Cyber attacks against UK property services businesses rose 17% to 208 in 2025, from 178 a year earlier, according to figures cited by Karis Insurance from the Information Commissioner’s Office.
The specialist property insurance broker said agents, surveyors and buy-to-let property managers are a growing target because they routinely hold identity documents, bank details, tenancy records and information connected with property transactions.
Property businesses can hold enough personal and financial information for a breach to affect both the firm and its clients. For landlords using an agent or manager, that makes data security part of the due diligence around who handles tenant records, deposits and payment instructions.
Data held by property firms can be valuable to criminals
Karis said criminals may use ransomware to lock a firm out of its own systems, steal identities or sell compromised data. Information connected with a sale can also be used in payment-diversion fraud, where a criminal attempts to substitute bank details during a transaction.
Ravi Sejpal, Director of Insurance at Karis Insurance, said property businesses often hold as much detail about their clients as a bank but may not have equivalent security arrangements. He said the sector had been slower than financial services and law firms to address the risk.
The ICO’s data-security incident trends explain that organisations must report qualifying personal-data breaches within 72 hours of discovery. Its published figures cover reports made to the regulator, rather than every attempted attack or every loss suffered by a property business.
Checks should cover agents and property managers
Landlords cannot audit an agent’s entire technical setup, but they can ask how documents are stored, who has access to them and how the firm verifies a late change to payment instructions. The answers are especially relevant when passports, right-to-rent evidence or bank information are being exchanged.
This follows Landlord Knowledge’s August report on Cifas figures showing mortgage fraud rising across its main categories. The two sets of data cover different problems, but both show why a request to change bank details or resend identity material should be checked through a known contact route.
Insurance can help with some of the financial aftermath of a breach, but it does not replace basic controls. Karis’s 17% comparison is based on ICO data for the year ended 31 December 2025, so landlords should not treat it as a measure of the current number of attacks or a forecast for 2026.
What this means for landlords
- If an agent holds your documents: ask how it protects identity, tenancy and bank data, and how it will contact you after a suspected breach.
- Watch for: unexpected emails asking you to change bank details, resend identification or use a new payment route.
- Bottom line: data protection is a practical risk for landlords as well as an issue for the firms that manage property information.
Editor’s view
Cyber security is easy to treat as an IT problem until a payment instruction or a passport copy is involved. Property firms that collect sensitive client data need clear controls, and landlords are entitled to ask how those controls work.
Author: Editorial Team – UK landlord & buy-to-let news, policy, and finance
Published: 14 September 2026
Sources: Karis Insurance, Information Commissioner’s Office data-security incident trends
Related reading: Cifas says mortgage fraud rose across every main category





Be the first to comment on "Karis: cyber attacks on property firms rise 17%"