The completion-day transfer that goes to the wrong account
A conveyancing matter is days from completion. The client gets an email that looks exactly like the last twelve — same signature, same matter reference, same turn of phrase — saying the client account details have changed. They send the money. Nobody notices until the other side asks where it is.
Other businesses lose their own money. A law firm loses client money, and that is a different order of problem: an Accounts Rules failure, a report to the SRA, a claim on the PII policy, and a client whose purchase has just collapsed. The attacker often does not need to break into your systems at all. They are frequently sitting in the estate agent’s mailbox, or the buyer’s personal webmail, reading a chain you are only one participant in.
lost to conveyancing fraud in a year, across 143 reports to Action Fraud — an average of roughly £78,000 a case
City of London Police / Action Fraud — conveyancing and payment diversion fraud figures, April 2024 to March 2025- Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
- Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
- External-sender warnings, and impersonation protection tuned to your own partner and fee-earner names
- SPF, DKIM and DMARC set to reject, so that someone else cannot send email as your domain
- A written rule that bank details are confirmed by phone, on a number you already held — never a number from the email