An attacker sits in the mailbox and waits for the transfer instruction.

Real estate and property handle large, irreversible payments between parties who mostly communicate by email and rarely meet. That is the ideal condition for the most profitable fraud in South African property.

How does property transfer fraud actually work?

An attacker compromises one mailbox in the chain, most often at the agency or the conveyancer, then reads quietly for weeks. When a transfer or deposit is due, they send the buyer new banking details from a genuine account in a genuine thread at exactly the right moment. The buyer pays, and the money is gone within minutes.

Nothing about the email looks fake, because technically nothing is. Read the full walkthrough, which is the piece to send to anyone who handles payments.

What is the one control that stops it?

Telephone verification of any banking detail, on a number obtained independently before the transaction began, and a written warning to every buyer at the start that banking details will never change by email. Both are process controls rather than technical ones, and together they defeat an attack that no email filter alone can reliably catch.

Why is an agency a target when the conveyancer holds the money?

Because the agency is usually the softest entry point into the conversation and the most trusted voice in it. Buyers act on what their agent tells them. An attacker does not need access to the trust account to redirect a payment, only access to the thread in which the payment is being discussed.

What does POPIA require of an estate agency?

POPIA applies in full. An agency holds identity documents, income verification, bank statements and contact details for buyers, sellers and tenants, which is a substantial concentration of personal information. Section 19 requires documented access control, encryption, tested backup and an incident response process, and a breach involving FICA documentation is a serious one.

What does LANTEK put in place for an agency?

Enforced multi-factor authentication and monitoring for mailbox rule changes, which is the fingerprint of a compromised account. Email security that flags a first ever banking change. Encrypted devices for agents working from cars and show houses. Independent Microsoft 365 backup. Dark web monitoring, and awareness training built around the transfer fraud scenario itself.

Before you call

Most of our agents work from their own devices. Is that a problem?
It is a manageable one, and pretending otherwise does not help. The workable answer is enforced multi-factor authentication, company data confined to managed applications, and the ability to revoke access remotely when somebody leaves. Insisting on company laptops for a commission based team rarely survives contact with reality.
What is a mailbox rule, and why does it matter?
A mailbox rule automatically files or forwards incoming mail. Attackers create one immediately after compromising an account, so replies from the real party are hidden from the account owner while the fraud runs. An unexplained new rule is one of the clearest signals of compromise, and it is specifically monitored.
Can you help us write the warning we send to buyers?
Yes. It works best as a standing line in the first written communication and again on any document carrying banking details, worded so it survives being skim read. LANTEK will draft it with you as part of onboarding.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.