Insights · Cybersecurity

Phishing in the notarial sector: why your office is a target.

Large sums, heavy e-mail traffic and time pressure: to a fraudster, a notary office is an interesting address. Here is how to recognise the attack, and how to make it fail.

22 September 2026·7 min read·Exon ICT Group

To a fraudster, a notary office is an interesting address. Large sums pass through it, dozens of e-mails are exchanged daily with banks, clients and fellow notaries, and the pressure to respond quickly is part of the job. It is precisely that combination that makes phishing so effective in the notarial sector. This article explains what the attacks look like today, how you recognise them, and what an office actually does to avoid falling for them.

Why your office is a target

The attacker is rarely after your computer. They are after three things a notary office has in abundance.

  • Money in transit. Deed funds, deposits, balances on the third-party account. Whoever can get an account number changed at the right moment needs to hack nothing else.
  • Trust. An e-mail that appears to come from "the notary" is followed without hesitation by a buyer or seller. Attackers abuse your name to rob your own clients.
  • Confidential files. Whoever gains access to your mailbox reads along with ongoing transactions and knows exactly when and to whom to send their fake e-mail.

What phishing looks like today

The typo-ridden e-mail from an unknown prince still exists, but nobody falls for it anymore. The attacks that do succeed look like this:

  • The hijacked conversation. The mailbox of a party in a file (an estate agent, a bank, a fellow notary) has been compromised. The attacker replies within an existing e-mail thread, with the right tone and the right attachments, and reports "a new account number".
  • The fake notary. Your client receives an e-mail that appears to come from your office, asking them to transfer the balance to an account that is not quite yours. The sender is a domain that differs by one letter from the real one.
  • The fake login page. "Your password is expiring", "a document is waiting for you", "your mailbox is full". The link leads to a perfect copy of the Microsoft sign-in page. Whoever enters their password there hands the attacker their mailbox.
  • Outside e-mail. A QR code on a letter, a text message from "the bank", a call from "the IT supplier" who needs to log in quickly. The channel changes, the trick does not.

What these attacks have in common: they are flawlessly written, they know your files, and they arrive at a moment when you are busy.

How you recognise them

No single feature is conclusive on its own, but together they are:

  • Urgency. Today, before noon, or the sale falls through. Pressure is the fraudster's tool.
  • A change of payment details. A new account number, "because the other account is blocked". This is always an alarm signal, without exception.
  • A request to log in. A genuine service never asks you by e-mail to confirm your password through a link.
  • The address behind the name. The sender's name says nothing; the e-mail address and domain do. Look at them before you reply, especially on a phone, where that address is hidden.
  • A link that goes somewhere else. Hover over the link without clicking and read the address. If the domain is wrong, the e-mail is wrong.

What an office actually does

Protection works on three levels at once. Skip one and you leave a door open.

Technology

  • Two-step verification on every account, without exception, and preferably a variant that cannot be phished (a physical key or an app with number matching). This is by far the measure with the greatest effect: a stolen password is then worthless.
  • Your own domain protected with the standards that prevent spoofing of your sender address. That makes it much harder for an attacker to send e-mails "on behalf of your office".
  • A mail filter that thinks along and stops dangerous attachments and links before they reach an inbox.
  • A backup out of reach, in case a click does lead to ransomware after all. We wrote about that in the article on downtime.

Rules

  • Payment details are never changed by e-mail. Every change is confirmed by phone, via a number the office already knew, not the number in the e-mail.
  • Four eyes on every transfer above an agreed amount.
  • Clients are told in advance: at the first appointment or in the engagement letter, it states that the office never communicates a different account number by e-mail. One sentence that prevents a lot of misery.

People

  • Short, repeated training instead of one long session a year. Twenty minutes a quarter, with real examples from the profession.
  • A culture in which reporting is normal. Whoever clicked and says so immediately limits the damage to a password change. Whoever hides it out of embarrassment gives the attacker days of head start.

If it happens anyway

Speed matters. Change the password of the affected account immediately and sign out all active sessions. Notify your IT partner. Check whether forwarding rules have been created in the mailbox, because that is the first thing an attacker does. If money has been transferred, call the bank at once; in the first hours a transfer can sometimes still be stopped. File a report with the police. And do not forget the notification duty: if clients' personal data may have been viewed, it must be reported to the Data Protection Authority within 72 hours.

The question is not whether someone in your office will ever click a wrong link. That happens everywhere. The question is what happens next, and that is something you do control.

Three questions to ask today

  1. Is two-step verification switched on for every mailbox in the office, including the notary's own?
  2. What do we do when an e-mail announces a new account number, and does everyone know that?
  3. Do our clients know that we never change an account number by e-mail?

Three times yes is an office that is hard to rob. Every no is a concrete first step.

How vulnerable is your office?

In a free audit we look at your two-step verification, the protection of your domain, your mail filter and your rules around payments. You get a clear picture, no obligation.

Schedule your free IT audit
← All articles