UK Homebuyers Lose Hundreds of Thousands to 'Friday Afternoon' Email Fraud
Criminals are hijacking email chains between buyers, solicitors and estate agents to redirect house-purchase deposits into fake bank accounts. One victim lost £300,000.

Key points
- Conveyancing fraud, where criminals intercept property-purchase emails to redirect payments, has cost some UK victims hundreds of thousands of pounds.
- At least one victim lost £300,000 in a single incident after receiving a spoofed payment email.
- Criminals gain access either by breaking into a solicitor's email account or by tricking the buyer directly through phishing, which means sending fake emails designed to steal login details.
- Buyers are most vulnerable in the final hours before a sale completes, a window criminals deliberately target.
What actually happens in this scam?
The criminal slips into an ongoing email conversation between a homebuyer and their solicitor or estate agent. They then send a fake payment instruction using a bank account they control.
The timing is deliberate. Property purchases in England and Wales typically complete on a Friday afternoon, when buyers are anxious, the chain is under pressure, and everyone wants to get it done. By the time the real solicitor calls to ask where the money is, the transfer has already gone through. That window gives the scam its nickname.
Access to the email chain can come from two directions. Sometimes the solicitor's own email account has been broken into, meaning the criminal can read and mimic every message with perfect accuracy. Other times the buyer falls victim to phishing first: a fake email tricks them into entering their email password on a bogus website, handing over the keys to months of correspondence.
Either way, the fraudulent payment request looks entirely convincing. It arrives from a familiar address, uses the right names, and references real details from the sale.
How much are people losing?
The Guardian reported individual losses ranging from tens of thousands of pounds to a single case of £300,000. These are not sophisticated corporate heists. They are ordinary families, often spending everything they have, who transfer their deposit and lose it within minutes.
Because the buyer authorised the payment themselves (even though they were deceived), UK banks often treat these as "authorised push payment" fraud, meaning a transfer the account holder appeared to consent to. Recovering the money is difficult and not guaranteed, though the rules around reimbursement have been tightening.
What should buyers watch for or do?
Before any transfer, call your solicitor on a phone number you looked up yourself, not one from the email. Confirm the account details verbally before sending a single penny. This one step would stop almost every instance of this fraud.
Also watch for subtle changes in an email address: a criminal might use a domain like "smithsolicitors.co" instead of "smithsolicitors.co.uk", counting on you to miss the difference under pressure.
Solicitors and estate agents carry their own responsibility here. Any firm handling property transactions should use multi-factor authentication on email accounts, which means requiring a second check beyond just a password before anyone can log in. Staff should also receive regular training on spotting phishing attempts, since a single compromised inbox can expose every client in an active chain.
From a threat-intelligence perspective this fraud pattern fits cleanly into what analysts call business email compromise, or BEC: medium-sophistication, low-cost to execute, and highly targeted. No malware required. Attribution is difficult and largely beside the point because the criminal ecosystem behind BEC is diffuse and commercially driven rather than state-linked. Capability here is trivially available; the intent is purely financial.



