Payment redirection scams took $166.8 million from Australians in calendar 2025, the second-largest scam category by reported loss behind investment fraud. This is the one where a criminal, using a hacked or lookalike email account, sends you fake trust account details, so the money you transfer for your deposit or your settlement balance lands in their account instead of your conveyancer's. It is a form of business email compromise, and property settlement is where it meets the largest single payment most households ever make.
When PEXA showed a fake settlement email to 1,028 Australians who had either bought in the past year or intended to buy within one, fewer than one in a hundred spotted the false letter hidden in the sender address. What follows is a verification protocol for the week your money moves, and an answer to the question most buyers only think to ask afterwards: who bears the loss. Almost every protection Australians assume exists does not apply here.
How much Australians lose to payment redirection scams
Australians reported $2.18 billion in scam losses across 481,523 reports in calendar 2025, according to the National Anti-Scam Centre. Payment redirection accounted for $166.8 million, second only to investment scams at $837.7 million. It ranked third in 2024, and it climbed 9.3 per cent from $152.6 million while most other top categories fell.
Reports reach the centre through several overlapping channels, and the split is telling. Payment redirection losses were $114.7 million through ReportCyber, the police channel, against $12.2 million through Scamwatch. People who lose money this way go to the police. No Australian agency separates property settlement fraud from the rest, so nobody can say how much of that total is conveyancing.
How a settlement payment redirection scam works
There are three variants, and from your inbox they look identical.
Mailbox compromise at the practitioner's end. A criminal phishes the password to your conveyancer's or the agent's email account, then reads it. They learn your file reference, your settlement date, the balance owing and the house style of the firm. When the timing suits they send from the genuine address, often inside the existing thread, so it reads as the next message in a conversation you have been having for weeks. The address survives every check you could run on it, because it is the real one.
The lookalike domain. ASD's Australian Cyber Security Centre describes criminals registering domains similar to legitimate companies by swapping letters or adding characters, along with free Gmail, Yahoo and Outlook addresses carrying the business name. A doubled letter, an added "s", an "rn" where there was an "m", or .com where the firm uses .com.au will all pass a glance. In August 2026 a Western Australian first-home buyer came within minutes of transferring $1.2 million after her settlement agent's account was compromised. A Westpac banker stopped it: the tone had changed, the address carried one extra letter, and the staff member named was on leave.
Your own mailbox. The compromise does not have to be at the firm's end. If a criminal is reading your inbox, the genuine email is intercepted and the one you act on is theirs, sent from a lookalike address dressed up as a resend. Turn on multi-factor authentication for the account you use for the purchase, check its settings for forwarding rules you did not create, and do not run settlement correspondence through a shared family address.
The trick is context. There is nothing technically clever about any of it. The email carries your file reference and the right amount to the dollar, and it lands in the week you were expecting it. The government's standing alert on this was published on 30 August 2021 and has not been updated since, which tells you how hard anyone is working to put it in front of buyers.
When your settlement money is most at risk
The ABS put the mean price of an Australian dwelling at $1,111,100 in the March quarter 2026, ranging from $1,324,800 in New South Wales to $597,300 in the Northern Territory. Four payments are exposed, at four different moments.
| Moment | What typically moves | Where it goes | Why it is exposed |
|---|---|---|---|
| Deposit on exchange | 5 to 10 per cent, about $55,000 to $111,000 at the national mean | Agent's or practitioner's trust account | No prior details on file to compare against |
| Transfer duty | In NSW, payable by the earlier of settlement or three months from the contract date | Trust account, then the revenue office | A hard deadline makes urgency plausible |
| Balance at settlement | Price less deposit less the lender's advance | Trust account or PEXA Source Account | Largest single push payment most households make |
| Adjustments and fees | Rates, water and land tax adjustments, professional fees | Practitioner's trust account | Small enough that people skip the call |
Know your duty deadline before someone tells you it is urgent, because stamp duty falls due differently in each state. At auction the deposit falls due on the hammer, so confirm the trust account by voice days beforehand, not on the footpath afterwards; the auction buyer's playbook covers that preparation. Off-the-plan deposits sit longest, sometimes a year with dozens of emails in between, which is its own due diligence problem.
Does PEXA stop settlement scams?
Electronic settlement does not remove this risk. In a PEXA workspace, funds must come from a registered trust account or the PEXA Source Account, and a trust account line item must be authorised by a Trust Account Authorised Signer. Practitioner talks to practitioner inside a controlled platform.
Your money still has to reach that trust account first, and that inbound transfer is an ordinary bank payment made by you, on details you were given by email. ASD's alert puts it plainly: "PEXA remains secure yet the new bank account details are fraudulent, resulting in the buyer sending funds to the cybercriminal's bank account".
How to verify trust account details before you transfer
Run these in order, every time, including the time you are sure it is fine.
- Get the details on paper at the start. The Legal Practitioners' Liability Committee tells Victorian practices to warn clients in their engagement letters that bank details must never be accepted or changed by email alone, and to notify any genuine change by post or hand-delivered letter. A change that arrives only by email is already outside recommended practice.
- Source the phone number independently. Use the engagement letter, the firm's website you navigated to yourself, or the licence register. Never the signature block of the email you are checking, because a compromised mailbox can rewrite a signature.
- Verify by voice before every transfer. Ask for the person handling your matter by name, then read the BSB and account number out digit by digit. Never ask "are these details correct", because a yes to a leading question tells you nothing.
- Treat any change of details as fraud until proven otherwise. An unannounced change in settlement week is the single strongest signal in this attack.
- Never accept new details communicated only by email. Not a PDF on letterhead, not a scanned signature, not a second email confirming the first. All three come from the same mailbox.
- Send a small test transfer. Push $1 or $100, then phone the office and have them confirm it landed before you send the balance. It caps your worst case at the test amount.
- Use Confirmation of Payee and take a no-match seriously. It is live across more than 100 Australian institutions and, on Australian Payments Plus figures, has been used more than 150 million times since July 2025. A no-match on details you were emailed ends the transfer. It is not a prompt to try again.
- Record what you did. Who you called, on what number, at what time, and what they confirmed. If liability is contested later, that record is your evidence.
Two cautions. Confirmation of Payee is advisory and domestic-only, and a trust account name often differs from what you type, producing a close match people wave through. And if you are buying with others, agree who initiates and who verifies when you set up the co-buying arrangement.
Bank cheque, PEXA Key or bank transfer
PEXA Key is the safer electronic route, because the details reach you inside the app rather than as text in an email, and it is the only channel covered by PEXA's Secure Communication Guarantee. If your practitioner offers it, use it, and treat any bank details arriving by email afterwards as fraudulent. A bank cheque cannot be redirected by an email at all, though many firms no longer accept them. A plain bank transfer on emailed details is the exposed option, and it is still the most common one.
A buyer's agent cannot stop this for you. The money moves between you, your bank and your conveyancer's trust account, and no agent is a party to that transfer. What an experienced buyer's agent can do is tell you which local firms verify by phone as a matter of course, and push back on a settlement timetable so tight you would feel pressured to skip the call. If you already have a conveyancer you trust and ten minutes to make one call, you do not need anyone else for this step. If you want that local knowledge, GoMatch can connect you with agents who settle every week.
Red flags in a fake settlement email
- Bank details differing in any respect from your engagement letter
- A sender address you have to squint at, usually a doubled letter or a changed domain suffix
- Urgency that was not there yesterday, such as settlement failing or penalty interest starting today
- A reply-to address that differs from the from address
- A staff name you have not dealt with, or a familiar name writing in an unfamiliar register
- Any instruction not to call, because the office is busy or the person is in court
PEXA found 66 per cent of the Australians it surveyed would meet their agent or conveyancer in person before sharing bank account details, well ahead of the 18 per cent who would use a phone call. Six in ten were aware of AI voice cloning scams, and among those intending to buy, 65 per cent were concerned or very concerned about them. That is why you ring a number you sourced yourself: anyone can ring you, but only the real firm answers its own published line. Voice cloning is the part of the AI shift in property that will reach you first.
What to do if you have already paid a scammer
Why a settlement transfer cannot simply be reversed
Most settlement payments now travel over the New Payments Platform and clear in seconds. There is no chargeback and no unilateral reversal. Your bank can only ask the receiving bank to freeze whatever is still sitting there, and receiving accounts are typically emptied within hours. Everything that actually protects you happens before you press send.
- Call your bank's fraud line first, before anyone else, and ask for a recall through the Fraud Reporting Exchange, which lets banks trace a transaction between institutions in near real time.
- Report to ReportCyber. The report routes straight to the relevant police jurisdiction. Record the reference beginning "CIRS-", because your bank and insurer will ask for it. The Australian Cyber Security Hotline is 1300 292 371.
- Report to Scamwatch so the loss lands in national data, and contact IDCARE for a free recovery plan.
- Notify the practitioner by phone, not email, since their mailbox may be the compromised one. Ask them to tell their indemnity insurer and regulator today.
- Engage your own lawyer, separate from the practitioner in the transaction, and ask your insurer in writing what is covered.
Recovery happens but is not typical, and it depends almost entirely on whether the funds are still sitting in the receiving account. One more caution: people who have just lost money get approached again by criminals offering to recover it. Treat any unsolicited offer of help as a second scam.
Who is liable if you pay a scammer at settlement
Liability turns on whose system was compromised and whether each party verified. The safety nets people assume exist mostly do not.
| Protection | What it actually does | Covers a spoofed email transfer? |
|---|---|---|
| ePayments Code | Recovery for mistaken internet payments | No. The mistaken internet payment provisions state they are "not intended to cover situations in which the user transfers funds to the recipient as a result of a scam" |
| Confirmation of Payee | Name checking on first-time and edited payees | Partly. The ABA calls it "an advisory checkpoint, not a hard block" |
| PEXA Key Secure Communication Guarantee | Up to $2 million per residential settlement where details sent through PEXA Key were corrupted | No, if you paid on an email that never went through PEXA Key. It excludes claims where you were responsible for the misdirected payment |
| Fidelity Fund (Vic), administered by VLSB+C | Compensates for dishonesty by a lawyer | No. VLSB+C states it "will not provide compensation, even if the funds were held in trust" |
| Mandatory bank reimbursement | Requires banks overseas to repay authorised push payment fraud | Not in Australia. There is no mandatory reimbursement scheme here |
| Scams Prevention Framework | Banking, telecommunications and digital platforms designated 28 May 2026 | Not yet. Sector code obligations with civil penalties are still to commence |
Contrast that with card fraud, where the ABS found 75 per cent of victims received a reimbursement in 2024-25, and 72 per cent were reimbursed in full. A push payment you authorised sits in a different category.
Suing the practitioner is not simple either. A negligence claim has to establish what a reasonable firm should have done, usually with expert evidence about industry standards, and most conveyancing practices now carry a cybersecurity warning on every outgoing email precisely so they can point to it later. That is general information rather than legal advice, and it is why the record you kept at step 8 matters. It is the only contemporaneous evidence that you verified.
What these figures cannot tell you
These are national aggregates, not your transaction. The PEXA Settlement Scams Index is industry research from a company that sells settlement infrastructure, which does not make it wrong, only interested.
Figures move. The most recent business email compromise total ASD has published covers 2023-24: almost $84 million across more than 1,400 loss reports, an average above $55,000. That is not a current-year number, though you will see it presented as one.
Liability is fact-specific. Get advice from a lawyer who is not the practitioner handling your purchase, and ask your insurer in writing before you need the answer.
FAQ: settlement payment scams
Can I get my money back if I send my house deposit to a scammer?
Sometimes, and only if you move within hours. Call your bank's fraud line first so it can attempt a recall through the Fraud Reporting Exchange. There is no mandatory reimbursement scheme in Australia, and the ePayments Code expressly excludes scam-induced payments from its mistaken payment protections. Recovery depends almost entirely on whether the funds are still sitting in the receiving account.
Who is liable if my conveyancer's email was hacked and I paid the wrong account?
Usually the buyer wears the loss. Liability turns on whose system failed and whether each party verified, and a firm that puts a cybersecurity warning on every outgoing email is in a stronger position when a client pays contrary to it. Fidelity funds are generally directed at dishonesty by a legal practitioner rather than by an outside criminal. Get your own lawyer, not the one acting in the purchase.
Does Confirmation of Payee stop settlement scams?
It helps, and it does not stop them. The Australian Banking Association calls it "an advisory checkpoint, not a hard block". It fires on first-time and edited payees, returns match, close match or no match, and lets you proceed anyway, on domestic payments only. Since trust account names rarely match what you type, the answer you usually get is the one that tells you least.
Should I send a small test transfer before paying the settlement amount?
Yes. Send $1 or $100, then phone the firm on a number you sourced independently and confirm it landed in the correct trust account before releasing the balance. Build an extra hour into your settlement timing for it. It is the cheapest control in this article, and the most you can lose running it is a dollar.
Protecting your settlement in 2026
Settlements in a falling market get done under time pressure, and that is the environment in which an urgent email about updated bank details reads as entirely normal.
Everything else in your purchase has a professional watching it. From 1 July 2026 real estate professionals, conveyancers and lawyers are regulated by AUSTRAC, which means identity checks where they provide a designated service, and source-of-funds enquiries where the risk assessment calls for them. Your lender checks your servicing. The one step with no institutional guardian is the moment you type a BSB into your banking app and press send.
So make the call. Every transfer, on a number you found yourself. Read the digits out loud. It takes a few minutes, and it is the one control in this article that no institution will apply on your behalf.
Sources
- National Anti-Scam Centre (ACCC), "Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025". Published March 2026.
- Australian Signals Directorate, "Annual Cyber Threat Report 2023-24", 20 November 2024, and ACSC alert "Property-related business email compromise scams rising in Australia", 30 August 2021.
- PEXA Group, "Settlement Scams Index 2026", and PEXA Key Secure Communication Guarantee terms. 2026.
- ASIC, ePayments Code, Chapter D (mistaken internet payments), effective 2 June 2022, and Australian Banking Association, "Confirmation of Payee" FAQ.
- Australian Payments Plus, "Businesses come on board as Confirmation of Payee enters its second year", 8 July 2026.
- Australian Bureau of Statistics, "Total Value of Dwellings, March quarter 2026", released 9 June 2026, and "Personal Fraud, 2024-25", released 12 March 2026.
- Revenue NSW, "Who pays transfer duty and when", updated 27 May 2026; AUSTRAC, "About the AML/CTF reforms"; and The Hon Dr Daniel Mulino MP, "Albanese Government steps up industry protections to stop scams", 28 May 2026.
- Legal Practitioners' Liability Committee, "Call before you pay", updated 11 June 2026; Victorian Legal Services Board and Commissioner, "Cybercrime: a growing threat to lawyers and clients", 27 June 2018; and Westpac newsroom, "Westpac banker's instinct saves customer from $1.2 million scam", 6 August 2026.



