Real estate cyber security: How your inbox can put transactions at risk

By Jerome Boutelet, Executive Head of Government Relations at InfoTrack

After spending a lot of time watching where regulation is heading across the property industry, one thing is becoming increasingly clear: cyber security is moving from an IT consideration to a business standard.

For Australian real estate agencies, that shift matters. Agents sit at the front of some of the most sensitive financial transactions Australians make. Contracts, personal information, settlement details and banking information can all pass through an agency’s systems, making real estate an increasingly attractive target for cybercriminals.

We’ve all seen the headlines, yet these situations remain common, with one of the biggest risks sitting in the place agents use every day: their inbox.

Why is real estate at risk from cybercriminals?

Real estate agencies handle exactly the kind of information cybercriminals want: personal details, contracts, transaction timelines and banking information. Much of this information is still exchanged by email, creating an opportunity for criminals to monitor a transaction and intervene when it matters most.

For a cybercriminal, an agent’s inbox can be the ultimate golden ticket. It can reveal who is involved, what is happening and when money is about to move. The more context they have, the easier it becomes to make a fraudulent request look like a legitimate part of the deal.

How are cybercriminals targeting real estate agencies?

One of the key risks is Business Email Compromise (BEC), also known as payment redirection in the context of business scams. This occurs when a cybercriminal gains access to, or impersonates, a legitimate business email account to deceive people into sharing information or transferring money.

Imagine a cybercriminal quietly sitting in an agent’s mailbox. They watch a transaction unfold, learn who is involved and see when a deposit or settlement payment is approaching. Then, at exactly the right moment, an email arrives that looks like a legitimate part of the conversation, except one detail has changed, the bank account.

The National Anti-Scam Centre’s Targeting Scams Report 2025 recorded $166.8 million in payment redirection scam losses in Australia in 2025, making it the second-highest scam type by reported losses. While this figure covers all industries, not just real estate, it puts the potential financial impact into perspective.

What can real estate learn from the legal and conveyancing sector?

The legal and conveyancing sector is already operating with cyber security built into the transaction process. The Australian Registrars’ National Electronic Conveyancing Council (ARNECC), which coordinates the national approach to electronic conveyancing, has security requirements within its Model Participation Rules for lawyers and conveyancers using electronic lodgement networks.

Under Rule 7.2.1 of the current ARNECC Model Participation Rules, subscribers are required to provide cyber security awareness training to their workforce. The rule specifically requires training to cover the secure use of email and other electronic communications, alongside other cyber security risks and controls. Put simply, secure communication is being treated as part of transaction security.

Real estate agencies are not subject to these same requirements, but the direction is relevant. If cyber security and the secure use of email are important enough to be built into the framework governing later stages of a property transaction, it is worth asking whether sensitive information should be handled less securely at the front end.

When secure solutions are available to protect sensitive transaction information, there is a strong case for making them part of the process rather than relying on ordinary email.

How can real estate agencies improve transaction security?

Agency principals can take three simple steps to reduce the risk around sensitive transaction information.

  1. Keep banking details out of email: Use a secure process to share trust account details and payment instructions instead of relying on email.

  2. Use secure platforms: Move sensitive transaction information into secure platforms or portals where you can control who can access and share it.

  3. Strengthen basic security: Use multi-factor authentication, keep systems updated and make sure staff know how to identify and report suspicious activity.

These are simple changes, but they can make a significant difference. With secure solutions are available, they should become part of the standard way an agency handles sensitive transaction information.

Is cyber security becoming part of the duty of care for real estate?

Email has been part of real estate for decades. It is fast and familiar, but that also makes it attractive to criminals. The question for agency principals is simple: have you implemented secure processes to protect sensitive transaction information?

As property transactions become increasingly digital, secure communication is becoming a standard part of doing business responsibly, not just a competitive advantage.

The time to strengthen transaction security is before something goes wrong, not after.