Cyberattacks on UK property firms rise 17% as hackers target client data | Insurance Business
Cyberattacks on UK property firms rise 17% as hackers target client data
Conveyancing fraud cost buyers £11.7 million last year. Cyberattacks on agents are adding to the risk
Cyber
Cyberattacks against UK property services businesses rose 17% in the year to 31 December 2025, climbing to 208 incidents from 178 the previous year, according to figures sourced from the Information Commissioner’s Office and cited by Karis Insurance, a real estate finance and insurance specialist.
Ravi Sejpal, director of insurance at Karis Insurance, said property agents and buy-to-let property managers are becoming more attractive targets for hackers as they collect increasing volumes of personal data, while criminals are also aware that a high proportion of property clients are affluent or high-net-worth individuals.
What agents actually hold, and why it’s valuable
Property agencies routinely collect passports and driving licences for anti-money laundering and know-your-customer checks, proof of address, bank account details, mortgage information and tenancy records from buyers, sellers, landlords and tenants. That data has multiple criminal uses: it can be locked up in a ransomware attack until a business pays to regain access, used for identity theft against the individuals affected, or simply sold on the dark web.
Data linked specifically to property transactions carries an additional risk. Criminals who gain access to it can attempt payment diversion fraud, substituting their own bank details for a seller’s during a purchase. This isn’t a hypothetical: City of London Police and Action Fraud reported 143 cases of conveyancing fraud between April 2024 and March 2025, resulting in £11.7 million in losses, with the vast majority involving residential transactions and an average loss of £78,393 per case.
The fraud typically works by criminals gaining access to email chains between buyers, sellers, solicitors and agents, then impersonating a trusted party to redirect a deposit or completion payment, often timed to coincide with the final, time-pressured stage of a transaction. The National Crime Agency and the Law Society launched a joint awareness campaign targeting solicitors and conveyancers on this exact fraud type, describing it as “a serious and growing threat.”
Sejpal’s central argument
“In many cases, property businesses hold just as much detail about their client base as a bank would,” Sejpal said. “However there are very few businesses in the property sector who have bank-level data security arrangements.”
He said the personal data property agencies hold could be hugely valuable if it fell into the wrong hands, and that the rising attack figures show hackers are increasingly recognising that. He said the property industry has reached a point where specialist data breach insurance is critically important, contrasting it with financial services firms and law firms, which he said understood the risks posed by hackers long ago given the business-critical consequences for those affected. The property industry, he said, “hasn’t quite moved at the same pace in getting on top of the risks.”
A gap consistent with the wider SME cyber insurance market
Karis Insurance’s warning fits a broader, independently documented pattern of SME cyber underinsurance across the UK more generally. GlobalData’s 2025 UK SME Insurance Survey found cyber insurance penetration rising sharply with firm size, from 13.1% of sole traders holding cover to 63% of medium-sized firms, leaving smaller businesses, which often have the weakest cyber controls, the least protected.
Separately, the UK government’s Cyber Security Breaches Survey found 43% of businesses reported a cyber security breach or attack in the past 12 months, while research from Grant Thornton found 35% of UK SMEs carry no cyber insurance at all.
That underinsurance gap has real consequences when a breach does occur. The 2025 cyberattack on Marks & Spencer, which began through a third-party partner and went undetected for two days, disabled online operations and left the retailer facing estimated losses of up to £300 million, illustrating how quickly a single intrusion can escalate once it reaches a business’s core systems.
While property agencies operate at a very different scale to a major retailer, the underlying vulnerability, limited internal security resources relative to the sensitivity of the data held, is consistent with what Sejpal describes for the property sector specifically.
