Regulator flags AI deepfakes as a growing threat to client verification
The SRA has warned that AI-generated deepfakes are becoming a credible threat to client verification across the legal sector. For conveyancers, this is not an abstract technology story. Property transactions involve high-value, largely irreversible transfers to parties the firm has often never met in person, which makes them an obvious target for identity fraud.
Why conveyancing sits in the firing line
Three features make property work attractive to fraudsters. The sums are large. The timelines are compressed, so pressure to move quickly is built into the process. And much of the interaction is remote, conducted by email, portal and video call. A fraudster does not need to defeat every control in a firm's file. They need one plausible seller and one set of bank details accepted without challenge.
Historically the weak point was the forged passport or the utility bill that did not quite match. Generative tools have shifted the problem. Convincing document images can be produced at scale, and live video calls can now be manipulated in real time with software that is neither expensive nor difficult to operate. The reassurance of "I saw them on screen and they looked like their photo ID" no longer carries the weight it did even two years ago.
What a deepfake attack on a transaction looks like
The most likely pattern is not exotic. A fraudster identifies an unencumbered property, often owned by someone living abroad, in a care setting, or at a different correspondence address. They instruct a firm as the registered proprietor, supply synthetic or manipulated identity documents, and complete a remote verification call using a manipulated video feed. The property is marketed slightly below value to attract a quick sale. Completion monies are then directed to an account that is closed within hours.
The second pattern is interception rather than impersonation. Email is monitored, and late in the transaction a request arrives to update account details, sometimes supported by a voice note or short video that sounds and looks like the client. Synthesised audio requires very little source material to be persuasive.
Practical steps for firms to review now
Verification should be layered rather than sequential. If identity rests on a single document check and a single video call, there is one point of failure. Consider what corroborating evidence you hold: length of ownership, connection to the property, consistency of the correspondence address with the register, and whether the transaction's economics make sense.
Electronic verification that includes liveness detection and cryptographic checks on document chips is materially harder to defeat than visual inspection by a fee earner. It is also more defensible in a claim, because it produces an auditable record of what was checked and how.
Treat any change to bank details as a red flag by default. Verify the change by calling a number you already hold on file, obtained independently of the email requesting the change, and never a number supplied in that correspondence. Where possible, confirm account details early in the matter and record that they will not be changed, so a late request stands out.
Look closely at transactions with recognised risk markers. An unregistered or long-held title with no mortgage, a seller who cannot attend in person, unusual urgency, instructions that arrive fully formed with an estate agent already appointed, and pricing that undercuts comparables all warrant additional scrutiny.
Finally, train staff on what these attacks now look like. Fee earners are still being told to watch for spelling errors and mismatched fonts. Those signals are disappearing. The more durable defences are process-based: independent verification of instructions, dual authorisation for payments, and a culture where slowing a transaction down to ask a question is treated as good practice rather than an obstruction.
Documenting the decision
Regulators and insurers will ask what the firm did and why. A note explaining which checks were run, what risk factors were identified, and how they were addressed is worth considerably more than a scanned passport in the file. Where a check produced an inconclusive result, record how that was resolved.
The technology available to fraudsters has improved faster than most verification processes have been reviewed. A short internal audit of how your firm confirms seller identity and bank details is a sensible use of an afternoon.
See how Searchpoint supports faster, better-documented client verification across your property files.