Cyber security for real estate agencies: the deposit-scam playbook

Real estate agencies are prime targets for deposit redirection and trust account fraud. The five attacks agencies see, five controls that stop them, and how to build the human layer.

A real estate agency moves more money through email than almost any other small business. Deposits, rent disbursements, trust account transfers and settlement funds all change hands on instruction, and those instructions arrive by email — which makes every agent, property manager and accounts clerk a target for the same scam: a convincing message that redirects a payment to a criminal's account. Cyber security for real estate agencies is therefore not an IT topic; it is a trust-account-protection topic. This guide sets out where agencies actually get hit, the five controls that stop the most common attacks, and how to build the human layer your software cannot.

Why agencies are prime targets

Three features of agency work make it unusually attractive to attackers:

The dominant attack is business email compromise: a criminal impersonates a buyer, a seller, a supplier or your own principal and asks for a change of bank details or an urgent payment. No virus, no broken software — just a persuasive email and a staff member doing their job.

The five attacks agencies see most

  1. Deposit redirection. The buyer receives an email that appears to come from your agency, with updated account details for the deposit. The scam often starts with a compromised agent mailbox — the attacker reads real thread details, then joins the conversation.
  2. Trust account fraud. An impersonated owner or supplier asks for an urgent disbursement or an invoice payment from the trust account, exploiting the trust placed in instructions from known names.
  3. Fake tenancy applications. Prospective tenants send documents laced with malware, or pay a bogus holding deposit after being phished themselves — either way the agency is entangled.
  4. Credential theft on the agent mailbox. A fake Microsoft 365 or Google login page captures an agent's email password. From there the attacker silently forwards mail, waits, and strikes during a real transaction when nobody questions the context.
  5. Supplier invoice fraud. Trades, cleaners and contractors' invoices are intercepted and re-issued with new BSB and account numbers, in the hope the accounts clerk pays without checking.

Five controls that stop most of it

You do not need an enterprise security team. Five controls cover the overwhelming majority of the attacks above:

If you want a structured view of where your agency stands against these controls, a cyber security gap assessment scores each one with evidence and turns the gaps into a 90-day plan.

The human layer: training that fits agency reality

Annual compliance videos do not change behaviour, and agencies cannot afford behaviour that stays unchanged. What works:

Measuring whether it is working

Agencies run on numbers, so treat security the same way. The four that matter: click rate on simulations, report rate, repeat clickers, and training completion. Cyber Aware's human risk reporting tracks all four per person per month, so the trend reaches the principal without a spreadsheet. If you are comparing platforms before committing, the comparison page breaks down simulation frequency, auto-enrolment and reporting side by side.

If a payment goes wrong

Speed decides recovery. Call your bank's fraud line immediately — every hour lowers the odds of recalling the funds. Report the scam to Scamwatch (https://www.scamwatch.gov.au/), which feeds the National Anti-Scam Centre's pattern data, and notify your insurer if you carry cyber cover. Reset the affected mailbox credentials from another device, check for forwarding rules the user did not create, and preserve the emails as evidence.

FAQ

Is cyber insurance enough? No. Insurance pays some losses after the fact; it does not stop the email, recover stolen funds reliably, or protect your reputation with vendors and landlords. Insurers increasingly also require evidence of controls such as multi-factor authentication before underwriting.

We are a two-office agency. Are we really a target? Small agencies are attractive precisely because they assume they are not. Attackers filter for industries handling large transfers, not for company size — and a two-office agency has the same payment flows with fewer people watching.

Who owns this in the agency — IT or the principal? The principal owns the risk; IT implements controls. The verification rule for bank detail changes, the training culture and the trust account procedures are management decisions, not software settings.

Where should a small agency start this month? In order: enforce multi-factor authentication on every mailbox, write the verbal verification rule for payment changes, and run a first phishing simulation to get a baseline. A gap assessment then shows what remains and in what order.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.