Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT Support for Estate Agents in the UK

In short

Estate agents handle client money, AML paperwork and large sums moving between buyers, sellers and solicitors, which makes them a prime target for fraud. This guide covers protecting client and AML data, working securely with property portals, stopping email fraud on deposits and completions, and keeping agents safe while working from phones and out on viewings.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

An industry built on trust, and on moving money

Estate agency runs on two things criminals love: personal data and large payments. In a single transaction you might handle a buyer’s and seller’s identity documents, anti-money-laundering (AML) checks, mortgage details, and payment instructions for deposits and completion sums that run into hundreds of thousands of pounds.

That combination puts a target on the profession. Attackers do not need to break into a vault; they just need to be in the right email conversation at the right moment. This guide sets out, in plain English, how to protect your clients, your firm and your reputation.

Client money and AML data: your biggest responsibility

Every estate agent is legally required to carry out AML checks, which means you collect and store some of the most sensitive information a person has: passports, driving licences, proof of address and details of where funds have come from. Losing control of that data is both a compliance failure and a gift to identity thieves.

A few principles keep this data safe:

  • Store it in secure, access-controlled systems, not scattered across inboxes, personal phones and desktop folders.
  • Limit who can see it. A negotiator does not need access to every client’s full AML file. Give people access to what their role requires.
  • Keep records only as long as you need them, then dispose of them securely, in line with your AML and data protection obligations.

If data protection feels like a maze, our GDPR basics for UK small business explains your duties without the legal jargon.

The big one: deposit and completion fraud

This is the threat every agent should understand, because it is common, costly and often devastating for the client.

Here is how it typically works. A criminal quietly gains access to, or convincingly spoofs, an email account involved in a transaction, perhaps the buyer’s, the agent’s or the solicitor’s. They watch the conversation until a large payment is due. Then, at exactly the right moment, they send a message that looks completely genuine, referencing the real property and the real sums, but with one change: new bank details. The buyer pays their deposit or completion money straight into the fraudster’s account, and by the time anyone notices, it is usually gone.

Attackers do not need to break into a vault; they just need to be in the right email conversation at the right moment.

Defending against this takes both people and technology.

People. Agree a firm-wide rule, and tell clients about it up front, that bank details will never be sent or changed by email, and that any payment instruction must be verified by phone using a number held on file, never a number supplied in the email itself. A thirty-second call has saved countless buyers a life-changing loss.

Technology. Protect your own email domain so criminals cannot easily impersonate your address. The three standards that do this are SPF, DKIM and DMARC, and our guide on how to stop invoice fraud and email spoofing with SPF, DKIM and DMARC explains them for non-technical readers. This is closely related to a wider threat known as business email compromise, covered in business email compromise (BEC) explained.

Locking down email in the first place

Almost all of this fraud depends on someone’s email account being accessed or trusted when it should not be. So the foundations matter.

Turn on multi-factor authentication (MFA) for every email account in the firm. This is the strongest single defence against account takeover, because even a stolen password is not enough to get in. Cyber Essentials already requires MFA on all cloud services, so it is now the expected baseline rather than a nice-to-have. See multi-factor authentication explained for the how.

Back that up with a password manager so every agent uses long, unique passwords instead of reusing the same one across the CRM, the portals and their email. Our best password manager for small business rundown compares the options.

And because these attacks arrive as convincing messages, train your team to recognise them. How to spot a phishing email is worth ten minutes in a team meeting.

Working with portals: Rightmove, Zoopla and your CRM

Estate agents live in portals and cloud systems all day, and each one is an account worth protecting. A hijacked Rightmove or CRM login can be used to post fake listings, harvest applicant data or gather details for the next scam.

Sensible habits:

  • Use a unique password and MFA on every portal and CRM account.
  • Never share logins between staff. Individual accounts mean you always know who did what, and you can cut off access instantly when someone leaves.
  • Remove access promptly when a negotiator moves on. A leaver with a live login is a real risk.

Mobile working, done safely

Estate agency is not a desk job. Agents are out on valuations and viewings, checking messages between appointments and pulling up applicant details on the move. That mobility is a strength, but it needs a safety net.

  • Encrypt and lock every device. Phones and laptops should require a PIN or biometrics and have full-device encryption switched on, so a lost handset does not become a data breach.
  • Enable remote wipe. If a device is lost or stolen, you should be able to erase it remotely. This is standard in Microsoft 365 and similar business platforms.
  • Keep work data in the cloud, not just on the device. If the phone is gone but the data lives in secure cloud systems, nothing is lost.
  • Be careful on public Wi-Fi. Cafe and station networks are convenient but not private. A reputable VPN, such as Proton VPN, encrypts your connection so listings, logins and client details cannot be snooped on while you work between viewings.

Also remember that Windows 10 support ended on 14 October 2025, so any office machines still running it should be moved to a supported system to keep receiving security updates.

Back up so a bad day is only a bad day

Between CRM records, valuation photos, contracts and AML files, agents accumulate a lot of important data. Ransomware, a failed drive or a simple mistake could wipe it out. The 3-2-1 approach, three copies, on two types of storage, one off-site, keeps you trading through almost anything. Our business backups and 3-2-1 guide sets it out simply.

Bringing it together

Estate agents do not need to become IT experts. You need a handful of reliable defences: MFA on everything, protected email that criminals cannot easily spoof, a strict phone-verify rule on all payment details, secure and access-controlled storage for AML data, well-managed portal logins, and safe mobile working. Get those right and you have closed the doors criminals rely on.

If you would like this handled for you, so your team can focus on selling and letting rather than security, we offer managed IT support and cyber security for estate agents across Leeds and Yorkshire. Get in touch for a straightforward conversation about protecting your firm and your clients.

Frequently asked questions

Why are estate agents such a common target for cyber criminals?

Because money and data flow through you constantly. You hold identity and AML documents, you sit in the middle of high-value property transactions, and completion sums move between buyers, sellers, agents and solicitors. If a criminal can intercept an email and redirect a deposit or completion payment, the amounts are large and often unrecoverable, which makes agents a very attractive target.

What is completion and deposit fraud?

It is when a criminal impersonates a party in a property transaction, often by compromising or spoofing an email account, and sends fake bank details at the moment a large payment is due. The buyer pays the deposit or completion money into the fraudster's account instead of the genuine one. The email usually looks entirely legitimate because it references real, current transaction details.

How do we protect payment details from being tampered with?

Agree a rule that bank details are never changed by email, and that any payment instruction is confirmed by phone using a number held on file, not one from the email. Technically, protecting your own email domain with SPF, DKIM and DMARC makes it far harder for criminals to spoof your address. Multi-factor authentication on email stops accounts being taken over in the first place.

Is it safe to access Rightmove and other portals on the move?

It can be, with a few precautions. Use strong, unique passwords and multi-factor authentication on every portal and CRM account, keep phones and laptops updated and locked with a PIN or biometrics, and avoid logging in over untrusted public Wi-Fi without a VPN. Never share a single login between staff, so you always know who did what.

What happens to our data if a phone or laptop is lost?

With the right setup, very little. Devices should be encrypted, protected by a PIN or biometrics, and set up so they can be remotely wiped if lost or stolen. Data should live in secure cloud systems rather than only on the device, and everything should be backed up. Get this right and a lost phone is an inconvenience, not a data breach.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.