Why Conveyancing Firms in Surrey and the Home Counties Are Being Targeted by Cyber Criminals

A conveyancing solicitor reviewing documents at a desk with a laptop, representing cybersecurity risks facing law firms.

The Threat Is Closer Than You Think

Cyber fraud targeting conveyancing solicitors is not a distant, abstract risk. It is happening to firms of your size, in your region, right now.

Action Fraud data consistently shows that conveyancing transactions are among the most targeted financial events in the UK. The average loss from a single conveyancing fraud incident runs into tens of thousands of pounds — sometimes the entire proceeds of a property sale. The Solicitors Regulation Authority has repeatedly warned that smaller firms, particularly those without dedicated IT or security oversight, are disproportionately exposed. Surrey, Kent, Essex, and the wider Home Counties — areas where property values are high and transaction volumes significant — are attractive hunting grounds for organised cybercriminal groups who know exactly what to look for.

If your firm handles completions, transfers client funds, or exchanges sensitive identity documents over email, you are a target.

Why Conveyancing Firms Are So Vulnerable

Conveyancing practices have a specific combination of characteristics that make them valuable and vulnerable at the same time.

First, you handle large, time-sensitive financial transfers. Criminals know that completion day creates pressure, and pressure leads to mistakes. A well-timed fraudulent email — impersonating a client, a seller’s solicitor, or even a colleague — can redirect a completion payment before anyone realises what has happened.

Second, your workflows depend heavily on email. Bank details, identity documents, signed forms, and contract amendments all flow through inboxes. Email is also the most common entry point for cyberattacks. Without the right security controls in Microsoft 365, a single compromised account can give an attacker access to months of sensitive correspondence.

Third, many smaller conveyancing firms in the Home Counties are still running Microsoft 365 in its default configuration. Out of the box, Microsoft 365 is not fully secured. Features like multi-factor authentication, advanced threat protection, and conditional access policies need to be deliberately enabled and correctly configured. Without them, your firm’s email environment has meaningful gaps that experienced attackers know how to exploit.

What a Breach Actually Costs a Firm Like Yours

The financial loss from a redirected completion payment is the most visible consequence, but it is rarely the only one.

The SRA requires firms to report cybersecurity incidents, and a breach involving client funds or personal data can trigger a regulatory investigation. Depending on the circumstances, this can result in sanctions, fines, or conditions placed on your practising certificate. Separately, a client who loses money due to a breach on your systems has grounds for a negligence claim, and even where your professional indemnity insurance responds, the reputational damage with local referrers and estate agents can take years to recover from.

For a firm with 15 to 50 fee earners operating in a competitive local market, the downstream effect on new instructions can be severe.

The Specific Risks in Your Microsoft 365 Environment

Most conveyancing firms we speak to are using Microsoft 365 for email, document storage, and increasingly for collaboration. It is the right platform for a firm of your size. But using it without security hardening is a significant exposure.

The most common vulnerabilities we identify in firms like yours include:

  • Multi-factor authentication not enforced across all user accounts, meaning a stolen password is enough to access your email
  • No email authentication records (SPF, DKIM, DMARC) configured correctly, making it easier for criminals to spoof your domain and impersonate your firm
  • Overly permissive mailbox access, where compromised accounts can read and forward email without triggering any alerts
  • No conditional access policies, so staff can log in from any device or location without verification
  • Insufficient audit logging, meaning a breach may go undetected for weeks and cannot be properly investigated after the fact

None of these are complex or expensive to address. But they need to be identified and fixed by someone who knows where to look.

What Good Security Looks Like for a Conveyancing Practice

Protecting a firm of your size does not require a large in-house IT team or enterprise-level investment. It requires the right controls, correctly implemented, and monitored on an ongoing basis.

At a minimum, your Microsoft 365 environment should have multi-factor authentication enforced for every user, properly configured email authentication, active monitoring for suspicious login activity, and a clear process for verifying bank account changes verbally before any transfer is made. Your staff should have received recent, practical guidance on identifying phishing emails — not a generic annual training slide, but something specific to the threats conveyancing teams actually face.

Beyond that, regular reviews matter. The threat landscape changes, and a configuration that was adequate eighteen months ago may not be adequate today.

Take the First Step

Computer Care works with conveyancing firms across Surrey and the Home Counties to secure their Microsoft 365 environments and remove the risk of email fraud and data breach.

If you are not certain your current setup is properly protected, we offer a free, no-obligation security posture review specifically for conveyancing practices. We will assess your Microsoft 365 configuration, identify any gaps, and give you a plain-English report — with no pressure and no jargon.

Get in touch with the Computer Care team to arrange yours.