A real estate agency moves more money through email than almost any other small business. Deposits, rent disbursements, trust account transfers and settlement funds all change hands on instruction, and those instructions arrive by email — which makes every agent, property manager and accounts clerk a target for the same scam: a convincing message that redirects a payment to a criminal's account. Cyber security for real estate agencies is therefore not an IT topic; it is a trust-account-protection topic. This guide sets out where agencies actually get hit, the five controls that stop the most common attacks, and how to build the human layer your software cannot.
Why agencies are prime targets
Three features of agency work make it unusually attractive to attackers:
- Large, time-pressured payments. Buyers transferring deposits under deadline pressure rarely stop to verify bank details, and a last-minute change of account looks plausible precisely because settlements really do involve last-minute changes.
- Email is the workflow. Offers, contracts, keys, inspection times and payment instructions all travel by email. Attackers do not need to hack anything — they only need to insert themselves into a conversation.
- Personal data in bulk. Tenant applications, ID documents and financial details sit in agency inboxes and property management systems, and a breach of that data carries notification and reputational consequences on top of any direct fraud.
The dominant attack is business email compromise: a criminal impersonates a buyer, a seller, a supplier or your own principal and asks for a change of bank details or an urgent payment. No virus, no broken software — just a persuasive email and a staff member doing their job.
The five attacks agencies see most
- Deposit redirection. The buyer receives an email that appears to come from your agency, with updated account details for the deposit. The scam often starts with a compromised agent mailbox — the attacker reads real thread details, then joins the conversation.
- Trust account fraud. An impersonated owner or supplier asks for an urgent disbursement or an invoice payment from the trust account, exploiting the trust placed in instructions from known names.
- Fake tenancy applications. Prospective tenants send documents laced with malware, or pay a bogus holding deposit after being phished themselves — either way the agency is entangled.
- Credential theft on the agent mailbox. A fake Microsoft 365 or Google login page captures an agent's email password. From there the attacker silently forwards mail, waits, and strikes during a real transaction when nobody questions the context.
- Supplier invoice fraud. Trades, cleaners and contractors' invoices are intercepted and re-issued with new BSB and account numbers, in the hope the accounts clerk pays without checking.
Five controls that stop most of it
You do not need an enterprise security team. Five controls cover the overwhelming majority of the attacks above:
- Multi-factor authentication on every mailbox and property management system login. This is the single highest-value control: it blocks the credential-theft attack even when the password is stolen. Use an authenticator app rather than SMS where possible.
- A verbal verification rule for every change of payment details. Write it into procedure: no bank detail change is ever actioned from email alone — the change is confirmed by a phone call to a number already on file, never one supplied in the email. Make it apply to the principal too; scammers impersonate directors precisely because nobody checks them.
- Email filtering and anti-spoofing records. Configure the domain records that stop criminals sending mail as your agency, and use filtering that flags external senders. Your IT provider or platform sets this up once.
- Monthly phishing simulations with same-week remediation. The deposit-redirection email works because it looks routine. Staff rehearse spotting it the same way they rehearse anything else. Cyber Aware's benchmark for monthly programmes is an average 80% reduction in clicked links by month eight.
- Segregated access and least privilege. Property managers should not all hold trust account payment authority, and leavers lose access the day they leave — stale accounts are a common quiet doorway.
If you want a structured view of where your agency stands against these controls, a cyber security gap assessment scores each one with evidence and turns the gaps into a 90-day plan.
The human layer: training that fits agency reality
Annual compliance videos do not change behaviour, and agencies cannot afford behaviour that stays unchanged. What works:
- Short monthly micro-training — five to ten minutes, mobile-friendly, on the scams actually circulating (Cyber Aware's training is built for exactly this cadence and tracks completion per person).
- Simulations modelled on agency scams — deposit changes, urgent trust transfers, tenancy documents. A generic Nigerian-prince email teaches nothing about the attacks your team will actually face.
- A one-click report button in the mail client, and praise for people who use it. A rising report rate is the earliest evidence your culture is working.
- Onboarding within the first week for new agents and property managers, who are the most phished people in the business during their first months.
Measuring whether it is working
Agencies run on numbers, so treat security the same way. The four that matter: click rate on simulations, report rate, repeat clickers, and training completion. Cyber Aware's human risk reporting tracks all four per person per month, so the trend reaches the principal without a spreadsheet. If you are comparing platforms before committing, the comparison page breaks down simulation frequency, auto-enrolment and reporting side by side.
If a payment goes wrong
Speed decides recovery. Call your bank's fraud line immediately — every hour lowers the odds of recalling the funds. Report the scam to Scamwatch (https://www.scamwatch.gov.au/), which feeds the National Anti-Scam Centre's pattern data, and notify your insurer if you carry cyber cover. Reset the affected mailbox credentials from another device, check for forwarding rules the user did not create, and preserve the emails as evidence.
FAQ
Is cyber insurance enough? No. Insurance pays some losses after the fact; it does not stop the email, recover stolen funds reliably, or protect your reputation with vendors and landlords. Insurers increasingly also require evidence of controls such as multi-factor authentication before underwriting.
We are a two-office agency. Are we really a target? Small agencies are attractive precisely because they assume they are not. Attackers filter for industries handling large transfers, not for company size — and a two-office agency has the same payment flows with fewer people watching.
Who owns this in the agency — IT or the principal? The principal owns the risk; IT implements controls. The verification rule for bank detail changes, the training culture and the trust account procedures are management decisions, not software settings.
Where should a small agency start this month? In order: enforce multi-factor authentication on every mailbox, write the verbal verification rule for payment changes, and run a first phishing simulation to get a baseline. A gap assessment then shows what remains and in what order.