Payment-Change Fraud in Property Management: Controls That Stop a Six-Figure Mistake
How fraudsters target rent, owner distributions and contractor payments, and the call-back, approval and email controls that property firms should have.
Property firms move money on behalf of other people. They collect rent, hold deposits, pay contractors and distribute funds to owners, often in large amounts and under time pressure. That makes them a favourite target for payment-change fraud, where an attacker impersonates a vendor, an owner or an executive and asks for banking details to be changed. The losses can run to six figures, and the recovery rate is poor. The controls that stop it are not expensive, but they must be written down and followed every time.
How the fraud works
A common pattern begins with a compromised email account at a contractor, a lawyer or an owner. The attacker reads the conversation, waits for an invoice and then sends a polite message from a lookalike address asking to update the bank details. The accounts payable clerk, seeing a familiar thread, makes the change.
Variations include impersonating a senior executive who needs an urgent transfer, a tenant changing automatic payments and an owner requesting that distributions be redirected. Generative tools now make the messages fluent and convincing.
The call-back rule
The single most effective control is a call-back on every change of banking details. Call the payee on a number you already hold, not on the number in the email. Confirm the change with someone you know, record who you spoke to and the time, and only then update the record.
Make the rule absolute. Exceptions are what the fraudster is looking for. Staff should be praised, not criticised, for pausing a payment to make the call.
Separation of duties
No single person should be able to change a payee's bank details and approve the payment. Use two people: one who maintains vendor and owner records, another who authorises payments. Set payment limits above which a second approver is required, and require extra scrutiny for first payments to a new account.
In small firms this can be difficult, but even a simple two-signature approach on bank changes provides real protection.
Locking down email
Most fraud starts with a stolen password. Enforce multi-factor authentication on every mailbox, disable legacy sign-in methods and review mailbox rules for hidden forwarding. Configure email authentication, with SPF, DKIM and DMARC, so that messages impersonating your domain are rejected.
Warn staff when email comes from outside the organisation, and flag newly registered or lookalike domains. These measures do not catch everything, but they make the easy attacks harder.
Tenant and owner portals
Rent and distributions are also at risk when portals are poorly protected. Use strong authentication for tenant, owner and vendor portals, notify account holders whenever banking details change and apply a waiting period before a changed account receives its first payment.
Monitor for unusual patterns such as several accounts changed in a short period, or changes originating from the same device.
Training that sticks
Short, regular sessions beat annual lectures. Use real examples, including lookalike invoices and urgent executive requests, and run simulated phishing tests to see who clicks. Make sure everyone knows the call-back rule and how to escalate.
Include front-desk and site staff, who may be targeted with requests to redirect parcels, reset passwords or issue access credentials.
If the worst happens
Speed matters. If a fraudulent payment is discovered, call the bank immediately to request a recall, notify the police and your insurer and preserve the email evidence. Change passwords and review the compromised account for other activity.
Have this plan written before you need it, with phone numbers for your bank's fraud desk. Every hour of delay reduces the chance of recovery.
Checklist
- Require a call-back, to a known number, for every change in banking details
- Separate the person who edits payee records from the person who approves payments
- Set payment limits and require a second approver above them
- Enforce multi-factor authentication on all mailboxes and portals
- Configure SPF, DKIM and DMARC for your domains
- Notify account holders when banking details change
- Run short, regular fraud-awareness training with simulated phishing
- Write and rehearse a response plan with your bank's fraud contact
Where this lands by property type
Property Management Companies
A management company sells reliability to owners. Its own systems, from the ledger to the after-hours phone line, are the product, and every outage is seen by clients who pay for calm. Typical exposure: head office and site offices on different standards.
REITs & Asset Managers
REITs and asset managers answer to unit holders, lenders and auditors. Technology risk across the portfolio sits inside that accountability, even when each building is run by someone else. Typical exposure: property managers using different systems with different controls.
Commercial Landlords
Commercial landlords compete on building quality: reliable connectivity, secure access and a smooth fit-out process. Technology gaps show up in vacancy and renewal rates. Typical exposure: tenants asking for connectivity options the building cannot provide.
Services that address this topic
Guidance like this works best inside a coordinated programme, not as a one-off fix. These PropertyIT services cover the topic directly.
Access Control & Video
Access Control & Video covers the readers, controllers, credentials, cameras and recorders that decide who enters a building and what is recorded when they do, along with the policies that govern both.
S / ConnectCommercial Office IT Fit-Outs
Commercial Office IT Fit-Outs coordinates the technology scope of a new or renovated suite, from cabling and rack layout to Wi-Fi, meeting rooms, telephony and the cutover from the old space.
S / SystemsMaintenance & Work-Order Systems
Maintenance & Work-Order Systems covers the selection, configuration and integration of tools that receive requests, dispatch technicians and vendors, track assets and feed costs into accounting.
Next step: a building technology survey
PropertyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery for property teams. If this article describes a situation in your buildings, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-language view of your options, and a fixed-price scope if you want one. No lock-in, no pressure and no obligation.
Frequently asked questions
Does multi-factor authentication stop this fraud?
It stops many account takeovers, which are the root of the problem, but not every impersonation. The call-back rule is the key backstop.
Will cyber insurance cover a fraudulent transfer?
Coverage varies and often requires specific controls. Read your policy and ask your broker about social-engineering and funds-transfer cover.
What is the first thing to do after a fraudulent payment?
Call your bank immediately and ask for a recall, then notify police and your insurer and preserve the emails.
Can PropertyIT review our payment controls?
Yes. Our portfolio cybersecurity assessments include email, identity and payment-process controls with a ranked remediation plan.