You hold the keys — and every applicant’s identity.
A rental application is a complete identity kit: photo ID, payslips, bank statements, references. A sales settlement moves six or seven figures through a trust account. Both make agents and hire businesses a first-choice target — and covered real-estate services now have AML/CTF obligations.
Dossier 08 / 10
Rental, Hiring & Real Estate
Every tenancy application is a complete identity kit — ID, payslips, bank statements — and every settlement moves through a trust account an attacker would love to redirect.
- Privacy Act 1988 / APPs
- AML/CTF Act (Tranche 2 reforms)
- State agents' Acts & trust-account rules
What the obligation actually requires of you.
- 01
Privacy Act 1988 / APPs
Where the Privacy Act applies, tenancy applications, ID documents and financial records require reasonable protection. Holding information longer than needed or leaving it in an unsecured portal increases exposure.
- 02
AML/CTF Act (Tranche 2 reforms)
Australia's Tranche 2 AML/CTF reforms extend reporting-entity obligations to real-estate businesses providing covered designated services. Those entities must verify customer identity, keep records and report suspicious transactions — controls that only work if the systems underneath them are secure.
- 03
State agents' Acts & trust-account rules
State agents' Acts and trust-account rules put licensed money in your care. A redirected settlement or a compromised trust-account instruction is both a client loss and a licensing risk, so payment-change verification is not optional housekeeping.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A deposit targeted for the wrong account.
Illustrative scenario — In this example, An agency's property-management inbox was accessed through a reused password with no MFA. The attacker sat quietly, learned the settlement cadence, then emailed a buyer's conveyancer with 'updated' trust-account details days before settlement.
Example response — A suitable response is to hold the transfer, call back on a known number, review mailbox and trust-account access, and document the verification before releasing funds.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, then see the priorities.
Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
Real Estate, Rental & Hire Cybersecurity Checklist
Complete each control to see your prioritised plan before submitting.
The questions this vertical always asks.
Because you hold high-value trust accounts and complete identity documents on hundreds of applicants, with controls that are often lighter than a bank's. That combination — big money, rich data, lean defences — is exactly what payment-redirection fraud looks for.
Covered designated services are now within the AML/CTF regime. Check whether your services are in scope and align customer verification, record-keeping and reporting with AUSTRAC guidance.
Verification by a second channel, every time. We enforce a policy that any change to payment or bank details is confirmed by phone on a previously known number before funds move — a practical control for reducing payment-redirection risk.
Find out exactly where your agency’s trust account is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au