Strata and body corporate managers hold something scammers want badly: signing authority over other people's money across dozens of client trust accounts. A single compromised manager can move funds out of every scheme they administer before anyone notices, and 2026 has already produced a case study in exactly how bad that gets.
Why this matters
In February 2026, the ACCC and NSW Fair Trading confirmed that a Coffs Harbour strata manager, Jessica Marrie Carah, made 398 fraudulent transactions transferring funds from 66 separate strata plans into her own accounts before her licence was cancelled. The total loss across those schemes reached roughly $2 million. NSW Police's Strike Force Colebrook is still investigating.
That case involved an insider, not a phishing email, but it illustrates the exposure every strata management business carries: one person or one compromised login sits between legitimate owners and the trust funds of dozens of unrelated properties. Layer in email compromise, invoice fraud and fake payment-detail changes - the more common external threat - and the risk multiplies across every scheme a manager administers, not just one.
CRM Brokers, which insures strata businesses, notes that social engineering attacks against the sector run predominantly through email and social networking, though phone and in-person approaches happen too. The common thread is trust: a request that looks like it comes from a committee member, a contractor, or even a colleague inside the management company.
Who this is for
This applies to strata managers, body corporate managers, and the administrative staff inside management companies who handle levy payments, contractor invoices, and communications with owners' corporations. If your business holds client trust money across multiple schemes, you carry concentrated risk that a single-site business does not.
What to look for in security awareness training for strata managers
Invoice and payment-detail verification
Strata managers pay dozens of contractors - plumbers, insurers, building managers, landscapers - on behalf of every scheme they run. A forged invoice or a "updated bank details" email targeting one payment run can hit every scheme simultaneously if it changes a shared contractor's details in the accounting system. Training needs to drill a specific rule: any change to bank details for an existing payee is verified by phone, using a number sourced independently of the request itself, before the change is saved.
Committee and owner impersonation
Scammers impersonate committee chairs or owners requesting urgent payments, refunds, or account changes. Because managers deal with dozens of committees, staff cannot rely on recognising every voice or writing style. Training should cover a standard callback verification step for any request involving money, regardless of how well the sender seems to know the scheme's details.
Internal control segregation
The Coffs Harbour case shows the ceiling of what one person with unchecked signing authority can do across 66 client accounts. Training for supervisors and business owners should cover segregation of duties - a second person verifying or approving fund transfers above a threshold - as a control that protects both clients and the staff member from being the sole point of failure.
Trust account access hygiene
Trust accounting software holds the payment rails for every scheme a business manages. Staff need training on strong, unique credentials for this system specifically, phishing-resistant multi-factor authentication where the platform supports it, and immediate reporting of anything unusual - an unexpected login prompt, an unfamiliar device notification, a password reset they did not request.
Recognising business email compromise
Business email compromise - a scammer gaining access to or spoofing a real email account inside the management company or one of its contractors - is the most common way payment fraud starts in this sector. Staff should be trained to notice subtle sender-domain differences, unusual urgency, and requests to bypass normal payment processes, and to report suspicion rather than deleting and moving on.
Reporting culture without blame
Because strata management runs on trust across many relationships, staff need to feel safe flagging a request that looks slightly off, even from a long-standing contractor or a colleague. A punitive culture around false alarms guarantees people stay quiet on the one that matters.
Top picks
Cyber Aware - the safe pick for Australian strata management businesses. Story-driven training covers business email compromise and payment fraud scenarios directly, phishing simulations can be built around invoice and committee-impersonation lures specific to property management, and the human risk reporting dashboard gives owners a single view of who has completed training across every branch office. Buy if you want Australian-context content and a reporting layer that supports insurance and compliance conversations.
A generic global awareness platform - broad content library, strong brand recognition, but scenarios are rarely tailored to trust-account and strata-specific fraud patterns. Consider if you already use one for a parent company and want to bolt strata-specific phishing tests on top rather than replace the whole program.
No formal training, relying on individual judgement - the default at many smaller strata management businesses. Skip. The Coffs Harbour case and the broader rise in email-based invoice fraud show that individual judgement alone is not a control; it needs a documented, repeatable verification process behind it.
What to avoid
Avoid training that treats strata management as generic small business - it undersells the concentrated trust-account risk this sector carries compared to a business handling only its own funds. Avoid a single annual training session with no ongoing phishing testing; payment fraud attempts happen year-round, not once a year. Avoid skipping segregation-of-duties training for supervisors on the theory that "our staff would never do that" - the point of the control is to protect everyone, including honest staff, from being the single point of failure.
Verdict comparison
| Criteria | Cyber Aware | Generic platform | No formal training |
|---|---|---|---|
| Australian scam content | Yes | Rarely | N/A |
| Payment fraud scenarios | Built in | Add-on at best | None |
| Reporting for multiple offices | Yes, human risk score | Varies | None |
| Verdict | Buy | Consider | Skip |
FAQ
What is the biggest cyber risk for strata management businesses? Concentrated trust-account access: one compromised login or one dishonest employee can affect dozens of unrelated client schemes at once, as the 2026 Coffs Harbour case demonstrated with 398 fraudulent transactions across 66 strata plans.
Does security awareness training prevent insider fraud like the Coffs Harbour case? Training alone does not stop a determined insider, but segregation-of-duties controls, transaction monitoring and a documented approval process for fund transfers reduce how much damage one person can do before detection.
What is the most common external cyber threat to strata managers? Business email compromise and invoice fraud, where scammers impersonate a contractor, committee member or colleague to redirect a payment.
How often should strata management staff receive phishing simulation training? Ongoing, not annual - a monthly or continuous simulation cadence reflects that payment fraud attempts happen year-round.
One last thing
The detail worth remembering from the Coffs Harbour case is not the dollar figure - it is the transaction count. Three hundred and ninety-eight separate transfers happened before the pattern was caught, which means the failure was not one bad decision but the absence of any second set of eyes checking fund movements over time. That is a control gap training and process can close.