●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

The email that quietly redirects your client's settlement money

A client is days away from settling on a property. They’ve been waiting for the email with the account details to send their funds, and here it is, from your firm, with everything looking exactly as it should. They transfer the money. And it’s gone, within minutes, into an account that has nothing to do with you.

The email wasn’t from your firm. Or it was, but it had been quietly tampered with. Either way, your client has just wired their life savings to a criminal, and a law firm is sitting in the middle of it. This is payment redirection fraud, and for a practice that handles settlements, it’s one of the most dangerous scams there is.

How it actually works

The scam goes by a dull name, business email compromise, but the mechanics are vicious. An attacker quietly gets into an email account somewhere in the chain, yours, the client’s, the agent’s, or simply spoofs one so the messages look right. Then they don’t do anything. They watch. They read the conversation, learn the deal, the names, the timing, the tone. And at the exact moment funds are due to move, they send a message with new bank details, or edit the real one.

The victim has no reason to be suspicious. The email arrives when they’re expecting it, from someone they trust, about a transaction they know is real. That’s what makes it so effective. It isn’t a clumsy “Nigerian prince” email. It’s a perfectly timed message that fits seamlessly into a conversation already underway.

Why property settlements are the perfect target

Settlements tick every box a fraudster wants. A large sum of money. A known date it has to move. Several parties (buyer, agent, conveyancer, lawyer, bank) all emailing each other. And everyone expecting account details to land at some point, so a set of details arriving raises no alarm.

The numbers bear it out. The ACCC’s Scamwatch has reported payment redirection scams costing Australian businesses well over $200 million in a single year, and says it receives, on average, two reports a week tied specifically to real estate transactions. One Australian homebuyer came within a whisker of losing $1.2 million this way. For criminals, conveyancing is a target-rich corner of the economy.

Why it lands hardest on law firms

You’re the trusted party. If a fraudulent email appears to come from your firm, the client doesn’t question it, because they trust you. That trust is exactly what’s being weaponised. And when a client loses their deposit or their settlement funds through a matter your firm was handling, the fallout (for the client, and for your firm’s reputation and possibly its exposure) is severe. This isn’t legal advice on where liability lands. The point is simpler: you do not want to be anywhere near this, and a few habits keep you clear of it.

How to shut it down

The technology behind the scam is sophisticated. The defence is almost embarrassingly simple, and it works:

  • Never act on changed bank details from an email alone. Any new or amended account details get verified by phone, on a number you already hold for that person, not a number written in the email. One call to a known number defeats the entire scam.
  • Set the expectation with clients upfront, in writing. Tell them at the start of the matter that your account details will never change by email, and that they must call your office on a known number to confirm before transferring a cent. If they’re warned in advance, the fake email has nothing to exploit.
  • Lock down your own email. Multi-factor authentication stops attackers getting into your accounts to lurk and strike in the first place. While you’re at it, check your mailbox for sneaky auto-forwarding or delete rules an intruder may have set.
  • Train your team to treat any last-minute change of payment details as a red flag. Every time, no exceptions, no matter how urgent the email claims to be. Urgency is the scammer’s favourite tool.
  • If it happens, move in minutes. Call the bank immediately to try to halt the transfer, and report it to ReportCyber. With these scams, the first hour is everything.

The takeaway

Payment redirection fraud isn’t beaten with clever technology. It’s beaten with a phone call to a number you already trust, made every single time money is about to move. Build that one habit into your firm’s process, and tell your clients to do the same, and the perfectly crafted fake email becomes harmless. It’s the cheapest insurance a practice can buy, and it’s free.

Is your firm a weak link in the payment chain?

Book a free Security X-Ray. We'll check whether your email and your settlement process could be exploited, and the simple steps that close the gap.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.