Preventing Payment Redirection in Property Transactions
Deposits, rent and settlement funds move through your business on emailed instructions. The question is whether your technology and your processes can stop an impersonated email from redirecting them.

Property transactions combine three things that rarely appear together in other businesses: large sums of money, tight deadlines, and parties who have never met each other. A deposit on a residential purchase, a bond transfer, a rent roll disbursement or a settlement fund movement can involve hundreds of thousands of dollars, must happen on a specific date, and is coordinated between an agent, a buyer, a seller, a conveyancer and sometimes a bank — most of whom communicate only by email.
That combination is unusually attractive to attackers. A criminal who can insert themselves into an email thread at the right moment can redirect a payment that the victim fully intends to make, to a legitimate-looking business, for a legitimate-looking purpose, at a time when the victim is expecting to be asked. The payment is not stolen in the conventional sense. It is instructed, by the victim, to the wrong destination — and once it is gone, it is rarely recovered.
Business email compromise and payment redirection are recognised threats to Australian businesses, reported on by the Australian Signals Directorate. The guidance here is about the technology and processes that reduce the risk — identity, email protection, verification and monitoring — not a guarantee that fraud will never occur.
How payment redirection actually works
Payment redirection is not a single attack. It is a sequence, and it depends on the attacker understanding the rhythm of a genuine transaction well enough to insert a false instruction at the exact moment it will be expected.
The pattern usually begins with an email account being compromised. That does not always mean a dramatic hack. It can be a phishing message that captures a password, a credential leaked from another service and reused, or a mailbox rule quietly created by an attacker that copies incoming messages to an external address. Once the attacker has visibility of the account, they do not act immediately. They wait. They read the mail. They learn when deposits are requested, how invoices are sent, what tone the agent uses, and which transactions are approaching settlement.
Then, at the right moment, they send a payment instruction. It may appear to come from the agent's own email address, or from a near-identical address with a single character changed. It may reply to an existing thread, so it carries the full context of the genuine conversation. It may include an invoice that looks correct in every respect except the bank account number. It arrives when the recipient is expecting to be asked for money, it asks for the right amount, and it provides new or changed bank details with a plausible reason — a changed account, a system update, a last-minute correction.
The victim pays. They were already going to pay. The instruction looked correct, arrived at the right time, and came from what appeared to be a trusted source. The money leaves their account and enters one the attacker controls, often to be moved again within hours. By the time anyone notices — usually when the genuine party asks where the payment is — the funds are gone, and the trail is cold.
The critical detail is that the victim did what they were asked to do. They were not tricked into paying something they did not owe. They were tricked into paying the right amount, to the wrong account, by an instruction that exploited their trust in the email channel and the timing of a real transaction. That is what makes payment redirection so difficult to stop after the fact — and why the work of preventing it has to happen before the instruction is sent.
Why property businesses are exposed
Property businesses are not uniquely careless. They operate in an environment that payment redirection attacks are specifically designed to exploit. Several factors combine to create the exposure.
Deadline pressure at settlement
Settlement dates are fixed. When a deposit or balance must be transferred by a specific time on a specific day, the pressure to act quickly is real and legitimate. An attacker who knows the deadline can exploit the urgency, because the recipient has no time to second-guess an instruction that looks correct.
Parties who communicate only by email
In most property transactions, the agent, the buyer, the seller and the conveyancer have never sat in the same room. They know each other through email. An instruction that arrives from a known address, in an existing thread, carries the full weight of that established trust — even if the address has been compromised or subtly imitated.
Agents working from phones between properties
Sales agents and property managers spend their days in cars, at inspections and between offices. They read and action email on mobile devices, often quickly, often between appointments. A payment instruction reviewed on a phone screen is harder to scrutinise than one reviewed on a desktop, and the context around the sender address is less visible.
Deposits and trust funds moving on written instruction
Property businesses move significant sums on the basis of written instructions — deposits, rent disbursements, bond transfers, settlement funds. The instruction itself is the authority to pay. If the instruction is fraudulent, the payment is fraudulent, and the business has no independent check beyond the email that told it to act.
Staff who reasonably assume a known email is genuine
Most staff are trained to be helpful and responsive. When an email arrives from what appears to be a known party — a regular buyer, a trusted conveyancer, the principal's own address — the assumption is that it is genuine. That assumption is exactly what the attack depends on, and it is reasonable in the absence of a verification step.
None of these factors is a failure in itself. Deadlines, email communication, mobile work and trust in known contacts are how property businesses operate. The exposure comes from the fact that the business has no independent verification step standing between a plausible instruction and a payment that may be going to the wrong place. When the email channel is both the source of the instruction and the only check on its authenticity, a compromise of the channel is a compromise of the entire payment process.
The exposure is also structural, not individual. A sales agent who pays a fraudulent instruction is not being negligent in the context of their normal work. They are doing what they do every day — responding to an email, actioning a payment, meeting a deadline. The failure is in the system that allowed a single email to carry both the instruction and the authority, with nothing else required before the money moves. Fixing that system is not about blaming staff. It is about changing the environment so that a plausible email is never, on its own, sufficient to redirect a payment.
The two separate failures
Payment redirection is not one problem. It is two, and both need to be answered independently. Addressing only one leaves the business exposed, because the attack can succeed through whichever gap remains open.
Failure one: the account is compromised
An attacker gains access to a genuine email account — the agent's, the buyer's, the conveyancer's or the principal's. From there, they can read transaction threads, learn the timing of payments, and send instructions that appear to come from a trusted source. Stopping this failure is a technology problem: multi-factor authentication, conditional access, email protection, detection of unusual mailbox rules and sign-ins, and prompt removal of access when people leave.
Failure two: the payment is made without independent verification
A payment instruction is received — whether from a compromised account, a spoofed address, or even a genuine account that has been manipulated — and the recipient acts on it without checking the bank details through a separate, trusted channel. Stopping this failure is a process problem: a verification step that is required for every new or changed payment detail, using a phone number the business already held, never one supplied in the email itself.
The two failures are independent. An attacker who cannot compromise an account may still succeed by spoofing an address closely enough to fool a busy reader. A business with perfect email security may still pay a fraudulent instruction if a staff member acts on an email without verifying the details. The only way to reduce the risk meaningfully is to address both: make the account hard to compromise, and make the payment hard to redirect without independent confirmation.
Many businesses focus on one and assume the other is covered. A property business that implements multi-factor authentication but has no verification process is still exposed, because a spoofed email does not require a compromised account. A business that has a verification process but weak email security is still exposed, because an attacker with mailbox access can intercept, alter or fabricate instructions in ways that a phone call might not catch if the number being called was also supplied in the fraudulent email. Both controls need to be in place, and both need to be applied consistently — not just when someone remembers.
Payment redirection succeeds when an account is compromised and a payment instruction is accepted without verification. Both need answering.
Stopping the account compromise
The first failure — an attacker gaining access to a genuine email account — is the one technology can address most directly. The controls are well established, and most of them are part of the Essential Eight published by the Australian Signals Directorate as a baseline set of mitigation strategies.
Multi-factor authentication
Every account that can send or receive payment-related email should require a second factor beyond a password. Multi-factor authentication is one of the Essential Eight mitigation strategies, and it is the single most effective control against account compromise. An attacker who captures a password cannot log in without the second factor.
Conditional access
Conditional access policies restrict sign-ins based on context — location, device, time, risk level. A sign-in attempt from an unusual country, an unmanaged device or an anomalous time can be blocked or challenged, even if the password and second factor are correct.
Email protection
Email filtering, anti-phishing controls and malicious-link detection reduce the volume of fraudulent messages that reach staff in the first place. The fewer phishing attempts that get through, the lower the chance one of them captures a credential.
Detecting unusual mailbox rules and sign-ins
Attackers often create hidden mailbox rules that forward copies of incoming mail to an external address, or that move certain messages to a folder the user never checks. Monitoring for unexpected rules, new forwarding addresses and anomalous sign-in patterns can detect a compromise before it is used.
Removing access promptly when people leave
Departed staff and contractors who retain access to shared mailboxes or individual accounts are a standing vulnerability. Offboarding should remove accounts, revoke permissions and confirm access is closed — consistently, not just when someone remembers.
Managed mobile devices
Agents who read and action email from phones need those devices to be enrolled, secured and remotely wipeable. A lost or stolen phone with an active mailbox session is an open door to every transaction thread it contains.
These controls are not exotic. They are standard, well-documented and available within Microsoft 365. The reason they are often not in place is not that they are difficult to implement — it is that no one has been given the responsibility to implement them, or the business has not treated email security as a payment-security issue. In a property business, it is. An email account that can be used to send fraudulent payment instructions is a financial risk, not just an IT one.
The detection side matters as much as the prevention side. An attacker who has compromised an account may sit quietly for weeks, reading mail and learning the pattern of transactions before acting. If the business is monitoring for unusual sign-in locations, unexpected mailbox rules and new forwarding addresses, the compromise can be detected during that quiet period — before any payment instruction is sent. Detection is not a luxury. It is the difference between discovering a compromise after the money is gone and discovering it while the attacker is still watching.
Stopping the payment being made
The second failure — a payment being made to fraudulent details without independent verification — cannot be solved by technology alone. It requires a business process, and that process has to be simple enough that staff will actually follow it under real deadline pressure.
The core principle is straightforward: any new or changed payment detail must be verified through a channel and a number the business already held before the request was received. Never a number supplied in the email itself. If an email says "please update our bank details" and includes a phone number to call if you have questions, that number is part of the attack. The verification must use a contact method that was already in the business's records — a phone number from a previous transaction, a known office line, a contact saved before the instruction arrived.
The verification step
When a new or changed bank detail arrives by email, the staff member responsible for the payment picks up the phone and calls a number they already had. They ask a person they can identify to confirm the change. If they cannot reach anyone on a previously known number, the payment does not proceed until they can.
This is a business process, not a software feature. Technology supports it — by protecting the email account so the instruction is less likely to be fraudulent in the first place, and by providing secure channels for communication — but the verification itself is a human action that no tool can replace.
The process must be non-negotiable. It cannot be something that staff do when they have time and skip when they are under pressure — because the attacker is specifically counting on pressure to bypass it. A verification step that is optional is not a control. It is a suggestion, and the attack is designed to defeat suggestions.
The process also needs to cover the full range of payment changes, not just the obvious ones. A new bank account is the clear case, but so is a changed account within the same institution, a request to split a payment across two accounts, a change to the reference details on an existing account, or a request to pay a slightly different amount to a slightly different destination. Any deviation from the details the business already holds should trigger verification, not just a completely new set of instructions.
The verification also needs to happen at the right point in the process. Checking bank details after the payment has been authorised but before it is released is too late in most systems — the instruction has already been given. The check needs to happen before the payment is authorised, as part of the authorisation itself. That means the person approving the payment is the person responsible for verifying the details, or the verification is documented and attached to the approval. The point is that no payment leaves the business on the strength of an email alone.
What good looks like
The target state is not a business that never receives a fraudulent instruction. It is a business where a fraudulent instruction cannot result in a payment, because the controls around the payment process make it impossible for an email alone to redirect funds. Good looks like this:
A verification step nobody is permitted to skip
Regardless of seniority, urgency or familiarity, every new or changed payment detail is verified through a channel the business already held. The principal is subject to the same process as the newest admin assistant. Urgency is not a reason to bypass the check — it is a reason to be more careful.
Staff who know that urgency is itself a warning sign
Training does not just tell staff to verify. It tells them that an email demanding immediate action, especially one involving changed bank details, is the single most common hallmark of payment redirection. Urgency is treated as a signal, not an excuse.
A compromised account is detected rather than discovered afterwards
Monitoring for unusual sign-ins, unexpected mailbox rules and new forwarding addresses means that if an account is compromised, the business finds out while the attacker is still watching — not after the payment has been sent.
Multi-factor authentication on every payment-relevant account
Every account that can send, receive or influence payment instructions requires a second factor. Not just the principal's email — the shared mailbox, the property manager's account, the admin assistant who processes invoices. The attacker only needs one unprotected account.
Access removed promptly and consistently when people leave
Offboarding is a process, not a memory task. When a staff member or contractor departs, their access is removed on the day, not when someone gets around to it. Shared accounts have been eliminated so that access is tied to individuals and can be truly revoked.
Mobile devices managed, encrypted and wipeable
The phones and laptops that agents use to read email and action payments between properties are enrolled, encrypted and remotely wipeable. A lost device is an inconvenience, not a doorway into every transaction thread.
The difference between the exposed state and the target state is not a different business. It is the same property business, with the same staff, running the same transactions — but with a verification process that is built into the payment workflow rather than left to individual judgement, and a technology environment that makes account compromise difficult and detectable rather than easy and silent.
In practice, good looks like a sales agent who receives an email asking them to update the bank details for a deposit transfer. They do not action it. They do not forward it. They pick up the phone and call the number they already had for the conveyancer — not the number in the email. They confirm the change or they do not. The entire interaction takes two minutes. The payment either proceeds to the correct account or it does not proceed at all. The agent does not feel heroic for doing this. They feel normal, because this is how payments work in their business.
Good also looks like a principal who can answer a simple question: if a fraudulent payment instruction arrived in our business today, what would happen? In the target state, the answer is that it would be verified, the verification would fail, and the payment would not be made. The principal does not need to know which staff member would handle it, because the process is the same for everyone. The answer is in the system, not in a person.
The target state also means the business can demonstrate its position without building a case. When a client asks what controls are in place around payment instructions, the business can describe a verification process, multi-factor authentication, conditional access, device management and monitoring — because those controls are actually in place and actually used. The position is visible in the way the business operates every day, not in a document that was written once and filed away.
How this maps to the LOOKUP Business Modernisation Framework™
Preventing payment redirection in a property business follows the same eight-stage sequence — so that identity is secured, email is protected and verification is built into the payment process before any transaction is at risk.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Discover
Map where payment instructions are received, who can authorise payments, which accounts handle deposits and trust funds, and what verification currently exists before any payment is released.
Secure
Put multi-factor authentication, conditional access and least-privilege permissions on every account that can send, receive or influence payment instructions, so that email compromise is difficult and detectable.
Modernise
Move payment-related communication and documentation into governed Microsoft 365 channels with email protection, anti-phishing controls and monitoring for unusual mailbox rules and sign-ins.
Standardise
Establish a consistent verification process for every new or changed bank detail, using a channel and number the business already held, so that no payment leaves on the strength of an email alone.
Optimise
Review mailbox rules, sign-in logs and forwarding addresses regularly, test the verification process under real deadline pressure, and confirm that offboarding removes access to payment-relevant accounts immediately.
Prepare
Build the governance foundations — documented verification steps, staff training on urgency as a warning sign, and managed mobile devices — that the business needs before introducing any automation around payments.
Implement
Deploy conditional access policies, email authentication controls and monitoring alerts that detect compromise while the attacker is still watching, and route any bank-detail change through the verification process automatically.
Improve
Review the payment security environment periodically as the business grows, ensuring verification stays non-negotiable, access stays controlled and monitoring catches new threats before a payment is redirected.
How LOOKUP helps
LOOKUP works on the Microsoft 365 environment around the specialist systems a property business uses. We do not replace trust accounting platforms, property management software or CRMs. We coordinate with them, and we secure the environment in which payment instructions are received, read and acted on.
The work that reduces payment redirection risk is the same work that strengthens the business generally:
Microsoft 365 identity
Multi-factor authentication, least-privilege access, and joiner-mover-leaver processes that ensure only the right people can access payment-related email and systems.
Conditional access
Policies that restrict sign-ins based on location, device and risk, so that an attempt to access an account from an unusual context is blocked or challenged before it succeeds.
Email protection
Advanced filtering, anti-phishing controls and malicious-link detection that reduce the volume of fraudulent messages reaching staff in the first place.
Monitoring
Detection of unusual sign-in patterns, unexpected mailbox rules and new forwarding addresses, so that a compromise is found while the attacker is still watching rather than after the payment is gone.
Device management
Managed, encrypted and remotely wipeable laptops and phones, so that a device lost between properties is an inconvenience rather than a doorway into every transaction thread.
Coordination with specialist platforms
Coordination with trust accounting, property management and CRM vendors to ensure the surrounding environment supports — not undermines — payment security.
For a broader view of how LOOKUP approaches technology for property businesses, see our Real Estate & Property Services industry page. For the Microsoft 365 environment specifically, see how we approach Microsoft 365 governance, and for security baselines, our work on the Essential Eight.
Frequently asked questions
Payment redirection fraud occurs when an attacker who has gained access to a genuine email account sends payment instructions that look correct and arrive at exactly the right moment in a transaction, causing the recipient to transfer funds to an account the attacker controls. The victim follows what appears to be a legitimate instruction from a trusted address, and the money is usually gone before anyone notices.
Property businesses are targeted because they combine large sums, tight settlement deadlines and parties who communicate only by email and have often never met. An attacker who can see a genuine transaction in progress can time a fake instruction to arrive at the exact moment a deposit, rent payment or settlement fund transfer is expected, making the fraudulent request appear routine.
Multi-factor authentication stops an attacker from compromising an email account in the first place, which is one of the two failures that lead to payment redirection — but it does not stop a payment being made to fraudulent details once an instruction is received. Both account compromise and unverified payment instructions need to be addressed independently, because fixing only one leaves the business exposed.
A property business should verify any new or changed payment detail using a channel and a phone number it already held before the request was received — never a number supplied in the email itself. Calling the known contact on a previously verified number, rather than replying to the email, is the independent verification step that stops a fraudulent instruction from being acted on.
No technology product guarantees protection against payment redirection, because the attack exploits human trust and business process as much as it exploits technical access. Technology — multi-factor authentication, conditional access, email protection and monitoring — reduces the likelihood of account compromise, but the independent verification of payment details remains a business process that technology supports rather than replaces.
Staff should treat urgency itself as a warning sign and verify the instruction independently before acting, using a channel and number the business already held. An email demanding immediate action, especially one involving new or changed bank details, should never be acted on without independent verification regardless of who appears to have sent it or how senior the request seems.
Executive guides
How LOOKUP can help
AI & Workflow Automation
Practical automation that reduces repetitive work.
Microsoft 365
Implement, optimise and secure your Microsoft 365 environment.
AI Readiness
Prepare data, permissions and governance for AI.
Virtual CIO
Senior technology leadership without a full-time hire.
Managed IT Services
Proactive support that keeps the business running.
Sources & Further Reading
The following primary and authoritative sources support the research, guidance and industry context discussed on this page:
Australian Cyber Security Centre (ASD) — Essential Eight Mitigation Strategies — 2024
The ASD's published baseline set of mitigation strategies, including multi-factor authentication, application control and patching, designed to reduce the risk of business email compromise and other cyber threats.
View Source →Evidence Standard
LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
Related outcomes
Protecting Personal Information in a Property Business
Hold only what you need and control who sees it — identity, access, Microsoft 365 governance and retention for tenant, buyer and landlord information.
Building a Technology Roadmap for a Property Business
Bring cyber security, Microsoft 365, automation, AI and AML/CTF technology implications into one coordinated roadmap.
Could a Fraudulent Email Redirect a Payment From Your Business Today?
If your answer is "probably not" or "I'm not sure," that is worth fixing before the question becomes urgent. Book a strategy session with LOOKUP to assess your email security, payment verification processes and monitoring — and build a practical environment where a single email cannot redirect a payment.
Peter Kantarelis
Founder, LOOKUP — Business Technology Strategist
Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.
View More Insights →