Fraud preventionAustralia

Australia: payment redirection scams in property settlements, explained

How official bodies in Australia describe email payment redirection in property deals, the losses they publish, the checks they list, and what the pages leave unsaid.

· 18 min read

Kooky
Written by
Kooky

Builder of Shaka, the payment router that pays every agent their commission on closing date.

About Kooky and Shaka →

A home purchase ends with one or two very large transfers: a deposit, then the balance needed for settlement. When the instruction to make them arrives by email, it comes in the name of someone the buyer already trusts, at a moment when the buyer is waiting for exactly that message. That is the opening a payment redirection scam uses. Consumer Protection in Western Australia reported one buyer who lost about A$732,000 in April 2022 and another who lost A$153,950 in 2024, both after emails with their settlement agent were intercepted.

This guide sets out what Australian public bodies have published on the subject: how they describe the scam, the loss figures and what each one counts, the checks they list for anyone about to pay, the steps and reporting channels after a wrong payment, and what their pages say, and do not say, about who ends up carrying the loss. It draws on Scamwatch and the National Anti-Scam Centre, both run by the Australian Competition and Consumer Commission (ACCC), the Australian Signals Directorate (ASD), Consumer Protection in Western Australia, and the Moneysmart consumer finance site. The state-level cases and counts are Western Australian only; the national material applies across the country.

A$227mlost nationally to payment redirection in 2021
A$732,000one WA home buyer's reported loss, April 2022
15%of top business cybercrime reports, FY2024-25

ACCC Targeting Scams data as reported by Scamwatch, July 2022; Consumer Protection WA, May 2022; ASD Annual Cyber Threat Report 2024-25 factsheet for businesses (business email compromise fraud with a financial loss).

Two names for one scam

Scamwatch treats the two terms as the same thing. In a notice dated 7 July 2022 it says payment redirection scams are "also known as business email compromise", and describes them in one line: scammers impersonate a business or its employees by email and ask for an upcoming payment to be redirected to a fraudulent account.

Related readTitle fraud in New South Wales: how the Torrens Assurance Fund works

The ASD, the federal agency behind the Australian Cyber Security Centre, uses the second name and files it under phishing. Its threat page calls business email compromise "a form of targeted phishing, or spear phishing". Criminals, it says, use it to scam organisations out of money or goods and to trick employees into revealing important business information. The ASD names two routes: posing as a business representative, and using the compromised email account of an employee.

The difference between those routes matters in a property deal. In the first, nobody's mailbox has been entered: the message comes from an address built to look like the real one. In the second, the criminal is inside a genuine account and can read the file, the names, the dates and the amounts. The National Anti-Scam Centre drew the same line in a release of 4 April 2024: scammers either hack a business's email or use a lookalike address that, in its words, often differs by one letter.

How the money is redirected, step by step

Consumer Protection in Western Australia set out the sequence in a media release of 11 July 2024. Fraudsters first hack email accounts and learn about financial transactions that are in progress. They then take control of a business's email address, or create a near-identical one that is hard to tell apart from the real one. Finally they send a message requesting payment, with the bank details changed to an account they control.

The agency explains why this works: the scam targets people who are expecting a payment request and are therefore less likely to question it. A buyer a few days from settlement fits that description exactly.

Related readWhy Singapore property agents ask for your ID and source of funds

The National Anti-Scam Centre adds the detail of what changes on the page. The scammer sends an invoice on which the BSB and account numbers have been altered. Everything else can be authentic. In the Western Australian case of April 2022, Consumer Protection said the email carried authentic-looking documents as attachments.

The same release says how such scams usually come to light: the victim discovers the problem only when the real business asks for payment. By then the transfer may be days old. The Western Australian buyer who lost about A$732,000 in 2022 found out when her real settlement agent reminded her about the payment before the final inspection of the property.

As for how a mailbox is entered in the first place, the 2022 release quotes Consumer Protection's executive director of the time: "These scams usually involve the hacking into someone's email account or computer system". The release adds that the hackers may have guessed a password, or installed spyware or malware after a recipient opened an attachment or clicked a link, and it names unsecured WiFi as another suspected exposure, particularly for people working from home.

Why property deals are a target

Three official statements point at property. The National Anti-Scam Centre said in April 2024 that the sectors most commonly targeted by payment redirection are real estate, legal and construction, with car dealerships and travel companies appearing in more recent reports. Consumer Protection WA said in July 2024 that the scam most often hits high-value transactions such as property purchases, vehicle purchases and business contracts, and that WA ScamNet, its scam reporting service, had also seen building contracts and a funeral payment targeted. Its 2022 release counted the property cases separately, as the figures below show.

Related readRental scams in Singapore: how fake property agent listings work

The illustration in the Centre's April 2024 release is not a property case, but it shows a pattern a buyer may recognise. A man paid the deposit on a car through the dealership's official website, then paid a fake invoice for the balance after the dealership's email was compromised, and lost more than A$35,000. The first payment went through a safe channel; the second, larger one followed an emailed instruction.

A property purchase has the same shape: several payments, several firms writing to the buyer, and a final amount far larger than the first.

What the published figures count

No single number describes this scam, because each body counts something different. The table brings together the national figures read for this guide, with the scope of each.

National figures and what each one measuresAustralia, amounts in Australian dollars
FigurePeriodWhat it counts
A$227 million2021Payment redirection losses from Scamwatch, ReportCyber, major banks, money remitters and other agencies combined; up 77% on 2020.
A$16.2 million2023Payment redirection losses reported to Scamwatch alone.
A$6.7 million2021Business losses to false billing, a Scamwatch category that includes payment redirection; median loss A$4,200.
A$80,850FY2024-25Average self-reported cost of a cybercrime report by a business, all cybercrime types; up 50%.

Scamwatch notice of 7 July 2022 (ACCC Targeting Scams report); National Anti-Scam Centre release of 4 April 2024; ASD Annual Cyber Threat Report 2024-25 factsheet for businesses and organisations.

The first two rows cannot be read as a fall. The 2021 figure pools bank and police data with consumer reports; the 2023 figure is what people told Scamwatch. On the Scamwatch series alone, the National Anti-Scam Centre said reports of this scam fell 28 per cent in 2023 while the amount lost rose 3 per cent, so that people lost significantly more per scam than in 2022.

The ASD's figures cover cybercrime reported to it in the 2024-25 financial year. Its factsheet for businesses records more than 84,700 cybercrime reports, about one every six minutes. Among the top cybercrimes that businesses reported, email compromise with no financial loss made up 19 per cent and business email compromise fraud with a financial loss 15 per cent, ahead of identity fraud at 11 per cent. Added together, the two email categories come to 34 per cent. The average self-reported cost per report was A$56,600 for a small business, A$97,200 for a medium one and A$202,700 for a large one; those averages cover every type of cybercrime, and the factsheet gives no separate average for business email compromise.

Related readSingapore scam figures and the audit checks a property agency can run

Scamwatch's 2021 business data shows who reports. Micro businesses with up to four staff made 1,093 reports with A$3.5 million lost, small businesses with five to 19 staff made 890 reports with A$3.5 million lost, and medium businesses with 20 to 199 staff made 551 reports with A$4.2 million lost. Email was the most common way scammers reached businesses that year. Those rows count every scam type reported by businesses, not payment redirection alone.

Western Australia's counts, year by year

Western Australia is the one state whose regulator's releases, read for this guide, publish a count of victims and losses for this scam, and split out property.

For 2021, Consumer Protection recorded 37 victims and A$1,013,278 in losses. Eight of them were involved in property transactions, with A$168,000 lost. Worked through, that is 21.6 per cent of the victims and 16.6 per cent of the money, and an average of A$21,000 per property case.

By 3 May 2022, nine victims had reported A$1,015,129 in losses, three of them in property transactions. That was already A$1,851 more than the whole of 2021. One purchase, the loss of about A$732,000, accounts for roughly 72 per cent of it.

In 2023, 29 victims lost A$501,028. By 11 July 2024, 11 victims had reported A$503,285, again more than the previous full year, this time by A$2,257. The A$153,950 lost by one home buyer is 30.6 per cent of that total.

A worked comparison shows how a single property case moves the picture. Dividing each total by its number of victims gives an average loss of about A$27,400 in 2021, A$17,300 in 2023 and A$45,800 in 2024 to 11 July. For 2022 to 3 May the average is about A$112,800; set the one A$732,000 purchase aside and the other eight victims average about A$35,400. These averages are computed here from the agency's totals and are not figures it published.

Related readUAE real estate brokers: AML duties and when a deal is reported

The counts are of reports made to the Western Australian agency. They say nothing about cases in other states, and nothing about losses that were never reported.

What the two Western Australian cases show

Read side by side, the two releases describe the same mechanism with two different disguises.

In the 2022 case, the fraudulent message came from a generic Hotmail address that used the settlement agency's name. It asked for money to be deposited into a bank account before settlement. Consumer Protection noted that earlier emails from the real settlement agent had carried scam warnings to clients. The warning had been given; the fraudulent message still succeeded, because it looked like the next step in a process the buyer was following.

In the 2024 case, the message posed as the settlement agent and the difference was smaller: the buyer did not notice a slight variation in the sender's email address.

Neither release says whether the money was recovered in those cases. The 2022 release does say that two victims recovered A$287,407 of their losses; it places the sentence after the 2021 figures without stating the year it belongs to. Recovery, in other words, has happened, and the published record gives no rate for it.

A buyer who expects a payment request is the buyer least likely to question one, which is why the warning in an earlier email was not enough.

The checks listed before any payment

The advice from the three bodies overlaps closely. The fullest list is the one Consumer Protection WA attached to its 2022 release, written for anyone who receives an email asking for a payment or announcing new bank details.

  1. Check the sender's address letter by letter. The agency says scammers often change a single character.
  2. Treat a message from a generic provider such as Gmail or Hotmail with particular suspicion.
  3. Call the sender to confirm the request and the account details, using a number already known, or one found through an independent search or the business's official website.
  4. Do not use the phone number or other details given in the email itself, since they may be fake.
  5. When answering, use forward instead of reply, and type the address by hand or pick it from the address book.
  6. For a large amount, where it is possible, go to the business's office and verify the details in person before paying.
  7. Set up multi-factor authentication on email, banking and social media accounts, following the Australian Cyber Security Centre's guidance.

The same release adds general hygiene: passwords that are hard to guess and changed often, no opening of attachments or links in suspicious emails, and a secured network with up-to-date virus protection. The 2024 release compresses the list to three actions: verify the sender, call to confirm that the request is genuine, and confirm the bank account details with the business before paying.

Related readTwelve US states now have deed-theft laws as Maryland's takes effect

The National Anti-Scam Centre frames the same checks as three words. Stop: do not rush, and call the business on details found independently to confirm the payment details. Think: scammers can copy logos and Australian Business Numbers, so a document that looks right proves little. Protect: if something feels wrong, go to the bank immediately.

Worth knowing

A logo, an ABN and real attachments prove nothing

The National Anti-Scam Centre says scammers can copy logos and business numbers, and Consumer Protection WA reported a fraudulent request that came with authentic-looking documents. Every list read for this guide comes back to one act: confirming the account details by phone on a number that did not come from the email.

How these checks land depends on who is paying. For a buyer, the step is to confirm the account before the deposit and again before the settlement money, because each request is a separate chance for a substitution. For an agent, conveyancer or settlement agent, the same rule runs the other way whenever a client or another firm sends new account details by email. None of the pages sets these checks out as a legal duty; they are published as guidance, and what a firm must do under its own licence and professional rules is a separate question that these pages do not address.

What firms are asked to do

Consumer Protection WA addresses businesses in both releases. In the July 2024 release the state's commerce minister asked businesses to warn their clients or contractors and to train staff to be scam aware; the May 2022 release makes the same request. The minister's comment on the stakes in 2024 was brief: "The large losses from these scams are extremely devastating to the victims."

The ASD's threat page gives a firm the signs that its own mailbox may be the one in use:

  • a friend, colleague or service provider reports a suspicious email from the firm's address that the firm did not send;
  • that email asks for an invoice to be paid or for bank account details to be changed;
  • unusual emails arrive about suspicious login activity or unexpected password resets;
  • emails in the account have been deleted or moved to other folders.

The last sign is worth a closer look in a conveyancing file. A criminal inside a mailbox has an interest in the firm not seeing replies about the payment, so messages that vanish or turn up in the wrong folder are listed by the ASD as a sign in their own right.

Related readIs FinCEN's all-cash home purchase rule in force in the United States?

The ASD's 2024-25 factsheet tells businesses to report suspicious activity, incidents and vulnerabilities through ReportCyber or the Australian Cyber Security Hotline, and says its cyber security centre gives free technical incident response advice around the clock. The detailed prevention measures the ASD publishes for businesses sit on separate pages that were not read for this guide.

The first hours after a wrong payment

Every body puts the bank first, and each uses a word about speed. The ASD's recovery page says to go to the bank or credit union "immediately" where funds have been transferred to fraudulent account details, and to call it on its official phone number. Scamwatch says "as soon as possible". Moneysmart gives the reason: the sooner a problem is reported, the more likely the money is to come back, and it is more likely still if the account that received it holds enough to cover the payment. Moneysmart also says to ask for a reference number when reporting.

The order the official pages giveNot every step applies to every case, the ASD notes
  1. The bank, at onceCall the bank or credit union on its official number and take a reference number.
  2. ReportCyberReport the cybercrime to the ASD's service, which passes reports to law enforcement.
  3. ScamwatchTell the National Anti-Scam Centre how it happened and what was lost, to help warn others.
  4. The email providerReport the impersonation to the service the false address belongs to.
  5. Identity supportIDCARE if a breach exposed personal information; the tax office if an identity was stolen.

For a firm, the same list applies with one more consideration from the ASD's page: where a personal or business identity has been stolen, the Australian Taxation Office is to be told, and the page says all tax-related security issues must be reported to it. In Western Australia, Consumer Protection also asks for online scams to be reported through WA ScamNet.

None of the pages read gives a number of hours or days within which a transfer can still be stopped. They give a direction, immediately, and no guarantee.

Who bears the loss: what the pages say

This is the question the official pages answer least. The clearest material is on Moneysmart, and it is written around two categories that do not fit the case neatly.

Related readMortgage fraud in the United States: red flags and where to report

An unauthorised transaction, Moneysmart says, is when someone transfers money from a person's account without permission. A mistaken transaction is when a person pays the wrong person or company by using the wrong bank details. A buyer who types in the account number from a fraudulent email has made the transfer personally, and has paid the wrong party because the details were wrong. The page does not say which category, if either, covers a payment that the customer made after being deceived.

For mistaken payments, Moneysmart says a bank that has signed up to the ePayments Code has to take steps to help with a personal account, and that different rules apply depending on whether the report is made within 10 business days, after 10 business days, or after seven months. The page does not set out what those rules are. For unauthorised transactions it lists factors that make a refund more or less likely: a customer is more likely to get money back where it is clear they did not contribute to the loss, and less likely where a password was not kept secret or a report was unreasonably delayed.

Where a bank's answer is disputed, Moneysmart describes two stages. The first is a formal complaint through the bank's internal dispute resolution process. The second is a complaint to the Australian Financial Complaints Authority, whose service the page calls free and independent. It says to complain as soon as possible after the bank has finished considering the matter, because time limits apply; it does not give the limits.

One structural point appears in the Scamwatch notice of July 2022. The ACCC said then that it would like to see confirmation of payee introduced in Australia, a check in which banks verify that the account name matches the account number. Whether and how that has since been put in place was not confirmed on a primary page for this guide.

What remains open

Several points could not be settled from the pages read, and are left open instead of being filled in.

  • No page states a general rule on who carries the loss when a buyer authorises a transfer to a scammer's account. The outcome depends on the case: how quickly it was reported, whether the money was still in the receiving account, and what the bank and any complaint body decide.
  • The Australian Financial Complaints Authority's own guidance on scam complaints, and the Treasury's material on the Scams Prevention Framework, could not be read for this guide. Nothing here describes their content.
  • The state figures are Western Australian. The regulators of New South Wales, Victoria, South Australia and the other jurisdictions were not read, and a rule or count from one state is not carried to another.
  • The most recent national figure for this scam alone is the A$16.2 million reported to Scamwatch for 2023. The larger pooled figure of A$227 million dates from 2021.
  • The pages give guidance, not obligations. What an agent, conveyancer or settlement agent is required to do when sending or receiving account details is set by each jurisdiction's own licensing and conduct rules.

What the published record does establish is narrow and consistent: the scam depends on an emailed change of account details being acted on without a separate confirmation, and every body that has written about it names the same first response once money has gone, which is the bank.

Kooky, from Shaka

Kooky edits Agents Estate and builds Shaka, the payment router he made for real estate professionals. One payment comes in, and every agent, agency and party in the deal receives their signed share on closing date.