
Of all the risks conveyancers deal with, Friday afternoon fraud is one of the most damaging. It does not rely on a defect in title or a missed search result. It relies on a single email arriving at the right moment with the wrong bank details.
Here is how it works, why the name undersells it, and what firms can do to stop it.
What is Friday afternoon fraud?
It is a form of payment diversion fraud. Criminals intercept and redirect legitimate property purchase funds by impersonating solicitors, estate agents or buyers. The aim is simple: persuade someone to send a deposit, completion monies or sale proceeds to an account the fraudster controls.
The numbers show why it persists. Between April 2024 and March 2025, 143 cases of conveyancing fraud were reported to Action Fraud, with losses of £11.7 million. The average loss was around £82,000, and victims were noticeably younger than for many frauds, with 32% aged 40–49 and 27% aged 30–39. For a first-time buyer, that is often everything they have saved.
Why Friday, and why does the name undersell it?
The name comes from timing. Completions often happen on a Friday, and the weekend buys criminals time to avoid detection. By the time anyone notices on Monday, the money has usually been moved on.
The name is also a little misleading, because it can happen on any day. The real pattern is not the day of the week. The scams are timed for the final stages of a transaction, when large sums are expected to move quickly. That can mean exchange, a deposit request or the release of sale proceeds, as well as completion.
How does the attack work?
There are two common routes. The fraudster either takes over a genuine email account or spoofs one with a lookalike domain, then sends “updated” bank details. A hijacked account is the more dangerous of the two, because the email really does come from the right address.
Compromised mailboxes are rarely used straight away. The fraudster will often read along for weeks, learning the matter, the names involved and the tone of the correspondence. The fake request then arrives at exactly the point a client is expecting to pay.
The weak point is not always the firm. Sometimes the solicitor has been hacked, but often the homebuyer has fallen for a phishing attack. That is why client education matters as much as internal security.
What are the warning signs?
Most fraudulent requests share a few features:
- Bank details that change, or arrive for the first time, late in the transaction.
- Small alterations to names, email addresses or company details, such as ‘m’ swapped for ‘rn’.
- A reply-to address that differs from the sender address.
- Pressure to pay quickly, often with a warning that any delay will cost the client the property.
- An account name or bank that does not fit the firm.
None of these is conclusive on its own. Together, they are a reason to stop and check.
What should firms have in place?
The most effective control is a simple rule: bank details are never changed by email. Give clients the firm’s account details at the start, in the client care letter and ideally by a second route. Tell them plainly that the firm will never change them by email.
The NCA and Law Society guidance for property transactions comes down to three steps. Call before transferring money, because emails can be intercepted. Send a small test sum and confirm it has arrived. Do not transfer anything until you are satisfied the details are correct. The call has to go to a number already held on file, never one given in the suspicious email.
Beyond that, firms can:
- Use multi-factor authentication on every mailbox.
- Train staff to treat any change of payment details as a potential fraud until proven otherwise.
- Put a fraud warning in email signatures and client care letters.
- Use Confirmation of Payee checks as an extra layer, but not as the only one.
The same discipline applies in the other direction. When a seller client emails asking for proceeds to go to a new account, it deserves the same scrutiny as a buyer being asked to pay.
What happens if money goes to the wrong account?
Speed is everything. Contact the sending bank immediately, because the chances of recovery fall with every hour. The incident should also be reported to the national fraud reporting service.
Firms have regulatory duties too. In one case, an experienced solicitor was fined £10,000 and ordered to pay £16,000 in costs after being tricked into transferring more than £290,000 to a hacker. There was no dishonesty, but the SRA expects such cases to be reported, even where the stolen money has been replaced.
Friday afternoon fraud succeeds because it exploits the moment a transaction is most exposed: large sums, tight deadlines and clients who are expecting to pay. The technology behind it can be sophisticated, but the defence is not. A clear rule that bank details are never changed by email, backed by a phone call to a known number, stops most attacks.
The firms that avoid losses are rarely the ones with the most advanced systems. They are the ones where every member of staff, and every client, knows to stop when payment details change and to check before anything moves.




