outgoing lender, so no further payments are made on the compromised instructions. 
  • Preserve the evidence. Keep the original emails with their headers intact and note times and account details before anything is deleted. 

How triSearch helps protect your client data

A secure and reliable practice management system is an important foundation for protecting sensitive client information and reducing cyber risk across your firm.  

triSearch uses encryption, access controls, ongoing monitoring, and regular backups, with triConvey data stored in Sydney on AWS infrastructure. These controls help protect information while it is being transmitted and stored, reduce the risk of unauthorised access or interception, and provide greater protection against data loss. Verification of Identity data is also encrypted in transit and at rest and stored in an ISO 27001-certified private cloud environment.  

See how triSearch keeps your firm’s data secure here. 

Subscribe free to
The Australian Conveyancer

Monthly magazine and weekly newsletter, direct to your inbox, with the latest conveyancing insights.