Industry guides

Cyber Exposure Checklist for Estate Agents

Estate agent cyber exposure is not just an IT issue. It is transaction-fraud context.

Most estate-agency visibility is normal: staff profiles, portal listings, branch details, director records, and transaction updates. The risk grows when someone can connect those signals with mobile numbers, breach history, broker records, lookalike domains, and exchange-stage timing.

Published

Quick answer

Cyber exposure for estate agents means the publicly visible data about your branch staff — negotiator mobiles on portals, director addresses on Companies House, personal emails in breach databases — that attackers can combine with transaction timing to make a deposit diversion or impersonation attempt feel credible. Start by checking what is already visible for your highest-risk roles.

Want this checked privately?

Want this checked privately?

Hushfolk can review branch and staff exposure, document priority findings, and provide a reduction plan without requiring staff or client data on the first call.


How exposure becomes risk

How estate-agent exposure becomes transaction-fraud context

A single visible mobile number is rarely the whole issue. The risk grows when public branch visibility, staff identity, contact routes, breach context, and transaction timing connect.

Diagram showing how portal profiles, branch records, broker contact data, breach signals, and transaction timing can create transaction-fraud context.

A negotiator profile may be normal. A live listing may be expected. A branch record may be public. A mobile number may be convenient. But when those signals connect to a live transaction, sold-STC context, exchange-stage pressure, or a familiar branch identity, the exposure becomes more useful to someone trying to impersonate, pressure, or misdirect.


Why it matters

Where estate-agent exposure becomes money risk

Estate-agent exposure matters most when it connects to a transaction. A visible negotiator profile is normal. A buyer knowing the branch name is normal. A solicitor receiving urgent emails near exchange is normal.

The risk appears when those normal signals combine with a visible mobile number, a lookalike agency domain, a personal email breach, or a director record that makes the message feel more credible.

Branch exposure is not only a privacy issue.

It can become deposit-diversion context, supplier impersonation context, or director-pressure context — without touching your CRM or internal systems.

Deposit diversion

Exchange-stage urgency combined with a familiar branch name and visible contact route creates pressure that makes payment detail changes harder to question.

Supplier impersonation

Branch email formats visible on portal profiles and lookalike domains allow believable supplier communication without access to any internal account.

Director pressure

Director names, roles, and home address links on Companies House create authority context that can be used to pressure junior staff into urgent actions.

Connected exposure

Individual signals rarely cause harm alone. The risk is when portal data, broker records, breach history, and transaction timing align around the same person.


Where to start

The five exposure surfaces every agency should review first

Do not start by searching randomly. Start with the surfaces most likely to create believable context around a branch, negotiator, director, or live transaction.

Five-card overview of estate-agent exposure surfaces including portal profiles, branch records, transaction context, staff breach exposure, and impersonation surface.
1

Property portal profiles

Why it matters

Public visibility, negotiator identity, listing credibility.

Check first

Staff names, photos, role details, mobile numbers, direct contact visibility, portal listing pages.

2

Branch & director records

Why it matters

Official branch details, registered addresses, director context.

Check first

Company filings, branch records, director details, registered address exposure.

3

Client transaction context

Why it matters

Live sale timing, progression signals, pressure near exchange.

Check first

Active listings, sold-STC properties, completion context, known transaction stages.

4

Staff breach & personal email

Why it matters

Recovery routes, old accounts, historical breach reuse.

Check first

Personal email exposure, breach records, old login traces, linked accounts.

5

Impersonation surface

Why it matters

Lookalike domains, fake branch identity, believable contact routes.

Check first

Copycat domains, cloned profiles, fake contact points, branch-name abuse.

Estate-agent exposure is rarely one record.

Risk grows when multiple surfaces connect. A portal profile is routine. A portal profile plus a broker record plus a breach signal near an active listing is not.


In practice

What counts as cyber exposure for estate agents

What counts as cyber exposure for estate agents?

Estate agents live publicly in a way most other businesses do not.

Negotiator names and mobile numbers appear on Rightmove and Zoopla listings. Branch managers show up in local press. Directors are listed at Companies House with service addresses that may still be home addresses. Agency principals show up on data broker sites with previous addresses, household links, and associated email addresses.

Then there is the breach side. Personal emails used for work systems, portal registrations, or old industry accounts appear in breach databases more often than people expect. An account from a previous agency. A Gmail address used to sign up for a property software trial. These surface with passwords, recovery addresses, and linked accounts.

There are also lookalike domains. Fraudsters register variations of agency names — sometimes weeks before a transaction completes. A domain with a one-letter change can carry convincing emails to buyers or solicitors at exactly the wrong moment.

Exposure includes: portal agent profiles with mobile and photo, branch contact pages with direct emails, director Companies House filings, broker records with address and household data, personal emails in breach databases, and lookalike or registered agency domain variants.

None of this requires hacking anything. It is the result of how estate agencies operate publicly — and how that visibility gets used by people who study it before acting.

Why property firms get targeted

Property transactions involve large, one-way payments. And the timing is predictable.

Buyers and solicitors are conditioned to receive urgent messages near exchange. They trust agency email addresses. They act quickly when something about a deposit or bank detail change feels like it needs immediate attention. That combination — trust, urgency, and a large sum — is exactly what makes property transactions a consistent target.

The exposure side makes it easier to build a convincing attack. A negotiator's name, branch email format, and mobile number are on Rightmove. The agency domain is well-known. The buyer knows who they are dealing with. A fraudster with access to those details can construct a message that feels like it came from the right person at the right firm.

It does not require compromising any internal system. It requires enough public context to make an email look plausible and enough knowledge of the transaction to make the timing feel right.

Senior staff add another layer of risk. A director's name, home address, and family links visible on broker sites give attackers authority context they can use to impersonate leadership or pressure junior staff. The pattern is the same as CEO fraud in other sectors — but in property, the transaction window is the trigger.


Run a 2-minute branch exposure readiness check

Self-assessment

This is not a scan. It does not search for staff data and does not require names, emails, addresses, property details, or client records. It helps you understand whether your agency has a basic process for reviewing branch-linked exposure.

A. Who is in scope for your review?
B. What do you currently review?
C. What process does your agency have in place?

No process yet?

If you cannot answer most of these, your agency does not have a branch exposure process yet.

That does not mean something has already gone wrong. It means fraudsters may have more context about your staff, listings, and transaction timing than your team is currently tracking.


Worked example

What a connected branch exposure record can look like

The goal is not to panic over a single public detail. The goal is to identify when multiple public signals connect around staff, branch identity, and transaction timing.

Fictional redacted estate-agent branch exposure record showing visible data, why it matters, and recommended actions.

Use fictional or redacted examples only when documenting exposure internally. Avoid circulating unnecessary staff or client personal data. This type of record exists to help agency owners and ops teams understand what connected exposure looks like — not as a template for sharing real staff information.


How fraud pretexts are built

How a believable deposit-diversion pretext is built

A credible property-fraud pretext does not always require a compromised CRM. Sometimes it is built from public listings, familiar branch identity, staff context, contact routes, and transaction timing.

Five-step defensive diagram showing how active listings, staff identity, contact routes, lookalike branch identity, and transaction timing can make a fraudulent payment request more believable.

The fraud path attackers actually use

Here is how a realistic property fraud pretext gets built.

A negotiator's name, email format, and branch mobile are on the Rightmove listing for an active property. The attacker notes the branch, the agent's name, and the agency's domain.

Next, they run the negotiator or branch manager through a data broker. They find a mobile number, a previous address, and a linked email address — sometimes matching the one already on Rightmove, sometimes a personal one.

They check Companies House for the director's service address. Still listed as a home address in some cases. They run a breach check on the personal email. It appeared in an old data breach. They now have a detailed picture of two or three people at the agency.

Then they register a lookalike domain — maybe the agency name with a hyphen or a different extension. They monitor the target property listing.

When exchange is close, they send an email to the buyer's solicitor — appearing to come from the agency — with updated payment details. Or they send one directly to the buyer with a bank account change request.

Total time to build the pretext: under an hour. The payment, if it goes through, is immediate and largely unrecoverable.

The agency often does not know it happened until the buyer calls to confirm the transaction.

The 15-minute branch exposure check

This is a process for agency owners, branch managers, or operations teams. It does not require collecting or sharing staff personal data — you are checking what is already publicly visible.

Start with your most active negotiators and branch managers. Search each name in quotes on a standard search engine. Note what contact details appear on the first two pages — portal profiles, branch pages, press mentions, event listings.

Run the name through one or two data broker sites. Note whether a personal mobile, home address, or household connection is visible without a subscription.

Check Companies House for any director filings. Look at the service address — is it a home address?

Run any known work or personal email addresses through a breach checking service. Note what was exposed and when.

Search for your agency domain with one-letter variations and alternative extensions. Note any registered lookalike domains.

Document what you find for each person reviewed. You are not trying to remove everything in one session. You are getting a clear picture of where the highest-risk exposure sits before anything happens.

Someone does not need every detail to create pressure. A small amount of public context can make a message feel plausible, especially if the recipient already recognises the branch, negotiator, property stage, or timing near exchange.

Private review

Could someone build this around your branch or director?

A private review shows whether portal profiles, director records, breach data, contact routes, and transaction timing are connecting in ways that deserve action before the next exchange.


Risk priority

What should be prioritised first

Not every public staff or branch detail carries the same risk. Prioritise exposure where transaction impact and connected visibility overlap.

Matrix showing how transaction impact and exposure depth affect estate-agent exposure priority.
Low

Basic portal profile, no personal contact data, and no live transaction context.

Medium

Single broker record, personal email breach, or one public contact route.

High

Active negotiator or branch lead with visible mobile or contact route and known transaction timing nearby.

Critical

Director or branch owner exposure connected to home address, personal email breach, household links, and live transaction context.


Documentation

What a useful branch exposure log should show

A serious process needs more than screenshots. It needs source notes, evidence dates, risk level, owner, action taken, and recheck schedule. Without it, findings get lost and removed records return unnoticed before the next exchange period.

Staff groupExposure foundRiskActionOwnerRecheck
Negotiator on active listingMobile visible on portalHighPortal update requestedBranch manager30 days
Branch managerPersonal email in breachHighMonitoring + password reviewOps / IT30 days
Agency directorCompanies House home addressCriticalSuppression route reviewedDirector60 days
Lettings coordinatorBroker profile with mobileMediumRemoval requestedBranch managerQuarterly

The purpose is to give branch owners, operations leads, and leadership a shared view of what was found, what was actioned, and what needs reviewing before the next busy exchange period.

Most agencies find exposure and then lose track of it.

They ask a portal to update a contact. They do not record when they asked, or whether it changed. Six months later they are not sure if the old mobile is still showing. A transaction gets close to exchange and nobody has checked.

A basic exposure log makes this manageable. For each staff member — starting with negotiators on active listings, branch managers, and directors — record: which site holds the data, what is visible, when you found it, what action you took, any confirmation reference, the expected response window, who owns follow-up, and when you will recheck.

A shared spreadsheet is enough. The point is that anyone in the team can open it and see what is done and what is not. That visibility matters most when a transaction is moving quickly and nobody wants to be guessing.


What good looks like

What good looks like: monthly branch exposure review

Branch exposure is not a one-off cleanup. Staff change, listings change, broker records can return after removal, and new breach data appears continuously. A monthly rhythm keeps the process manageable without becoming a burden.

Five-step monthly branch exposure review process showing review, log, remove, recheck, and brief.
  1. 1
    Review active staffNegotiators on live listings, branch managers, lettings staff, and directors.
  2. 2
    Log visible sourcesPortal profiles, company records, broker profiles, breach signals — date and source noted.
  3. 3
    Remove or restrict priority exposureRequest removals, reduce visibility, review direct contact routes.
  4. 4
    Recheck returned recordsMonitor previously removed records for reappearance, unresolved risks, or new signals.
  5. 5
    Brief branch owner or ops leadUpdate leadership on findings, active owners, and next steps.

The honest version: exposure comes back.

Broker sites re-aggregate from public sources continuously. Portal contact details change when staff update their profiles. New breach data enters databases on a rolling basis. A negotiator who joined in the last six months may not have been checked at all.

What works: assign one person who owns the exposure log — branch manager, ops lead, whoever runs admin processes — and give them one hour a month. Check two or three current staff each month, rotating through the team. Add an exposure check to your process when someone joins or leaves. Keep the log updated so pending removals do not get forgotten.

The goal is not to clear every piece of public data. It is to remove the combinations that matter — the ones that connect a name to a mobile to a home address to an active transaction. One hour a month, done consistently, beats an intensive review once a year that nobody follows up on.


Checklist

Quick-start checklist

Start here before the full worksheet. Work through one staff group at a time, starting with negotiators on active listings.

  • Checked negotiator names on active listings for visible personal mobile numbers or home contact routes
  • Reviewed branch manager and director names on data broker sites for address or household exposure
  • Confirmed director Companies House service address is a business address, not a home address
  • Checked personal and work email addresses for high-risk staff against breach databases
  • Searched for lookalike or impersonation domains registered against the agency name
  • Reviewed portal profiles on Rightmove, Zoopla, and OnTheMarket for any unnecessary contact details
  • Confirmed a deposit or bank detail change verification process is in place and understood by staff
  • Logged at least one removal request with date, route used, and confirmation reference
  • Assigned one person who owns the exposure log and knows when the next review is due
  • Added a monthly branch exposure recheck to the team calendar

Free download

Get the full 20-point Estate Agent Cyber Exposure Worksheet

Branch prioritisation framework, redacted exposure record template, and a monthly review schedule built for agency owners and ops teams.

Request the worksheet

Frequently asked questions

How is estate agent exposure different from general employee exposure?

The key difference is transaction context. Most employees have some visible data online. Estate agents have that plus their active property listings, client-facing contact details, and publicly visible transaction involvement. That combination gives attackers specific timing information — they can act when a transaction is close to exchange, when urgency is highest and verification habits may slip.

Is it appropriate for agencies to review publicly visible staff data?

Yes, with a clear internal policy. The data being reviewed is already publicly accessible — the review is about understanding what is visible and how it could be used, not collecting new personal data. Most agency owners treat this as straightforward business security practice. The ICO's guidance on legitimate interests supports proportionate internal reviews of publicly available information where there is a clear business security purpose.

How often should branch and negotiator exposure be rechecked?

Monthly spot checks for active negotiators on live listings, and quarterly for the rest of the team. Triggers for an off-cycle check include a new staff member joining, someone leaving, a branch move, significant press coverage, or any indication that a specific transaction or property has attracted unusual attention.

What should be prioritised first for negotiators vs agency directors?

For negotiators on active listings, the priority is portal contact details — mobile numbers, email addresses, and anything that could be used to impersonate them during an active transaction. For directors and branch owners, the priority is Companies House service address exposure, broker profiles linking a home address to a public role, and personal email breaches that could support impersonation of the business owner.


Private branch exposure audit

Turn this checklist into a reviewed agency exposure report

For agencies that want this handled properly, Hushfolk can review negotiator, branch manager, director, and lettings staff exposure, then provide documented findings and a reduction plan.


Sources