How Irish solicitors can stop conveyancing email and bank-detail fraud

Practical steps for Irish solicitors to stop conveyancing fraud: bank-detail checks, Microsoft 365 hardening, email security and what to do if money goes.

The short answer: most conveyancing fraud starts with an email that changes bank details. So treat any new IBAN or BIC as a red flag. Verify it by phone on a number you already hold. Then make sure the person sending the money is the one who checks. Behind that habit, protect every mailbox with multi-factor authentication (MFA). Also watch for hidden forwarding rules, and train everyone who can move client money.

This guide is for principals and practice managers in small and mid-sized firms in Meath, Cavan, Westmeath, Louth and Dublin. It covers payments and email. For sending documents safely, see our guide to secure file sharing for law firms.

Why conveyancing fraud keeps targeting Irish law firms

A sale or remortgage brings large transfers, tight deadlines and a long chain of emails. That makes conveyancing fraud worth a criminal’s time. The Law Society’s practice note on spear phishing describes criminals intercepting an email and changing only the IBAN and BIC. They may also forge an internal email, for example from a partner to a secretary.

The problem isn’t limited to law firms, either. FraudSMART, led by Banking & Payments Federation Ireland, reported that SMEs lost €9.9m through email-related fraud in 2023. Most cases were invoice-redirection scams.

For solicitors, the stakes are personal. According to the Law Society, any client account deficit is the personal responsibility of the partners or principal. That applies even when the firm is a victim of cybercrime.

Payment checks that stop conveyancing fraud

Technology helps, but the payment check does the heavy lifting. Based on the Law Society’s spear-phishing tips, a written firm rule might say:

  • Any change of bank details is a red flag, whoever it seems to come from.
  • IBANs and BICs received by email get a phone call to verify them, with a memo on the file.
  • Calls go to a number you already hold or find independently, never one from the email.
  • Internal emails asking for a transfer are also checked by phone with the sender.
  • Clients hear early that your firm doesn’t change its bank details by email, if that’s true for you.

The Law Society has also warned that criminals can alter verified details in a later internal email. That’s why the person making the transfer should do the check themselves. In addition, the NCSC recommends dual approval for payments over a set threshold.

Contracts matter too. The Conveyancing Committee suggests not including client account numbers in full, for example by redacting the last four digits.

Harden Microsoft 365 against mailbox takeover

Many attacks begin with a stolen password. The Law Society describes fraudsters setting up a rule that forwards every email to themselves without the owner knowing. As a result, they can read client bank details, passports and closing dates as they arrive.

To make conveyancing fraud harder, the NCSC’s business email compromise guidance recommends:

  • MFA on all email accounts, including partners and shared mailboxes.
  • SPF, DKIM and DMARC on your domains, so others find it harder to spoof you.
  • Regular checks for suspicious forwarding rules.
  • Email filtering that flags anomalies.

Keep administrator accounts separate from everyday ones, too. The NCSC’s Office 365 secure configuration framework is a useful checklist for the rest.

Email security and staff awareness

Basic spam filters catch a lot, but not every convincing impersonation. Dedicated email security adds another layer against conveyancing fraud. Even so, people remain the last check. Short, regular training should include partners, fee earners, secretaries and accounts staff, because attackers aim at whoever can move money.

What to do if conveyancing fraud gets through

Speed matters once a payment has gone, so agree these steps now:

  • Contact your bank straight away to try to stop or recall the payment.
  • Report it to your local Garda station, with copies of the emails, as An Garda Síochána advises.
  • Notify your insurer immediately, as the Law Society’s note on cybercrime and PII recommends.
  • Ask your IT provider to change passwords, check forwarding rules and keep the evidence.

Hypothetical example

A conveyancing secretary in a Dundalk practice receives an email that seems to come from a client’s broker. It attaches “updated” account details for the balance. However, the firm’s rule says nobody uses emailed bank details until someone rings a number already on file. The call shows the broker sent nothing, so no money leaves the client account. Afterwards, IT checks the mailbox for forwarding rules.

A short agenda for your next partners’ meeting

Finally, a few points on conveyancing fraud to raise with the partners:

  • Confirm the written rule for bank-detail changes and who signs off payments.
  • Check MFA is on for every account, including principals.
  • Ask your IT provider whether email security and forwarding checks are in place.
  • Book a short phishing refresher before the next busy property period.
  • Agree who calls the bank, Gardaí and your insurer if something goes wrong.

How Sweeney Computer Services can help

We support solicitors and law firms across Meath, Cavan, Westmeath, Louth and Dublin from Hurdlestown, Kells, Co. Meath. Silver is from €45 per user per month excluding VAT. It covers remote support, monitoring, patching, antivirus, endpoint detection and response, and ransomware protection. It also includes Microsoft 365 backup. However, it doesn’t include email security, which matters most against conveyancing fraud.

Gold, from €70 per user per month excluding VAT, adds email security with advanced threat filtering and phishing awareness training. It also adds Microsoft 365 admin, leaked-password alerts and 24/7 security monitoring through our partner. Microsoft 365 licences are billed separately. Our helpdesk runs Monday to Friday, 9am to 5:30pm.

See our IT support for solicitors and law firms, along with our cybersecurity and Microsoft 365 services. We’re an IT company, not legal advisers, so check professional obligations with the Law Society or your own advisers.

more insights