Property Settlement Scams Redirect Six-Figure Payments

The email arrives at the most expensive moment of the transaction. Settlement is close, everyone is busy, and a familiar contact appears to provide the bank details needed to finish the property purchase.

The message may be polished, personal, and part of a real conversation. It can mention the property address, the parties, the deadline, and details that only someone following the sale should know.

One changed account number is enough to send a six-figure payment somewhere the buyer, seller, agent, and conveyancer never intended.

Realistic reconstruction of a property settlement email containing fraudulent replacement bank details

Overview

What property settlement scammers change

The scam does not need to invent a property transaction. It inserts itself into a real one. A criminal impersonates a buyer, seller, real estate agent, solicitor, or conveyancer and supplies bank details controlled by the scam network.

The message may come from a compromised mailbox, a lookalike address, or another channel using stolen information. The request often arrives just before a deposit or final settlement payment is due.

Why the losses are so large

Property payments are unusually valuable and time-sensitive. Commonwealth Bank reported that one intercepted attempt almost diverted $200,000. The bank also cited $166.8 million in Australian payment-redirection scam losses during 2025.

A victim can follow what appears to be the correct process and still send money to the wrong account. If the email account itself is compromised, replies may go back to the criminal.

The verification that stops the scam

Bank details must be confirmed through a trusted channel established before the payment request. Call the known conveyancer, solicitor, or agent using a number already saved or independently found.

  • Never accept changed settlement instructions through email alone.
  • Do not use the phone number in the message you are trying to verify.
  • Read the account details back during an independently placed call.
  • Treat last-minute urgency as a reason to pause.
  • If money was sent, contact the bank immediately and request a recall.

Why a Perfectly Written Email Can Still Be Fake

Spelling mistakes are no longer a dependable warning. Criminals can copy previous messages, use artificial intelligence to draft professional replies, and collect personal details from social media.

A compromised mailbox is more dangerous than a simple imitation. The criminal can see the real transaction, learn how the parties write, wait for the payment stage, and reply inside an existing thread.

The CommBank account describes a scammer who already knew the parties, property address, nearby landmarks, and even a favorite local cafe. A phone conversation with agency staff made the impersonation sound more credible.

The attempted $200,000 diversion was stopped because the genuine seller said they had not provided the bank details. That ordinary question exposed the entire substitution.

The official CommBank property settlement warning says fraudsters are using social media, AI, and increasingly convincing communications. The practical defense remains simple: verify payment details by phone through a number you trust.

How the Property Settlement Scam Works

Step 1: The criminal learns a real transaction exists

The information may come from a compromised email account, phishing, stolen documents, social media, a breached business, or public property details. The scammer identifies who is buying, selling, or handling the settlement.

They do not need every document. A property address, expected date, names of the firms, and one authentic email chain can be enough to build a convincing request.

Step 2: The scammer watches the conversation

When a mailbox is compromised, the criminal may quietly monitor messages for days or weeks. They learn the language used by the parties and wait until a large payment is expected.

Rules can be added to hide replies or forward messages. A victim may not see warnings sent by the genuine firm because the criminal controls what remains in the inbox.

Step 3: Replacement bank details arrive at the right moment

The fraudulent email may say the trust account has changed, a previous account is being audited, the payment must be split, or updated instructions replace an earlier document.

The message can use copied letterhead, signatures, invoice formats, and reference numbers. It may arrive in the original thread, which makes the account change feel like a routine update.

Realistic reconstruction of a property settlement payment instruction page with substituted bank account details

Step 4: Urgency prevents an independent phone call

The payment is framed as the final action before settlement. The buyer may be told that delay will breach the contract, create a penalty, or postpone possession.

A criminal controlling the email can answer questions instantly. That response is not independent confirmation. It is the same person defending their own bank details.

Step 5: The payment reaches a mule account

The victim transfers money believing it is going to a solicitor, conveyancer, agent, buyer, or seller. The recipient account is actually controlled by the scam network or a money mule.

Funds may be moved quickly through additional accounts or converted into cryptocurrency. Every delay after discovery can reduce the chance of a successful freeze or recall.

Step 6: Both real parties think the other has the money

The sender may receive a fake confirmation, while the genuine recipient waits for funds that never arrive. The fraud can remain hidden until someone phones about the missing settlement payment.

By then, the scammer may have deleted messages, changed forwarding rules, and emptied the receiving account. The dispute can also damage trust between the real parties at the worst possible time.

The Email Thread Is Not a Verification Channel

When the risk is that email has been compromised, sending another email cannot resolve the risk. A reply can go directly to the attacker.

Call a number established earlier in the transaction. If you must find a number, use the firm’s official website, professional registry, or documents obtained before the suspicious instruction appeared.

During the call, read back the account name, BSB, account number, amount, and reference. Ask the other person to confirm each item from their own system.

For a very large payment, consider a second verification step and a small test transfer if the professional and bank agree. A test only helps when the recipient confirms receipt through an independent channel.

MalwareTips has covered a related vendor invoice scam exposed by one extra letter. Property settlement attacks may use the same business email compromise techniques, but the scheduled six-figure payment makes the timing especially dangerous.

Property transactions involve many legitimate messages, several professionals, and deadlines that can affect moving plans. A criminal does not have to invent that pressure. The real settlement calendar supplies it.

The fraudulent instruction may arrive when the buyer expects final figures or when the seller expects proceeds. A message sent at the right hour can look like the last routine adjustment in a long process.

Large payments also receive fewer practice runs. Most people do not regularly transfer a house deposit or settlement balance, so an unfamiliar portal, limit, or bank procedure may not feel unusual.

Criminals exploit that uncertainty with confident language. They may say the trust account changed, the previous account reached a limit, or a corrected statement must be paid before a cutoff.

A copied signature and an intact email history can make the request appear settled before the recipient has considered it. The safest response is to pause precisely when the message says there is no time.

Call the known professional and read the account details aloud. Ask them to confirm the account name, bank, branch information, and final digits. A vague yes is not enough.

For a large payment, ask whether a small test transfer is appropriate and how receipt will be confirmed. The professional and bank should agree on the process before the settlement deadline, not while an urgent email is waiting.

Keep the verified details outside the email thread. A printed engagement letter or saved contact from the beginning of the matter provides a separate reference if the mailbox is later compromised.

One deliberate verification phone call can feel inconvenient during a busy settlement. It is far less disruptive than trying to recall a six-figure transfer after the money has been split across other accounts.

Red Flags in Settlement Payment Instructions

Some attacks contain no obvious spelling error. Process changes and payment behavior are often more useful than visual clues.

  • Bank details change shortly before settlement.
  • The email says the previous trust account is unavailable.
  • The payment must be split among unexpected accounts.
  • The sender discourages a phone call or claims staff cannot be reached.
  • A new mobile number appears only in the changed instruction.
  • The account name does not match the verified firm or party.
  • The sender creates unusual urgency or threatens immediate penalties.
  • A reply confirms the change but no independent channel does.
  • The email address contains a small spelling or domain variation.
  • The professional cannot see messages that appear in your thread.

Company and Checkout Checks

Verify the professional and firm

Confirm the solicitor, conveyancer, and real estate agency through official registries and websites. Record trusted phone numbers early in the transaction, before payment instructions arrive.

Establish bank details before settlement day

Ask how instructions will be delivered and whether the firm ever changes them by email. Agree on a verbal verification process for any account details or last-minute changes.

Match the recipient during payment

Use available confirmation-of-payee or account-name checks, but do not rely on them alone. Stop if the displayed recipient differs from the verified party or firm.

Confirm receipt through a separate channel

After payment, call the known contact and ask them to confirm receipt. Do not accept an email receipt as the only evidence when email compromise is the suspected method.

What to Do if You Have Fallen Victim to This Scam

  1. Call your bank immediately. State that a property settlement payment was redirected by fraud. Ask for an urgent freeze, recall, and contact with the receiving institution.
  2. Call the genuine solicitor or conveyancer. Use a trusted number, not the email thread. Tell every legitimate party that the instructions may have been compromised.
  3. Preserve the mailbox. Do not delete messages. Save full email headers, attachments, account details, timestamps, and screenshots. Export the thread if possible.
  4. Secure email accounts. Change passwords from a clean device, enable multi-factor authentication, sign out unknown sessions, and remove unfamiliar forwarding or deletion rules.
  5. Check connected accounts. Review cloud storage, document portals, phones, and other mailboxes used during the transaction for unauthorized access.
  6. Scan affected devices. If attachments were opened or remote access was allowed, Malwarebytes can help check for credential stealers, malicious extensions, and remote-control software.
  7. Report the crime. File reports with the relevant police or cybercrime service, national scam authority, and any professional regulator involved.
  8. Beware recovery contacts. A person promising to retrieve the settlement money for an upfront fee may be attempting a second scam.

AdGuard can help reduce exposure to phishing ads, malicious redirect pages, and tracking links. It cannot protect a compromised email conversation, so independent verbal confirmation remains the critical control.

Realistic reconstruction of a banking transfer status showing a six-figure property payment sent to the wrong recipient

A Safer Settlement Payment Routine

Discuss payment security at the beginning, not on settlement day. Ask each professional which channels they use, which account will receive money, and how changes are confirmed.

Create a written call-back procedure. If any account detail changes, stop the transaction and speak with a known person at a known number. For high-value transfers, require two people to review the instruction.

Keep email accounts protected with unique passwords and multi-factor authentication. A property transaction should not share a password with shopping, social media, or old services.

Avoid posting settlement dates, moving plans, firm names, and property details publicly while the transaction is active. Those facts can help a criminal make an impersonation sound personal.

After sending money, confirm receipt promptly. The goal is to discover a problem while the receiving bank still has a chance to freeze the funds.

Frequently Asked Questions

Can a scam email come from the real address?

Yes. If a mailbox is compromised, the attacker can send from the genuine account or reply inside an existing conversation.

Should bank details ever be verified by email?

Email alone is not enough for a settlement payment. Confirm the complete details through a trusted phone number or another agreed independent channel.

What if the message has no spelling mistakes?

Professional writing does not prove authenticity. Criminals can copy earlier emails and use AI to produce convincing messages.

Does the account name check guarantee safety?

No single check is perfect. Treat it as one signal and still verify the details directly with the known professional or recipient.

How fast should I contact the bank?

Immediately. Payment-redirection funds can move through several accounts quickly. Minutes and hours may matter.

Who may be impersonated in this scam?

The criminal may impersonate a buyer, seller, agent, solicitor, conveyancer, lender, or another professional involved in the transaction.

The Bottom Line

Property settlement scams do not need a fake property. They redirect a real payment by inserting fraudulent bank details into a genuine transaction.

Never trust settlement account details because they arrived in the right thread at the right time. Verify them through a channel the sender does not control, and call the bank immediately if a transfer has already gone to the wrong account.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Brighton Federal Agent Scam: How Criminals Collect Your Cash in Person

Next

Springfield Armory PayPal Scam: How Fake Gun Invoices Hijack Your Computer