News

Cyber Security

The buyer who never existed

  • 6 August 2026
  • Andrew McColl, Chairman, RPSA
The buyer who never existed

A buyer, a property link and a fake login: the phishing scam surveyors need to recognise.

The ordinary enquiry that hid a credential-stealing trap

A convincing request for a home survey led to a property page carrying copied portal branding and an unexpected email login. This article follows the approach step by step, explains the warning signs and sets out what to do if credentials have been entered. 

How the enquiry began

It begins exactly as many surveying instructions begin. A prospective purchaser completes the website contact form and asks for information about survey levels, costs and timescales. You reply, because responding promptly to enquiries is part of running a successful practice. Nothing appears especially alarming. Then comes the property link.

In this case the enquiry came from “Helen Randall”, who said she was in the process of purchasing a property and wanted to arrange a survey. Could the surveyor set out the RICS Home Survey levels, the differences between them, and the cost of each? If any further information about the property was needed in order to quote, she would be happy to supply it. Bear in mind throughout that the name, like everything else in the message, may well be invented, or borrowed from an entirely innocent person.

Screenshot of the initial website contact-form enquiry, with the surveying practice identity removed

Figure 1. The initial contact-form enquiry, with the surveying practice identity removed. Sender details are shown as received.

The surveyor replied the way any of us would, because that is the nature of securing work, and asked for the address of the property so the listing could be checked and proper advice given.

Why the follow-up looked convincing

The reply came back the following morning. It thanked the surveyor for the prompt response, provided a link to “the property listing page on the estate agent website including the sale memorandum”, and then did something clever. It asked good questions. Whether the wall between the kitchen and dining room was load-bearing. Whether removing it would need an RSJ or an LVL. Particular attention to the roof and chimney, damp, structural movement, the loft, pointing, drainage and the visible services. Which level of survey would be recommended, what was the fee, and could she be present at the inspection? The purchase price, she added, was £560,000.

Every one of those details is there to make you lean in. A half-million pound instruction, a client who has apparently done her homework, and a set of questions that flatter your expertise. The only thing she actually needed the surveyor to do was click the link.

There were clues, with hindsight. The font size at the top of the message did not match the pre-made text beneath it, suggesting a template. The enquiry supplied an unusual amount of unprompted detail for this stage of a transaction. The sender was on a free webmail address. But be honest with yourself: no single feature proved that this was fraudulent. Some genuine clients are thorough, copy text between devices, or ask elaborate questions. The warning came from the combination of circumstances, and above all from what happened next.

How the enquiry changes character

  1. 1Normal enquiryA buyer asks about survey levels, fees and timescales.
  2. 2Convincing detailSpecific questions create urgency and flatter professional expertise.
  3. 3External linkA familiar portal name appears in the message, but not in the true domain.
  4. 4Credential requestThe page asks for an email login before showing the property details.

The link that changed everything

The message mentioned Zoopla, and a version of this scam does the same with Rightmove. But look at where the link actually went:

Read the address, not the logo

https://residential-property-forsale-listing[.]com/.../zoopla/

True domain

residential-property-forsale-listing[.]com

Misleading path text

/zoopla/ - it does not make the site part of Zoopla

The suspicious address is deliberately neutralised. Do not attempt to visit it.

This is the lesson worth committing to memory. A logo can be copied in seconds, and so can a folder name. The true website address is the section after https:// and before the next slash. Everything appearing after that next slash is merely a path or folder within the site, so the word “zoopla” appearing there does not make the site part of Zoopla. Here the actual domain is an unfamiliar one with no connection to Zoopla at all, and while its long, keyword-heavy style is common among fraudulent sites, that is a supporting clue rather than the decisive point. The decisive point is that, despite the branding, the site was not operating on a Zoopla domain.

Important clarification

Nothing in this article suggests that Zoopla was responsible for, involved in or aware of this communication. Zoopla’s branding was copied and used without authorisation on a third-party domain with no connection to Zoopla.

Zoopla’s advice to surveyors

“Our advice to residential surveyors is straightforward: treat any enquiry with a link with caution, check any website addresses carefully to ensure it's not a lookalike domain. When receiving an email check the sender's actual email address, not just the display name.”

Why the padlock did not make it safe

The site showed the browser padlock and used an https address, and it is worth being clear about what that does and does not mean. The padlock only means that the connection between your browser and that website is encrypted. It does not prove that the person operating the website is honest, or that the site belongs to the organisation whose branding appears on the page. Criminals can obtain SSL certificates for their sites in minutes, free of charge, and routinely do.

The trap

Following the link led to a page that looked convincingly like Zoopla. Navigation bar, search box, house photograph, the lot.

Screenshot of a fake property listing with the true third-party domain highlighted and the page marked as not Zoopla

Figure 2. Screenshot of the page presented by the third-party domain. The true domain has been highlighted and the copied page clearly marked as fake.

Then the pop-up appeared. To read the Memorandum of Sale, please log in with your email provider. Outlook, Yahoo, AOL, Google, or other. It looks plausible precisely because so many genuine sites and apps now ask you to sign in this way.

Screenshot of the fake email-provider login prompt, labelled as an unexpected login request

Figure 3. The credential-harvesting prompt. Entering an email address and password here would not log the user into a property portal.

Enter your email address and password here and you have not logged in to anything. You have handed your mailbox credentials directly to a criminal. They now have the keys to the front door.

What the criminals may gain

This is the point at which a momentary mistake can become a serious professional incident, because your mailbox is not just your mailbox. It is your client list, your quotes and invoices, your bank details, your report attachments and years of correspondence. Once an attacker has working email credentials, they may be able to:

  • read confidential client correspondence and attachments;
  • impersonate you, emailing clients and contacts from your genuine address;
  • send altered invoices or payment instructions at exactly the moment a transaction completes;
  • request password resets for banking, cloud storage and other services registered to that address;
  • create forwarding or hidden inbox rules so they keep reading your mail even after you change the password;
  • target your clients, staff and professional contacts with far more convincing scams of their own.

Nor is this theoretical. Rightmove’s own guidance records that, in the first two months of 2021 alone, it knew of six estate agents whose email inboxes had been compromised following phishing attacks, with at least one having to report the incident to the ICO. The precise lure may differ, but the underlying mechanism is the same: stolen credentials giving an attacker access to a professional mailbox. And the mechanism does not care whether that mailbox belongs to an agent or a surveyor.

For a surveying practice the regulatory position is worth stating plainly. A compromised mailbox containing client personal data must be recorded and assessed under the firm’s data breach process. Not every compromise has to be reported to the ICO, but a reportable personal data breach must be notified without undue delay and, where feasible, within 72 hours, and high-risk breaches may also require the affected individuals to be told.

I entered my password. What now?

Act immediately. Do not wait to see whether anything happens.

  • Contact your IT provider or email administrator using a trusted telephone number.
  • Change the affected password through the genuine provider’s website, never through a link in the original message, and change it anywhere else the same or a similar password was used.
  • Revoke all active login sessions and check the multifactor authentication methods and connected applications registered to the account, removing anything you do not recognise.
  • Inspect email forwarding, inbox rules, delegates, sent items and deleted items. Hidden forwarding rules are a favourite trick and one people often miss.
  • Enable multifactor authentication if it is not already active.
  • Contact your bank immediately if banking credentials, payment details or funds may be affected. Where the mailbox has been compromised, consider warning clients involved in live transactions to verify any payment instructions by telephone using a trusted number.
  • Run an up-to-date security scan if anything was downloaded or installed.
  • Preserve the original email, its headers, screenshots and a timeline of what happened.
  • Notify your cyber insurer and, where relevant, your professional indemnity insurer or broker in accordance with the policy terms, and assess whether client or other personal data may have been accessed.

Changing the password alone may not be enough. If the attacker has set up a forwarding rule or registered their own login method, they are still inside until you remove it.

Further help for RPSA members

RPSA members can also read Useful Document 25: Cyber Insurance - What It Covers and Why It Is Important, available in the Members Area. The guide explains common cyber risks, including phishing, hacking, malware and ransomware, together with the types of incident-response and financial protection that cyber insurance may provide. Members should check the precise terms, limits and notification requirements of their own policy, as cover varies.

Where to report it

Reporting feels pointless in the moment, but it is how these sites get taken down and how the pattern gets tracked. Use the route that fits what happened:

  • Suspicious email: forward it to report@phishing.gov.uk, the National Cyber Security Centre’s reporting address.
  • Suspicious website: report it through the NCSC’s online suspicious website form. Do not click the link in order to report it; copy the address carefully into the form instead.
  • Actual fraud, financial loss or account compromise: report it to Report Fraud, which replaced Action Fraud in December 2025, or telephone 0300 123 2040. In Scotland, contact Police Scotland on 101. Where payments or banking details are involved, contact your bank immediately.
  • Impersonation of a property portal: Zoopla asks for suspicious communications using its branding to be forwarded to members@zoopla.co.uk, and Rightmove to fraud@rightmove.co.uk.
  • Possible data breach: record and assess it under your firm’s data breach process and consider whether ICO notification is required.

Help us protect other members

Have you received a similar enquiry, spotted another potential scam, or been caught out yourself? Please tell us at info@rpsa.org.uk. Do not be embarrassed, even if the warning signs appear obvious in hindsight. These scams are deliberately designed to exploit ordinary working routines and can catch busy, experienced professionals. Your information could help us identify a wider pattern and warn other members before they suffer the same experience. Reports will be treated sensitively, and we will not publish your name, practice details, client information or anything that could identify you without your express permission. Please send the original email as an attachment where possible, so that the technical headers are preserved, together with useful screenshots and a brief explanation of what happened. Never send passwords, verification codes, banking credentials or unnecessary client information.

Simple safeguards for every practice

The single habit that defeats this scam is precise rather than absolute. Never enter your email credentials into a page reached through an unexpected property enquiry. Open the relevant portal or service independently, using its known website or app, and locate the information from there. No genuine portal will ever ask for your email password to show you a listing or a Memorandum of Sale.

If you cannot locate the property independently, that is not automatic proof of fraud, since listings can be removed, off-market or agent-only. Ask for the full address and the selling agent’s details, then verify them through a separate and trusted route. A genuine buyer should normally be able to provide both, or explain why the information is not yet available.

Beyond that, turn on multifactor authentication today if you have not already, brief anyone else in the practice who handles enquiries, and let unprompted, overly elaborate detail in an enquiry raise an eyebrow without condemning it. Genuine buyers usually give you an address and ask what it costs.

Act rather than hide

These scams work not because professionals are careless, but because the criminal places the trap inside an ordinary and familiar working process. Surveyors are expected to respond to new enquiries, inspect property particulars and communicate quickly. The fraudster is exploiting good professional habits.

These emails are landing in surveyors’ inboxes now, through the very contact forms we rely on for work, and they are good enough to catch busy, capable people. If one arrives in yours, you will now recognise it. That is the whole point of this article.

Links and reporting routes checked against official sources on 6 August 2026.