Practice Management Integration

Streamline administrative tasks and optimise workflows

Integration Support Guides

Access our support guides for comprehensive self-help assistance

Partner Network

Discover an ecosystem of trusted partners designed to support your matters

InfoTrack Connect

Allows suppliers to connect their products and services with the InfoTrack Ecosystem

News and Insights

Find out the latest industry updates

AML/CTF Training

Take on compliance with confidence

Events and Webinars

Take your professional development to the next level

Cyber Security Awareness Training

Build your cyber resilience

Property Market Update

Discover leading edge property insights

InfoTrack on Claude Cowork

Access InfoTrack directly inside Claude Cowork

playbook playbook white logo
Monthly digest covering the latest news for legal and conveyancing industries.

About Us

Learn more about who we are and what we do

Our Team

Find out who drives InfoTrack's innovation and strategy

Join Us

Be a part of our award-winning culture

Media

Featured media releases and mentions

Contact

Get in touch with a member of our team

Awards

Showcasing our people, solutions and service

Discover our award-winning technical innovations.

The moment a property settlement scam succeeds, and how to catch it sooner

Vishal Duggal

Property settlement fraud sits inside one of the fastest growing categories of scam loss in Australia. Payment redirection scams, the category that covers settlement fraud, took $166.8 million from Australians in 2025, second only to investment fraud among all reported scam types. The figure climbed by 9.3 per cent on the previous year even as most other major scam categories fell, and no single agency separates conveyancing losses out from the wider payment redirection total. That absence of a clean number is not the interesting part of this story. The mechanics of how the money moves, and the exact moment a firm or a client could have stopped it and did not, are far more useful to a legal or conveyancing practice than another aggregate figure.

What a property settlement scam actually is

A property settlement scam is a form of business email compromise (BEC) in which a criminal gains access to, or convincingly imitates, the email account of a conveyancer, lawyer, agent or client, then inserts fraudulent bank details into what looks like a routine settlement instruction. The Australian Signals Directorate’s Cyber Security Centre describes the pattern as criminals impersonating one of the parties to a transaction and swapping in bank details they control, so a victim who believes they are paying the correct account is instead funding the criminal directly. Successful compromises can sit unnoticed for weeks, since nothing about the payment itself looks unusual until someone asks why the money never arrived.

Where the interception happens

The Legal Practitioners’ Liability Committee notes that conveyancing transactions attract criminals largely because of the size of the sums involved, and that in most cases it is the lawyer’s, the client’s or the agent’s email account that is compromised, letting the criminal either read a genuine message containing bank details or draft a convincing fake one that redirects payment to an account they control. In practice this happens in one of three ways. A criminal phishes the password to a mailbox and simply reads the thread until a payment instruction appears. A criminal registers a domain that differs from the real one by a single character and inserts themselves into the conversation as a new participant. Or a criminal intercepts a genuine email mid-transit and edits the account number before it reaches the recipient. From inside an inbox, all three look identical to a legitimate message.

Where it usually goes wrong

The interception is only half the story. The loss happens in the gap between the fraudulent instruction landing and someone picking up the phone to check it. Real cases show how narrow that margin is, and how little the outcome depends on the sophistication of the fraud itself.

 

In one matter recorded by the Legal Practitioners’ Liability Committee, a firm acted on fraudulent instructions and paid more than $600,000 held on trust for a beneficiary into an account controlled by criminals, only discovering the fraud weeks later when the beneficiary asked why the funds had not arrived, by which point the money had moved offshore and could not be recovered. Contrast that with a case where the outcome was different. A purchaser’s client queried a change in bank details after receiving a hacked email demanding $75,000 be paid to a new account, and that single phone call meant most of the money was frozen and recovered before it left the banking system.

 

The same pattern holds outside conveyancing firms. A South Australian conveyancing firm’s email was compromised and used to send an overseas client a fraudulent invoice for $338,000, though the Australian Federal Police’s Operation Dolos intercepted the payment in time to recover the full amount. By comparison, a Tasmanian client lost $120,000 after a spoofed email replicated a legitimate construction company’s invoice in every detail except the payment account, and a delay in reporting meant the funds could not be traced or recovered. The difference between a recovered loss and a permanent one is rarely the sophistication of the fraud. It is almost always the speed of detection and reporting.

What closes the gap

The Legal Practitioners’ Liability Committee recommends firms state in the standard engagement letter that trust account details will never change by email, and that clients must telephone the firm on a known number to verify any message that appears to alter payment instructions rather than replying to it. It also advises against assuming an overdue transfer is simply delayed, since waiting a few extra days before checking with the client has repeatedly given criminals the window they need to move funds beyond recovery. The underlying pattern holds regardless of which settlement platform is used: a criminal does not need to breach an IT system if a person can be persuaded to skip one phone call.

 

Much of that exposure sits upstream of the firm, at the point where a real estate agent first collects a buyer’s or seller’s bank details. Platforms such as Securexchange are built for agents specifically, letting them exchange bank details with verified buyers and sellers inside a controlled workspace instead of by email, with funds guaranteed for up to $1,000,000 when trust details are shared and verified this way. A practice cannot install this control itself, but it can ask the agents it regularly deals with whether they use one and can flag it as a condition worth raising in the referral relationships that bring settlement work through the door. Practitioner-to-practitioner settlement platforms with built-in authentication remove another leg of the risk, but the buyer’s or seller’s own inbound transfer, made on details received by email, remains an ordinary bank payment and the point most exposed to interception.

 

Property settlement will keep attracting criminals for the reasons it always has, large sums, tight timeframes, and routine reliance on email between parties who have often never met. What determines the outcome is not whether a firm can prevent every attempt, but how quickly it notices when one has succeeded, and how much friction sits between a fraudulent instruction and the funds moving. A phone call that takes five minutes was the difference between a scam that cost nothing and one that cost six figures in the cases above, and that habit costs a practice far less than it saves.

About Vishal Duggal

Vishal Duggal is a technology leader with 20+ years of experience, overseeing IT & Security operations across four geographies. He partners with leadership teams to turn technology strategy into outcomes, covering cloud, infrastructure, cybersecurity, and IT service management, while leading teams through change and maximising ROI.