The reported 17% rise in cyberattacks against UK property-services businesses should be viewed as more than another sector-specific increase in breach statistics. Property firms have become unusually attractive targets because they sit at the intersection of highly sensitive personal information and some of the largest financial transactions ordinary consumers will ever make. Insurance Business reports that cyber incidents involving UK property-services businesses rose from 178 in 2024 to 208 in the year ending December 31, 2025, based on figures sourced from the Information Commissioner’s Office and cited by Karis Insurance. The increase matters because estate agents, property managers and related firms routinely collect identity documents, bank account information, mortgage details, proof of address, tenancy records and other KYC information while also participating in transactions where hundreds of thousands of pounds may move within narrow completion windows. This creates an unusually valuable combination for criminals because the same breach can provide material for identity theft, targeted social engineering, ransomware, data extortion and payment diversion fraud. 

The sector’s exposure is particularly serious because property businesses often hold data comparable in sensitivity to information held by financial institutions without necessarily operating with the same level of security maturity. Karis Insurance argues that property firms can possess as much detailed personal information about clients as banks while frequently lacking comparable data-security controls. That assessment should not be interpreted as suggesting that every estate agency has weak security, but it does identify a structural problem common to many smaller professional-services businesses: the value of the information they hold has increased much faster than their cybersecurity capabilities. A small estate agency may have only a handful of employees and limited internal IT resources, yet still store passport images, driving licences, financial information and detailed correspondence relating to high-value clients. From an attacker’s perspective, the size of the company is almost irrelevant if the information accessible through one compromised mailbox or cloud account is sufficiently valuable.

Payment diversion fraud is one of the clearest examples of why property-sector compromise produces disproportionate financial damage. City of London Police and Action Fraud recorded 143 conveyancing-fraud cases between April 2024 and March 2025, resulting in £11.7 million of losses. Residential transactions accounted for 140 of those reports and almost £11 million of the losses, with an average residential loss of £78,393 per case. Commercial cases were fewer but even more damaging individually, averaging more than £250,000. These crimes commonly involve attackers obtaining access to or convincingly impersonating email conversations between buyers, sellers, solicitors and estate agents, then inserting fraudulent bank details at the moment deposits or completion funds are due to be transferred. The attacker does not need to defeat the banking system itself. They simply need to become sufficiently convincing inside an already trusted conversation at the exact moment when the victim expects to transfer money.

That timing element makes property transactions exceptionally vulnerable to social engineering. House purchases are stressful, deadlines are fixed, buyers may fear losing the property, and large payments are expected. Criminals deliberately exploit that pressure. The City of London Police notes that fraudsters often wait until late in the transaction, when funds are expected to move quickly, before instructing victims to send money to attacker-controlled accounts. The National Crime Agency and the Law Society have similarly described payment diversion fraud as a serious and growing threat, warning that criminals impersonate solicitors, estate agents or buyers to redirect deposits and completion funds. This is an important security lesson because technical compromise and psychological manipulation work together. Access to one email account gives the attacker context, but knowledge of the transaction timeline tells them when that access becomes financially useful.

Property firms therefore need to treat email security as part of payment security rather than merely a communications issue. A compromised mailbox can reveal transaction values, client identities, expected completion dates, solicitor details and historical correspondence that allows attackers to reproduce the tone and formatting of legitimate messages. Once criminals are inside an email conversation, conventional phishing awareness becomes much less effective because the fraudulent message may arrive from a legitimate compromised account and contain information only the real parties would normally know. Strong MFA, preferably phishing-resistant authentication, should therefore be considered baseline protection for staff handling property transactions. Password-only access or SMS-based MFA provides considerably weaker protection for accounts capable of influencing substantial financial transfers.

The industry should also move away from using email as the authoritative channel for changes to bank details. Payment instructions should be established through a separate verified process, and any change should require independent confirmation using previously known contact information. City of London Police specifically advises consumers and firms to verify new bank details through an established telephone number or in person rather than trusting information received by email. This principle should be built into business processes rather than left entirely to individual judgement. A completion-day email containing new bank details should trigger a defined fraud-control workflow, not a hurried reply.

Transaction monitoring can provide another important layer. Property businesses know when large payments are expected and who the legitimate recipients should be. Changes to beneficiary details, unusual payment instructions, unexpected forwarding rules or emails sent from unfamiliar locations should therefore be treated as high-risk events. Banks have spent years developing behavioral fraud detection around financial transactions; property firms need similar thinking around the communications and documents that cause those transactions to happen.

The KYC information held by property firms also creates substantial identity-theft risk even where no money is immediately redirected. Copies of passports and driving licences, proof-of-address documents, mortgage information and bank details can be combined to create highly credible identity profiles. Criminals can use those records for fraudulent account opening, loan applications, SIM swaps or targeted impersonation. Unlike passwords, many of these attributes cannot simply be reset after a breach. A person can change a password in minutes, but cannot realistically change their date of birth, historical addresses or facial image. That permanence makes KYC datasets particularly attractive for long-term criminal use.

Data minimization should therefore become a much more serious issue within property businesses. Firms should ask not only whether they are legally entitled to collect a document but also how long they genuinely need to retain it, who needs access and whether a less sensitive representation would satisfy the same compliance purpose. If a passport is required during onboarding, that does not automatically justify keeping an unrestricted copy accessible to every employee indefinitely. Sensitive documents should be encrypted, access-controlled and retained according to clear legal and operational requirements rather than accumulated simply because storage is inexpensive.

Access controls need to reflect job roles as well. Lettings staff, sales agents, property managers, accountants and administrators do not necessarily require identical access to client identity and financial data. Excessive internal access increases the damage caused when one account is compromised. Least privilege can reduce the blast radius by ensuring that an attacker who steals one employee’s credentials does not automatically gain access to every client record maintained by the company.

Ransomware adds another dimension because property businesses frequently depend heavily on digital access to contracts, tenant information, maintenance records, transaction files and client communications. An attack that encrypts those systems can create immediate operational pressure even if the underlying information is never publicly leaked. Modern ransomware groups increasingly combine encryption with data theft, making backups necessary but no longer sufficient. Restoring files may recover operations, but it does not undo the disclosure of client identity information already copied by attackers. Property firms therefore need both resilience controls, such as offline or immutable backups, and exfiltration-focused controls capable of detecting unusual outbound transfers.

Third-party risk is equally important because property transactions involve an ecosystem rather than a single organization. Estate agents interact with solicitors, mortgage brokers, lenders, property managers, referencing services, surveyors, cloud platforms and numerous software providers. A criminal does not necessarily need to compromise the best-defended participant. They can attack the weakest organization in the chain and then use trusted communications to influence everyone else. The security posture of suppliers handling client data should therefore be part of procurement and risk management, particularly where vendors receive large volumes of KYC information or integrate directly with internal systems.

The rise in attacks also has obvious implications for cyber insurance, which is the context in which Karis raised the issue. Smaller property firms may underestimate the scale of their exposure because they associate major cyber losses with large corporations. Yet a relatively small agency can face notification costs, legal expenses, forensic investigation, operational interruption, regulatory exposure and third-party claims following a breach. Insurance Business cites broader UK SME data showing that cyber-insurance penetration remains substantially lower among smaller organizations, despite the fact that they often have fewer internal resources to absorb an incident. Insurance can provide valuable financial support, but it should not be treated as a substitute for controls because insurers increasingly examine MFA, backups, privileged access and incident-response preparedness when assessing risk.

Incident-response planning is particularly important for firms involved in payment flows because the first few hours after fraud can determine whether funds are recovered. If a fraudulent bank transfer is discovered, the sending bank should be contacted immediately, along with the receiving bank where possible, while the incident is reported through the appropriate fraud channels. The City of London Police emphasizes rapid contact with the bank because early intervention may prevent further losses or improve the chance of recovering diverted funds. Firms should rehearse these steps before an incident occurs rather than attempting to discover telephone numbers and responsibilities during a live fraud.

Cybersecurity awareness within the property sector also needs to move beyond generic annual phishing training. Staff should understand the specific fraud patterns relevant to their work: fake changes to solicitor bank details, compromised landlord accounts, urgent requests during completion, fraudulent deposit refunds, manipulated invoices and impersonation of senior staff or clients. Training becomes far more effective when employees recognize scenarios they actually encounter rather than being shown yet another example involving a fictional parcel-delivery email.

Technical controls should support that awareness rather than expecting employees to become human intrusion-detection systems. Email authentication, strong MFA, endpoint protection, DNS and web filtering, security monitoring, DLP, anomaly detection and controlled access to client records all reduce the amount of judgement required from individual users. Sensitive documents leaving the organization should be monitored for unusual destinations or volumes, particularly when passports, financial statements or transaction documents are involved. A user downloading hundreds of KYC documents or sending large collections of files to a new external destination should generate scrutiny even if the account has authenticated successfully.

Network segmentation can further reduce damage where property firms operate multiple systems or offices. A compromised reception workstation should not automatically provide access to document stores, accounting systems and backup infrastructure. Administrative interfaces should be isolated, privileged accounts separated from ordinary user accounts and remote access restricted to managed devices. Smaller firms sometimes assume segmentation is relevant only to large enterprises, but modern cloud and network-security platforms make least-privilege architectures increasingly practical for SMEs as well.

Cloud configuration deserves equal attention because many property businesses have moved document management, email and CRM systems into Microsoft 365, Google Workspace or industry-specific SaaS platforms. Moving data to the cloud does not remove the organization’s responsibility for authentication, permissions and monitoring. Attackers frequently target cloud identities because a stolen account can provide access to email, documents and transaction information without placing malware on an endpoint. Conditional access, device compliance, suspicious-login monitoring and restrictions on external sharing can significantly reduce this risk.

The reported 17% increase should also be interpreted carefully. The 208 incidents represent reports recorded in the underlying ICO-related figures cited by Karis, not necessarily the total number of cyberattacks occurring against the entire UK property sector. Many attacks are blocked, some breaches are never detected and others may not meet reporting thresholds. The figures therefore provide evidence of a rising reported trend rather than a complete measurement of criminal activity. That caveat does not reduce the concern; if anything, it means the visible incidents are likely only part of the sector’s actual exposure.

The wider pattern is clear. Real estate and property businesses are increasingly attractive because they concentrate three things criminals value: sensitive identity data, trusted communications and large financial transactions. Unlike many other sectors, all three frequently converge inside the same email thread or client file. A criminal who compromises that environment can steal information, impersonate trusted parties and potentially redirect a six-figure payment without ever needing to attack a bank directly.

The strongest defense therefore has to combine data security with transaction security. Firms should protect the KYC documents they store, but they must also protect the processes through which money moves. They should secure email accounts, but they must also assume that an email account can eventually be compromised and require independent confirmation for high-risk changes. They should maintain backups, but they must also detect data exfiltration. And they should purchase cyber insurance, but only as part of a broader resilience strategy rather than as compensation for weak controls.

The deeper lesson from the UK property sector is that attackers increasingly follow business processes rather than technology categories. They do not care whether an organization considers itself an estate agent, property manager, law firm or financial institution. They care where identity documents are stored, where trusted conversations occur and when money is about to move. Property firms happen to offer all three. 


Conveyancing fraud cost buyers £11.7 million last year. Cyberattacks on agents are adding to the risk

Source: Cyberattacks on UK property firms rise 17% as hackers target client data via insurancebusinessmag.com.