UK Homebuyers Lose Hundreds of Thousands to 'Friday Afternoon' Email Fraud
Criminals hijack email chains between buyers, solicitors and estate agents to redirect house-purchase deposits into fake bank accounts. One victim lost £300,000.

Key points
- Conveyancing fraud, where criminals intercept property-purchase emails to redirect payments, has cost some UK victims hundreds of thousands of pounds.
- At least one victim lost £300,000 in a single incident after receiving a spoofed payment email.
- Criminals gain access either by breaking into a solicitor's email account or by tricking the buyer through phishing: fake emails designed to steal login credentials.
- Buyers are most vulnerable in the final hours before a sale completes, a window criminals deliberately target.
What actually happens in this scam?
The criminal slips into an ongoing email conversation between a homebuyer and their solicitor or estate agent, then sends a fake payment instruction using a bank account they control.
Timing is deliberate. Property purchases in England and Wales typically complete on a Friday afternoon, when buyers are anxious and everyone wants it done. By the time the real solicitor calls to ask where the money is, the transfer's already gone through. That window gives the scam its nickname.
Access comes from two directions. Sometimes the solicitor's own account has been broken into, so the criminal reads and mimics every message with accuracy. Other times the buyer falls victim to phishing first: a fake email tricks them into entering their password on a bogus site, handing over months of correspondence.
Either way, the fraudulent request looks convincing. It arrives from a familiar address, uses the right names and references real details from the sale.
How much are people losing?
The Guardian reported individual losses ranging from tens of thousands of pounds to a single case of £300,000. These aren't sophisticated corporate heists. They're ordinary families, often spending everything they have, who transfer their deposit and lose it within minutes.
Because the buyer authorised the payment themselves, even though they were deceived, UK banks often treat these as "authorised push payment" fraud: a transfer the account holder appeared to consent to. Recovering the money is difficult and not guaranteed, though reimbursement rules have been tightening.
What should buyers watch for or do?
Before any transfer, call your solicitor on a number you looked up yourself, not one from the email. Confirm account details verbally before sending anything. That single step would stop almost every instance of this fraud.
Also watch for subtle changes in an email address: a criminal might use "smithsolicitors.co" instead of "smithsolicitors.co.uk", counting on you to miss the difference under pressure.
Solicitors and estate agents carry their own responsibility. Any firm handling property transactions should use multi-factor authentication on email accounts, requiring a second verification beyond a password before anyone logs in. Staff training on phishing matters too, since one compromised inbox can expose every client in an active chain.
Should you worry about getting money back?
It depends. The ecosystem behind this fraud pattern, which analysts call business email compromise or BEC, is diffuse and commercially driven rather than state-linked. As we reported on 30 June, BEC is better understood as a supply-chain operation involving account access, target research and money mules. No malware's required. Attribution rarely helps victims. What helps is speed: our 31 July story on Interpol's payment-fraud interception network shows that frozen transfers are recoverable, but only if banks are alerted within hours. Don't wait to see whether the money arrives.



