You hold the keys — and every applicant’s identity.
A rental application is a complete identity kit: photo ID, payslips, bank statements, references. A sales settlement moves six or seven figures through a trust account. Both make agents and hire businesses a first-choice target — and covered real-estate services now have AML/CTF obligations.
Dossier 08 / 10
Rental, Hiring & Real Estate
Every tenancy application is a complete identity kit — ID, payslips, bank statements — and every settlement moves through a trust account an attacker would love to redirect.
- Privacy Act 1988 / APPs
- AML/CTF Act (Tranche 2 reforms)
- State agents' Acts & trust-account rules
What the obligation actually requires of you.
- 01
Privacy Act 1988 / APPs
Where the Privacy Act applies, tenancy applications, ID documents and financial records require reasonable protection. Holding information longer than needed or leaving it in an unsecured portal increases exposure.
- 02
AML/CTF Act (Tranche 2 reforms)
Australia's Tranche 2 AML/CTF reforms extend reporting-entity obligations to real-estate businesses providing covered designated services. Those entities must verify customer identity, keep records and report suspicious transactions — controls that only work if the systems underneath them are secure.
- 03
State agents' Acts & trust-account rules
State agents' Acts and trust-account rules put licensed money in your care. A redirected settlement or a compromised trust-account instruction is both a client loss and a licensing risk, so payment-change verification is not optional housekeeping.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A deposit targeted for the wrong account.
Illustrative scenario — In this example, An agency's property-management inbox was accessed through a reused password with no MFA. The attacker sat quietly, learned the settlement cadence, then emailed a buyer's conveyancer with 'updated' trust-account details days before settlement.
Example response — A suitable response is to hold the transfer, call back on a known number, review mailbox and trust-account access, and document the verification before releasing funds.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- MFA enforced on every email account, CRM and property-management platform
- Trust-account and settlement payment changes verified by call-back on a known number, every time
- Tenancy-application data encrypted and deleted on a defined retention schedule, not kept forever
- Access to applicant and vendor records limited to staff who need it, and logged
- Staff trained to spot conveyancer- and vendor-impersonation email fraud
- Card-on-file hire and bond payments handled through a PCI-compliant processor, never stored in spreadsheets
- A breach-response process mapped to the Privacy Act's Notifiable Data Breaches scheme
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
Because you hold high-value trust accounts and complete identity documents on hundreds of applicants, with controls that are often lighter than a bank's. That combination — big money, rich data, lean defences — is exactly what payment-redirection fraud looks for.
Covered designated services are now within the AML/CTF regime. Check whether your services are in scope and align customer verification, record-keeping and reporting with AUSTRAC guidance.
Verification by a second channel, every time. We enforce a policy that any change to payment or bank details is confirmed by phone on a previously known number before funds move — a practical control for reducing payment-redirection risk.
Find out exactly where your agency’s trust account is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au