Property cyber attacks climb as broker data piles up

Only 10% of UK businesses hold a standalone cyber policy, government survey finds

Property cyber attacks climb as broker data piles up

Cyber attacks against UK property services businesses rose 17% in the year to Dec. 31, 2025, according to Karis Insurance, a real estate finance and insurance specialist, which said reported attacks climbed to 208 from 178 a year earlier. The brokerage attributed the figures to the Information Commissioner's Office.

The claim lands in a market where the documents that move a mortgage case – passports, driving licences, proof of address, bank details and lender correspondence – sit in the same email chains and case-management systems that criminals target.

Karis Insurance said estate agents, surveyors and buy-to-let property managers are becoming more attractive targets because they collect more personal data than ever, and because their client lists carry a high proportion of affluent individuals.

What sits in the case file

Anti-money laundering and know-your-customer rules require identity documents to be collected and retained. Karis Insurance said property agencies now routinely hold passports, driving licences, proof of address, bank account details, mortgage information and tenancy records.

Ravi Sejpal, director of insurance at Karis Insurance, said property businesses often hold as much client detail as a bank. "However there are very few businesses in the property sector who have bank-level data security arrangements," Sejpal said.

The government's Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology and the Home Office on April 30, 2026, found 43% of UK businesses identified a breach or attack in the previous 12 months, equating to about 612,000 organisations. Phishing was the most prevalent attack type, reported by 38% of businesses, and was rated the most disruptive by 69% of those affected.

The same survey found 89% of finance or insurance businesses treated cyber security as a high priority, against 83% in the administration or real estate grouping.

Diverted completion funds

Compromised property data also feeds payment diversion fraud, in which criminals substitute their own bank details for a seller's or solicitor's.

City of London Police reported 143 cases of conveyancing fraud to Action Fraud between April 1, 2024 and March 31, 2025, producing £11.7 million in losses. Residential transactions accounted for 140 reports and £10.97 million, an average of £78,393 per case, while three commercial cases averaged £257,833. Victims were predominantly aged 30 to 49. The National Crime Agency, in a campaign run with the Law Society, put average losses for affected buyers at about £82,000 over the preceding year and urged solicitors and conveyancers to scrutinise payments more closely.

The agency advised buyers to send a small test payment first and to confirm account details directly with their solicitor.UK Finance recorded £41.3 million in invoice and mandate scam losses across 2,305 cases in 2025, down 4% and 2% respectively, in a category that includes criminals posing as conveyancing solicitors.

Cover and controls

The breaches survey found 47% of businesses held cyber cover in some form, but only 10% held a standalone cyber policy. Among businesses without cover, 39% said they were unaware such insurance existed and 34% said it was not a budgetary priority. Adoption of two-factor authentication stood at 47%, and 5% of businesses held Cyber Essentials certification.

Sejpal said the sector has reached a threshold on cover.

"The property industry has now reached a point where having specialist insurance for data breaches is critically important," he said.

Technology providers have issued parallel warnings to intermediaries. Mortgage Brain has advised brokers to enable multi-factor authentication, avoid reusing passwords, avoid emailing sensitive documents and refrain from entering client data into consumer AI tools. Cloë Atkinson, chief operating officer at Mortgage Brain, said brokers need to make data security non-negotiable.