<15 min Response

20+ Years Experience

Cyber Essentials Certified

Check IT & Cyber Score

Remote SOS Support

Friday Afternoon Fraud: How Conveyancing Firms Get Caught, and What Stops It

Conveyancing payment diversion fraud, also known as Friday afternoon fraud, targeting a law firm

A solicitor acting on a property sale was deceived into transferring more than £290,000 to fraudsters. Emails between the firm and its client had been intercepted somewhere between exchange and completion. A last-minute request arrived to change the destination bank account, followed by a reconfirmation email. The funds went the next working day.

The bank raised concerns nearly two weeks later. The solicitor reported it to the police and the SRA three months after that. The Solicitors Disciplinary Tribunal found the solicitor “should have known the circumstances were suspicious and worthy of proper investigation to prevent fraud”, and described the failure to insist on additional verification as particularly troubling. The penalty was a £10,000 fine plus £16,000 in costs.

That case is worth sitting with, because nothing exotic happened. No ransomware, no dramatic breach. Someone read the firm’s email and waited for the right moment.

What payment diversion fraud actually is

Payment diversion fraud, still widely known as Friday afternoon fraud, is when criminals impersonate a solicitor or a bank to persuade someone to send money to the wrong account. The Law Society’s guidance is blunt about the mechanism: emails can be intercepted or diverted, and fraudsters frequently work from a compromised mailbox.

The reason it works on conveyancing rather than other legal work is timing. Completion has a fixed date, large sums move on a deadline, and everyone involved is under pressure to get it done before the weekend. A fraudster reading the mailbox knows exactly when to send the account change, because they have been watching the thread.

The part most firms miss

The email account is usually compromised weeks before anything happens. Nobody notices, because the attacker does not send anything or change the password. They read.

The technical signature is almost always the same: once inside a mailbox, the attacker creates inbox rules that quietly move or delete replies containing words like “invoice”, “bank”, “account” or “payment”. That way the genuine client’s confused reply never reaches the fee-earner, and the fraudulent thread carries on undisturbed on both sides.

If nobody is monitoring for new forwarding or inbox rules on your Microsoft 365 tenant, that activity is invisible until the money has gone.

The warning signs in that case

  • The request came from an email address that was slightly different from the genuine one
  • The bank details changed at the last minute
  • Nobody picked up the phone to the client to confirm it
  • It landed under time pressure, ahead of a Monday completion

Each of those on its own is survivable. Together they are the pattern, and the pattern repeats.

What actually stops it

Process controls

The Law Society’s advice to clients is the same advice firms should be enforcing internally. Give bank details at the start of the matter, in person or over the phone. Make clear that your details will not change. As the guidance puts it, law firms rarely change their bank details, so any announcement that they have should be treated as suspicious until proven otherwise.

If a change request arrives, verify it by calling a number you already hold, never a number contained in the email asking for the change. Never release funds until you are satisfied. A small test payment first is a reasonable belt-and-braces step on a large transfer.

The single most effective rule is the simplest: bank details are never changed on the basis of an email. Write it into your file-opening letter, tell every client at the outset, and make it a disciplinary matter internally rather than a guideline.

Technical controls

Process fails when people are busy. These reduce the chance a mailbox is readable in the first place, and shorten the time it takes to spot one that is.

  • Multi-factor authentication on every account, with no exceptions for partners. Compromise almost always starts with a password.
  • Conditional Access policies so a login from an unexpected country or an unmanaged device is challenged or blocked.
  • Alerting on new inbox and forwarding rules. This is the one most firms do not have, and it is the control that catches this specific attack.
  • Email authentication (SPF, DKIM and DMARC) configured properly, so spoofing your domain is harder.
  • Impersonation protection that flags lookalike domains and display-name spoofing, which is what “an email address slightly different from the genuine one” means in practice.
  • Audit logging retained and readable, so that if something does happen you can establish what was accessed and whose data was involved.

Most of these are already available in the Microsoft 365 licences firms are paying for. They are simply not switched on.

If it happens anyway

Speed matters more than anything else, and the case above shows what delay costs.

  1. Contact the bank immediately and ask them to request that the receiving bank freezes the funds.
  2. Report to Action Fraud, online or on 0300 123 2040.
  3. Report to the SRA. A serious breach of the SRA’s Standards and Regulations must be reported under Rule 3.9 of the Code of Conduct.
  4. Assess whether personal data was involved. A reportable personal data breach must reach the ICO within 72 hours of you becoming aware of it.
  5. Check whether other matters are affected. If a mailbox was compromised, this transaction is unlikely to be the only one the attacker was reading.

That last point is the one firms forget in the panic. The question is not only “how do we recover this payment”, it is “what else did they see”.

ATS Connection provides IT support for solicitors and law firms, including Microsoft 365 hardening and monitoring for the mailbox activity behind this kind of fraud. If you are working out where you stand more broadly, our guide to SRA IT requirements and our explanation of whether the SRA requires Cyber Essentials are the sensible next reads.

Frequently asked questions

What is Friday afternoon fraud?

Friday afternoon fraud is a form of payment diversion fraud targeting conveyancing. Criminals intercept or monitor email between a firm and its client, then send a last-minute request to change the bank account funds should be sent to, timed to land under deadline pressure before a weekend or a Monday completion.

How do fraudsters get into a law firm’s email?

Most commonly through a stolen or guessed password on an account without multi-factor authentication. Once inside, attackers typically read quietly for weeks and create inbox rules that hide replies mentioning payments or bank details, so neither side notices the conversation has been hijacked.

Can a solicitor be fined for falling victim to this?

Yes. In a case reported by the Law Society, a solicitor who transferred more than £290,000 to fraudsters after a last-minute bank change was fined £10,000 with £16,000 in costs. The tribunal found the circumstances were suspicious enough that they warranted proper investigation before the funds moved.

What is the single most effective control?

A firm-wide rule that bank details are never changed on the basis of an email, verified by a phone call to a number already on file rather than one supplied in the message. Technically, multi-factor authentication on every account combined with alerting on new inbox and forwarding rules catches the underlying compromise.

Who do we report payment diversion fraud to?

Contact your bank immediately to try to freeze the funds, report to Action Fraud on 0300 123 2040, report a serious breach to the SRA under Rule 3.9 of the Code of Conduct, and notify the ICO within 72 hours if personal data was involved.