Fraudsters are increasingly targeting property transactions because of the large sums of money involved.
Criminals may attempt to gain access to email accounts or email conversations involving buyers, sellers, solicitors and estate agents, and then impersonate someone involved in the transaction.
They may contact you by email, telephone, SMS or social media, pretending to be Neilsons or a member of our staff and asking you to transfer money to what they claim is our client bank account.
These attacks can be extremely convincing. A fraudulent message may appear within a genuine email conversation, may use information specific to your transaction and, in some circumstances, may even come from a genuine email account that has been compromised.
This type of crime is sometimes referred to as conveyancing fraud or “Friday afternoon fraud”, as criminals often target transactions shortly before settlement, when clients are expecting to transfer substantial sums and may be under time pressure.
Before sending any money to Neilsons
Please remember these important rules:
- Our bank details will never change during the course of your transaction.
- We bank with Clydesdale Bank and will not suddenly ask you to send money to an account with another bank.
- Never act on an email, text message or telephone call telling you that our bank details have changed.
- Before making a substantial payment, contact a Neilsons office using a telephone number you have obtained independently from our official website – not a telephone number contained in an email or message asking you to make the payment.
- We recommend sending £1 as a test payment before transferring the full amount. Someone at Neilsons whom you have been dealing with can confirm that the £1 has safely reached our account before you send the balance.
- When setting up a bank transfer, pay close attention to any Confirmation of Payee or account-name warning from your bank. If the account name does not match what you expect, or your bank displays any other warning, stop and contact us before proceeding.
Never allow urgency to override these checks. A request saying that money must be transferred immediately, that completion will be delayed or that bank details have unexpectedly changed should be treated as a warning sign.
Sending your bank details to us
If you are a beneficiary in an estate and need to tell us which account your entitlement should be paid into, please do not send your bank details by email. We will not accept bank details by email. They must be provided by signed letter so that we can verify their authenticity.
Similarly, if you are selling a property and need to provide details of the account into which your sale proceeds should be paid, do not send these details by email. They must be provided by signed letter.
How to protect yourself from email, telephone, SMS and social media fraud
1. Check email addresses carefully – but don’t rely on this alone
Neilsons email addresses use the format (name)@neilsons.co.uk.
Fraudsters sometimes create addresses that look almost identical to genuine ones, perhaps by changing, adding or removing a letter or punctuation mark.
However, a correct-looking email address is not proof that a message is genuine. Email accounts can themselves be compromised.
For that reason, treat any unexpected email requesting money, providing bank details or changing payment instructions as suspicious, even if it appears to come from someone you know at Neilsons.
2. Verify payment instructions independently
If you receive payment instructions from us, particularly for a substantial amount, verify them by contacting Neilsons using an official telephone number obtained independently from our website.
Do not use a telephone number supplied in the email or message you are trying to verify.
Where possible, confirm our bank details before you reach the point in the transaction when you need to transfer funds. This reduces the risk of making an important decision while under time pressure.
3. Protect your email account with MFA, 2-step verification or a passkey
Your email account is particularly valuable to criminals because gaining access can allow them to see details of your property transaction and send highly convincing messages at exactly the right time.
Turn on multi-factor authentication (MFA), two-factor authentication (2FA) or two-step verification (2SV) for your email and other important accounts.
Where your email provider or other online service supports passkeys, consider using them. Passkeys provide strong protection against phishing because they cannot simply be copied from you in the same way as a password or verification code.
4. Use strong, unique passwords
Do not reuse your email password on other websites or services.
Use a strong, unique password for every important account and consider using a reputable password manager to create and store them securely.
There is generally no need to change a strong password simply because a certain amount of time has passed. Instead, change it promptly if you believe it may have been compromised or reused somewhere that has suffered a security breach.
5. Be careful what you post on social media
Avoid publicly announcing that you are buying or selling a property, particularly while the transaction is ongoing.
For example, posting that you have “just had an offer accepted”, sharing a link to the property, mentioning your moving or completion date, identifying your solicitor or estate agent, or posting that you are “finally settling on Friday” can provide criminals with useful information.
Fraudsters can combine information available on social media with information obtained elsewhere to create a highly convincing impersonation or phishing attempt.
Review the privacy settings on your social media accounts and consider what information about your property transaction is visible to people you do not know.
Also be cautious about unsolicited direct messages or friend/follow requests while your transaction is taking place.
6. Avoid accessing sensitive accounts using public Wi-Fi
Be cautious about using public Wi-Fi in cafés, hotels, airports, trains or other public places to access your email, online banking or information relating to your property transaction.
Where possible, use your own trusted mobile data connection or another trusted network when accessing sensitive accounts or dealing with payment information.
7. Never approve an unexpected MFA request
If you receive an unexpected authentication notification, login approval request or verification code, do not approve it or give the code to anyone.
A genuine member of Neilsons staff will not ask you to disclose your email password, online-banking password or security authentication code.
8. Keep your devices up to date
Install security and software updates for your phone, tablet and computer promptly and enable automatic updates wherever possible.
Keep your web browser and email applications up to date as well.
9. Be suspicious of urgency
Fraudsters frequently try to create pressure:
“The bank details have changed.”
“You must transfer the deposit today.”
“Settlement will fail unless you make the payment immediately.”
“Don’t call the office because I’m in a meeting – just make the transfer.”
Stop and verify the request independently. Taking a few minutes to make a telephone call could prevent the loss of a substantial amount of money.
10. Telephone numbers can also be spoofed
Do not assume that an incoming call is genuine simply because the number displayed on your phone appears to be correct.
If someone calls claiming to be from Neilsons and asks you to transfer money or provide sensitive information, you can end the call and contact us yourself using one of our independently verified telephone numbers.
If you think you may have sent money to a fraudster
Act immediately.
Contact your bank straight away and explain that you believe you have made a fraudulent transfer. The sooner your bank is notified, the greater the opportunity may be to attempt to stop or recover the funds.
You should also contact Neilsons immediately so that we can check your transaction and communications.
If you believe an email or online account has been compromised, change the affected credentials, secure the account and check for suspicious activity.
If in doubt, contact Neilsons.
If you receive an email, telephone call, text message or other communication claiming to be from Neilsons that asks you to make a payment, change bank details, provide personal information or take an action that you are unsure about, do not act on it until you have spoken to us.
Contact us using one of our established office numbers:
Head Office: 0131 316 4444
Picardy Place: 0131 556 5522
South Queensferry: 0131 331 4009
Bonnyrigg: 0131 663 9988
Property Department: 0131 625 2222
When it comes to transferring money during a property transaction, it is always better to stop, check and speak to us before making the payment.