Conveyancing Email Fraud: How Small Law Firms Protect Client Money
The email that redirects a completion payment rarely looks fake. How mailbox takeovers and lookalike domains get into a property transaction, the Microsoft 365 settings and office habits that stop them, and what to do in the first hour if money has gone.
A buyer is two days from completion. An email arrives from the address they have been using for weeks. It has the matter reference, the right fee earner’s signature and a completion statement they half recognise. It says the firm’s client account has changed because of an audit, and asks them to use the new details for the balance.
Nothing about it is clumsy. That is the problem.
The SRA calls this email modification fraud. In the regulator’s 2020 review of cybercrime reports it received, it was the largest single category by some distance. Conveyancing attracts it for plain reasons: large sums, a predictable timetable, and a completion date everyone can see coming. The general version of the scam, and the payment controls every business should have, are in our guide to invoice fraud and business email compromise. This post is about what is different when the money belongs to a client and moves through a property chain.
Where the fake email actually comes from
A transaction involves a lot of mailboxes. Yours, your client’s, the other side’s firm, the estate agent, sometimes a broker and a lender. The fraudster only needs one of them. In practice it arrives by one of three routes.
A mailbox inside your firm has been taken over. Someone signed into a convincing fake Microsoft login page weeks ago. The attacker has been reading quietly since. Before acting, they often create an inbox rule that moves replies containing words like “bank” or “completion” into a folder nobody opens. Then the email goes out from your genuine address, and the client’s worried reply never reaches the fee earner.
Your client’s personal email has been taken over. This is common and entirely outside your control. The fraudster writes to you as the seller, from the seller’s real address, with new details for the sale proceeds.
Someone has registered a lookalike of your domain. One letter swapped, a hyphen added, .co.uk became .uk. The email copies your formatting, and the reply-to address quietly points somewhere else.
Each route needs a different defence, which is why no single product fixes this.
The Microsoft 365 settings that matter
Most small firms run on Microsoft 365. These are the settings we would check first.
Multi-factor authentication for every account, with no exceptions. That includes the consultant partner who works two days a week and the shared accounts nobody thinks about. Security defaults give you a basic version on any plan. Business Premium adds Conditional Access, which lets you block old sign-in methods that skip MFA and refuse logins from places your firm never works.
Turn automatic external forwarding off explicitly. Microsoft’s default setting is called “Automatic - System-controlled”, and Microsoft’s own documentation says it can still allow forwarding in some older tenants. Set it to Off, then make named exceptions if a genuine need exists.
Make sure someone reads the alerts. Microsoft’s security portal ships with alert policies for suspicious forwarding activity. An alert that lands in a mailbox nobody monitors has not protected anyone.
Confirm mailbox auditing is on. Microsoft turned it on by default in 2019, but it can be switched off, and what you can search depends on your licence. If a mailbox is compromised, the audit record is how you work out what the attacker read. That shapes what you tell clients, your insurer and the regulator.
Publish SPF, DKIM and DMARC for your domain. These stop criminals sending email that claims to come from your exact domain. They do nothing about a lookalike domain or a genuine mailbox that has been taken over. Our plain-English explainer on SPF, DKIM and DMARC covers how to roll them out without breaking your own mail.
Tag external mail and watch for near-miss domains. A visible banner on mail from outside the firm helps staff notice when “your colleague” is writing from somewhere else. Some filtering tools can also flag first contact from a domain that closely resembles yours.
If you are not sure how your tenant is configured, a Microsoft 365 setup review is a sensible place to start. It sits naturally inside a wider cyber security check.
Process does at least half the work
The technology reduces how often a fake email appears. It cannot decide whether to pay. These habits close that gap.
Tell clients at the start, in writing. Put your account details in the client care letter or a secure portal. Say plainly that they will never change by email, and that any message claiming otherwise is fraud. The SRA’s own guidance recommends exactly this.
Take the client’s account details early. Collect details for sale proceeds at onboarding, then confirm them by calling the number you verified during identity checks. Never use a number from an email signature.
Treat any late change as a stop. Agree an internal rule. A change of payee details close to completion goes to a named partner and waits for a phone confirmation, whatever the chain says.
Verify the other side independently. If a firm’s details look new, find their number from a source you trust rather than from the email in front of you.
Train for the Friday pressure, not the theory. The staff most at risk are busy, competent and trying to keep a chain together. Security awareness training built around your own payment steps is worth more than a generic phishing video.
If money has already gone: the first hour
Speed decides whether any of it comes back. Work through this in order, with different people on different steps if you can.
- Ring your bank’s fraud team using the number on their official website or your card, not one from any email. Ask them to contact the receiving bank straight away.
- Phone the client and the other side’s firm. Warn them not to send anything further, and agree how you will communicate from now on.
- Report it to Report Fraud, the police service that replaced Action Fraud, online or on 0300 123 2040.
- Lock the mailbox without destroying evidence. Reset the password, sign the account out everywhere, and check for new inbox rules, forwarding and unfamiliar MFA methods. Record what you find before removing anything.
- Bring in your COLP and COFA. The SRA says it expects firms to report cyber attacks. The Accounts Rules require money improperly withdrawn from client account to be replaced. If personal data was exposed, a notifiable breach must reach the ICO within 72 hours of the firm becoming aware of it. Tell your insurer early, too.
Do not wipe the laptop or delete the mailbox in a panic. The logs are what tell you how the attacker got in and what they saw.
Where this fits
Payment diversion is one of several risks that make a law firm’s IT different from an ordinary office. Misdirected email, matter permissions and long file retention sit alongside it, and we cover those in our page on IT support for small law firms. If you would like someone to look at your Microsoft 365 settings and walk through your completion process with you, remotely or on site across South London and Surrey, get in touch.
Frequently asked questions
Our seller client emailed new account details for their sale proceeds, and it genuinely came from their usual address. Is that safe to use?
No, not on that basis alone. A message from the right address only proves it came from that mailbox, and personal email accounts are taken over all the time. If the client's own mailbox has been compromised, the fraudster is writing from exactly the address you expect, with the whole transaction history to copy from. Ring the client on the number you took at onboarding, have them confirm the account details aloud, and record that you did. If they cannot be reached before completion, the payment waits.
Would a secure client portal remove the need for all this?
It helps, and it is not a cure. Moving bank details and completion statements into a portal takes them out of the inbox, where most of these frauds happen. But portal logins can be phished too, and clients will still email you, so a fraudster can still write in claiming the details have changed. The portal works best as part of a promise you make in writing at the start of the matter: this is the only place our account details will ever appear, and we will never change them by email.
Would Cyber Essentials certification have stopped this kind of fraud?
Not on its own. Cyber Essentials is a baseline for technical controls on your devices and accounts, and those make a mailbox takeover harder. It says nothing about how your firm checks a change of bank details, which is where these frauds are won or lost. The SRA has observed that firms holding Cyber Essentials Plus tended to have better policies in place, so the process of getting certified is useful. If you hold a legal aid contract, check the Legal Aid Agency's current certification requirements, because those are a separate question.
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
