Payment diversion is the fraud that most worries UK conveyancers, and with good reason. It works in the gap between two trusted parties, it is hard to spot from the inside, and the losses land at the worst possible moment: completion, when the largest sums in the transaction move.
This guide explains how the fraud happens, the warning signs that appear in practice, and the checks that stop money going to an account you did not intend to pay. It is written for conveyancers, so the language is practical and the controls are ones you can put in place this week.
Why payment diversion works
The fraud does not depend on hacking a bank or breaking encryption. It depends on a simpler failure: both parties assume the bank details they are holding are the correct ones.
In a property transaction the same details pass through many hands. The seller, the seller's solicitor, the buyer, the buyer's solicitor, the lender, the estate agent, and often a moving company or a managing agent all handle the account numbers that funds will travel to. Every copy is a point of trust. If a fraudster changes one copy that no one re-checks, the rest of the chain carries the wrong account all the way to the payment.
That is why the fraud is described as payment diversion rather than payment interception. The funds are not stolen in transit. They are diverted because the instruction itself was altered before it reached the person sending the money.
How a typical attack unfolds
Every case has its own details, but the shape is remarkably consistent. Understanding the four steps helps you know where to look.
Step 1: the compromise
Fraudsters get into an email account somewhere in the transaction chain. It is often a client's account, because client email is monitored less closely than firm email, but it can be an estate agent's, a moving company's, or occasionally a firm's. The entry is usually a phishing message, a credential leak, or an account reused across services. Nothing about the attack needs to be sophisticated to succeed.
Step 2: the planted message
Once inside the account, the fraudster reads the thread. They learn the names involved, the stage of the transaction, and the language the parties use with each other. They then plant a message that looks like a routine part of the existing conversation. This is the detail that makes the fraud believable: the message is not a cold email, it is a reply inside a real thread.
Step 3: the urgent change
The message carries a change. The most common versions are that the bank details have changed, that a different account should be used for this payment, or that funds need to go elsewhere because of a delay or a problem with the original account. The change is always urgent, and there is always a reason it must happen now. The urgency is the fraudster's engine: it discourages the checks that would normally apply.
Step 4: the completion payment
Completion arrives, the funds move to the account in the altered instruction, and the fraud is only discovered when the legitimate party asks where the money is. By then the funds have usually been moved on and broken up, and the realistic recovery rate is low. For the buyer and seller the loss is devastating. For the firm, the matter file becomes a dispute, and the professional indemnity claim follows.
The scale of the problem in numbers
Cifas reported 143 reported cases of payment diversion in property in a single year, worth £11.7 million, with an average loss of around £78,000 per case. Those are the reported figures. Conveyancers in practice will tell you that many attempted diversions are caught before completion, which means the figure understates how often the attack happens.
Two facts stand out. The first is that the risk concentrates at completion, when the largest sums move between buyer, seller, solicitor, and lender. The second is that the fraud works because the details are assumed correct. Both facts point to the same control: verify the receiving account before the funds move, as a deliberate step, not as a hope.
The warning signs to look for
Not every diversion can be spotted from the message alone, but a set of signals recurs often enough that they are worth teaching to every fee earner and legal assistant:
- Bank details that arrive as a change rather than as part of the original instructions
- A request that is time-pressured, with a penalty attached to any delay
- Details embedded in an email attachment or an image rather than in the body of the message
- A sender address that is a close misspelling of a known address
- A change that was not mentioned on the phone or in a meeting
- A client who suddenly cannot be reached by phone to confirm
The strongest single control is cheap: any change to bank details is confirmed with the account holder on a known, verified number, by voice, and recorded. If a firm only does this one thing, it closes the most common route the fraud uses.
The checks that stop it
A confirmation call handles the change of details. The wider risk needs a wider set of checks, and this is where the four-check structure comes in:
- Bank account verification. Confirm the receiving account is registered to the party you are paying. In the UK this is the logic of Confirmation of Payee: the account name, sort code, and account number are checked against the account held by the receiving bank.
- Document forensics. Review the documents behind the money: payslips, proof of funds, ID, and source-of-funds paperwork. The point is to find signs of tampering or AI generation before the transaction leans on them.
- Identity and media screening. Check the identity documents and any media provided for deepfake or AI-generated content, because a convincing false identity is the enabling step for many frauds.
- The confirmation call. Confirm the exact bank details with the account holder in their own words, recorded, so there is an artefact on the matter file.
Run together, these four checks cover the account, the documents, the people, and the confirmation. Each one on its own leaves a gap.
Building a repeatable control
The firms that defend against this fraud best treat verification as a repeatable control rather than a one-off favour. A repeatable control has three properties. It is documented, so anyone can see what was checked and when. It is consistent, so every matter gets the same treatment rather than whatever the fee earner remembered that day. And it produces an artefact, so there is something on the file that an insurer, an auditor, or a court can look at.
This is the argument for a signed verification report. It is not that a report proves the transaction is safe. It is that the report records exactly what was checked, when, and how, and it can be independently verified by anyone with the public link. A lender, an insurer, or a colleague can confirm the report is genuine and unaltered. That record is the difference between a firm that has a control and a firm that can prove it had one.
What to do if you suspect a diversion
If a client, a seller, or a lender reports that funds have not arrived, move quickly and keep the evidence intact:
- Stop any further payments immediately
- Contact the receiving bank and the sender's bank in the same call where possible
- Report to the police and to Action Fraud, and request a crime reference number
- Keep the compromised account intact for forensic review
- Notify your professional indemnity insurer at the first sign of a claim
- Record the full timeline, including who held which details and when they changed
Speed matters because the recovery window is short. The account that received the diverted funds is often emptied within hours, so the bank needs to act on the first call, not after a round of internal approvals.
Verification before the money moves
The pattern across all of this is consistent: the fraud succeeds when the receiving account is assumed rather than verified. The fix is to make verification a named, documented step that happens before completion funds move, for every matter, without exception.
Immutis runs the four checks for you, produces one signed verification report per matter, and gives you a public verify link that anyone can check against the published signing key. You can run it on a single matter or on every matter in the firm, and the report sits on the file ready for your lender, your insurer, and your audit.
If you want the practical detail behind the bank check specifically, read the next article in this series on Confirmation of Payee for conveyancers. It covers what the check does, what it does not do, and why it is not enough on its own.