PIPropertyITBUILDING TECHNOLOGY
Field guide / Security

Payment-Change Fraud in Property Management: Controls That Stop a Six-Figure Mistake

How fraudsters target rent, owner distributions and contractor payments, and the call-back, approval and email controls that property firms should have.

  • By Ali Sedighi, MBA
  • Reviewed 2026-10-06
  • 5 min read

Property firms move money on behalf of other people. They collect rent, hold deposits, pay contractors and distribute funds to owners, often in large amounts and under time pressure. That makes them a favourite target for payment-change fraud, where an attacker impersonates a vendor, an owner or an executive and asks for banking details to be changed. The losses can run to six figures, and the recovery rate is poor. The controls that stop it are not expensive, but they must be written down and followed every time.

How the fraud works

A common pattern begins with a compromised email account at a contractor, a lawyer or an owner. The attacker reads the conversation, waits for an invoice and then sends a polite message from a lookalike address asking to update the bank details. The accounts payable clerk, seeing a familiar thread, makes the change.

Variations include impersonating a senior executive who needs an urgent transfer, a tenant changing automatic payments and an owner requesting that distributions be redirected. Generative tools now make the messages fluent and convincing.

The call-back rule

The single most effective control is a call-back on every change of banking details. Call the payee on a number you already hold, not on the number in the email. Confirm the change with someone you know, record who you spoke to and the time, and only then update the record.

Make the rule absolute. Exceptions are what the fraudster is looking for. Staff should be praised, not criticised, for pausing a payment to make the call.

Separation of duties

No single person should be able to change a payee's bank details and approve the payment. Use two people: one who maintains vendor and owner records, another who authorises payments. Set payment limits above which a second approver is required, and require extra scrutiny for first payments to a new account.

In small firms this can be difficult, but even a simple two-signature approach on bank changes provides real protection.

Locking down email

Most fraud starts with a stolen password. Enforce multi-factor authentication on every mailbox, disable legacy sign-in methods and review mailbox rules for hidden forwarding. Configure email authentication, with SPF, DKIM and DMARC, so that messages impersonating your domain are rejected.

Warn staff when email comes from outside the organisation, and flag newly registered or lookalike domains. These measures do not catch everything, but they make the easy attacks harder.

Tenant and owner portals

Rent and distributions are also at risk when portals are poorly protected. Use strong authentication for tenant, owner and vendor portals, notify account holders whenever banking details change and apply a waiting period before a changed account receives its first payment.

Monitor for unusual patterns such as several accounts changed in a short period, or changes originating from the same device.

Training that sticks

Short, regular sessions beat annual lectures. Use real examples, including lookalike invoices and urgent executive requests, and run simulated phishing tests to see who clicks. Make sure everyone knows the call-back rule and how to escalate.

Include front-desk and site staff, who may be targeted with requests to redirect parcels, reset passwords or issue access credentials.

If the worst happens

Speed matters. If a fraudulent payment is discovered, call the bank immediately to request a recall, notify the police and your insurer and preserve the email evidence. Change passwords and review the compromised account for other activity.

Have this plan written before you need it, with phone numbers for your bank's fraud desk. Every hour of delay reduces the chance of recovery.

Checklist

  • Require a call-back, to a known number, for every change in banking details
  • Separate the person who edits payee records from the person who approves payments
  • Set payment limits and require a second approver above them
  • Enforce multi-factor authentication on all mailboxes and portals
  • Configure SPF, DKIM and DMARC for your domains
  • Notify account holders when banking details change
  • Run short, regular fraud-awareness training with simulated phishing
  • Write and rehearse a response plan with your bank's fraud contact

Where this lands by property type

Property Management Companies

A management company sells reliability to owners. Its own systems, from the ledger to the after-hours phone line, are the product, and every outage is seen by clients who pay for calm. Typical exposure: head office and site offices on different standards.

REITs & Asset Managers

REITs and asset managers answer to unit holders, lenders and auditors. Technology risk across the portfolio sits inside that accountability, even when each building is run by someone else. Typical exposure: property managers using different systems with different controls.

Commercial Landlords

Commercial landlords compete on building quality: reliable connectivity, secure access and a smooth fit-out process. Technology gaps show up in vacancy and renewal rates. Typical exposure: tenants asking for connectivity options the building cannot provide.

Next step: a building technology survey

PropertyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery for property teams. If this article describes a situation in your buildings, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-language view of your options, and a fixed-price scope if you want one. No lock-in, no pressure and no obligation.

Frequently asked questions

Does multi-factor authentication stop this fraud?

It stops many account takeovers, which are the root of the problem, but not every impersonation. The call-back rule is the key backstop.

Will cyber insurance cover a fraudulent transfer?

Coverage varies and often requires specific controls. Read your policy and ask your broker about social-engineering and funds-transfer cover.

What is the first thing to do after a fraudulent payment?

Call your bank immediately and ask for a recall, then notify police and your insurer and preserve the emails.

Can PropertyIT review our payment controls?

Yes. Our portfolio cybersecurity assessments include email, identity and payment-process controls with a ranked remediation plan.

Call (604) 632-4959Email [email protected]Book a consultation