Every property transaction is built on trust.
Each day, practitioners, lenders, financial institutions, government agencies and technology providers work together to help Australians complete one of the most significant financial decisions of their lives. While the industry has undergone a remarkable digital transformation over the past decade, maintaining continued confidence in that system requires more than secure technology alone. It requires a shared commitment to protecting the people, processes and relationships that underpin every transaction.
Recent media coverage of an attempted payment redirection scam during a residential property purchase serves as a timely reminder that cyber criminals continue to target the property industry. The specifics of any one incident matter less than the broader pattern it represents. As digital services continue to evolve, so too do the methods used by those seeking to exploit them.
The encouraging news is that our industry has never been better positioned to respond.
Cyber criminals are targeting people, not platforms
The Australian property industry has made significant progress in strengthening the security of digital property transactions. Today’s settlement process is more transparent, auditable and resilient than the paper-based processes it replaced. Entire categories of risk have been removed through secure digital platforms, stronger identity controls and improved governance.
As these protections have matured, attackers have adapted.
Rather than attempting to compromise well-governed platforms directly, cyber criminals increasingly focus on people and business processes. Their objective is not to break sophisticated technology, it is to exploit trust, create urgency and persuade someone to act before they have an opportunity to verify.
Business Email Compromise (BEC) and payment redirection fraud remain among the most effective techniques because they rely on human behaviour rather than technical vulnerabilities. In many cases, attackers patiently observe legitimate communications, understand normal business processes and strike only when the timing is right. The result is that what may appear to be a routine request can, in reality, be a carefully orchestrated attempt to redirect funds.
Emerging technologies are adding another dimension to this challenge. AI-enabled voice cloning and deepfake technologies can make impersonation attempts increasingly convincing, potentially making a fraudulent request appear to come from a trusted client, colleague or business contact. This reinforces the importance of relying on established verification processes rather than familiarity with a voice, email or incoming call alone.

Why property transactions remain attractive targets
Property transactions present a unique combination of characteristics that make them attractive to organised criminal groups.
They involve significant financial value, multiple organisations, strict settlement timeframes and numerous exchanges of information between trusted parties. For many Australians, buying or selling property is an infrequent experience, which means they have limited opportunity to recognise when something doesn’t seem quite right.

This complexity is not a weakness, it is simply the nature of modern property transactions. However, it does mean that maintaining trust depends on every participant playing their part.
Importantly, cyber security is no longer solely about protecting individual organisations. It is about protecting the confidence Australians place in the property ecosystem as a whole.
Security is a shared responsibility
One of the defining characteristics of the Australian property industry is the extent of collaboration required to complete every transaction.
Technology providers, practitioners, lenders, financial institutions, government agencies and customers each contribute to a successful outcome. That same collaboration is equally important in strengthening cyber resilience.
No single organisation can eliminate cybercrime on its own.
Secure technology provides a strong foundation by removing many traditional risks from the settlement process. Effective governance strengthens that foundation through clear responsibilities, secure access management, supplier assurance and well-defined operational controls.
The final element is culture.
Policies and procedures are important, but they are only effective when people feel empowered to use them. Organisations that encourage staff to pause, question unusual requests, and independently verify payment instructions create an environment where secure decisions become routine rather than exceptional.
Good security culture is not built on suspicion, it is built on confidence that taking a moment to verify is always the right decision.
Practical steps that strengthen resilience
While cyber threats continue to evolve, many of the most effective controls remain straightforward and practical.
Verify changes to payment instructions independently. Any request to change bank account details should always be confirmed through an established verification process, using trusted contact information already on file, not details contained within the email, message or incoming call requesting the change.
Treat urgency as a reason to verify, not a reason to hurry. Settlement deadlines are important, but they should never override established security processes. Time pressure is precisely what cyber criminals seek to exploit.
Protect digital identities and access. Multi-factor authentication, strong credential management and the protection of digital signing certificates remain among the most effective controls available to organisations.
Maintain strong cyber hygiene. Regular patching, supported systems, appropriate user access reviews and ongoing monitoring significantly reduce opportunities for attackers to gain an initial foothold.
Build confidence through education. Regular cyber awareness training helps people recognise emerging threats, but equally important is fostering a workplace culture where verifying an unusual request is encouraged and expected.
None of these measures are particularly complex. Their strength lies in being applied collectively and consistently across every transaction.
Protecting trust together
Trust has always been fundamental to Australia’s property market.
While cyber criminals will continue to evolve their methods, our collective ability to respond continues to strengthen. Secure technology, effective governance, informed practitioners and collaborative partnerships all contribute to a more resilient property ecosystem.
At PEXA, we believe protecting trust is a shared responsibility. We remain committed to investing in secure, resilient technology while supporting practitioners with practical guidance that helps them strengthen their own cyber resilience.
The future of digital property transactions depends not only on innovation, but on continuing to work together to protect the confidence Australians place in our industry every day.
Learn more
PEXA provides a range of cyber security resources and Subscriber Security Policy materials to help practitioners strengthen everyday cyber practices. To help recognise potential scams, strengthen their cyber security practices and protect themselves during property transactions, PEXA has also launched the PEXA Security Hub.
The hub features practical guidance and the second annual Settlement Scams Index by PEXA, which examines consumer awareness and detection of property settlement scams.
We encourage all subscribers to regularly review their security practices and remain vigilant against evolving cyber threats.
For more information, visit the PEXA Security resources or contact security@pexa.com.au if you encounter suspicious activity.




