The deposit that goes to somebody else’s account
A tenant has been approved and is about to move in. They get an email that looks exactly like the last six — your branding, your negotiator’s signature, the right property address — with the account details for the deposit and first month’s rent. They pay. You find out on move-in day.
This is the single most damaging thing that happens to small agencies, and it usually does not involve breaking into your systems at all. Either the attacker is in the tenant’s own mailbox reading the thread, or they have simply registered a domain one character different from yours and copied your signature block off your website. The tenant has lost money they had saved for a year, they blame you, and the complaint goes to your redress scheme. Reported rental fraud is getting less frequent and considerably more expensive, which is what you would expect if criminals are moving from scattergun fake listings to patient, targeted interception.
average loss per reported rental fraud in 2025/26, up 46% on the previous figure — 4,092 reports and £12.84m lost in total, even as the number of reports fell
Letting Agent Today, August 2026 — Action Fraud and Metropolitan Police rental fraud figures analysed by Just Landlords: 4,092 reports and £12.84m lost in 2025/26, an average of £3,138 per report, up 46%- Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
- Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
- SPF, DKIM and DMARC set to reject, so that somebody else cannot send email as your domain
- Registering the obvious look-alike domains yourself, which costs about as much as a tank of fuel
- Bank details given once, on paper or in the portal, with a line in every email saying they will never change — and a phone check on any message that says otherwise