UK solicitors
31.4% grade D or worse
Completion-money fraud starts with a spoofed email. A criminal who can send mail that appears to come from a firm can redirect a house purchase, and the money is usually gone the same day. Email authentication is the control that stops it, and it is the one most often left incomplete.
See the numbersUK estate agents
57.6% grade D or worse
Deposit diversion is the same attack wearing a different hat: an email that looks like it came from the agent, sending a tenant or buyer to the wrong account. High transaction values and a lot of email between strangers make this sector a standing target.
See the numbersUK online retailers
27.8% grade D or worse
Two mandates land on the same page. PCI DSS 4.0 requires every script on a payment page to be inventoried and watched for change, and accessibility law is being litigated hardest against online retail. Both are checkable from outside, which means a complainant can check them too.
See the numbersUK accountants
38.7% grade D or worse
Invoice fraud and client-data duty in one place. A practice sends payment instructions and holds financial records for dozens of businesses, so a spoofable domain is not a theoretical risk to them, it is a risk to every client on their books.
See the numbersUK charities
24% grade D or worse
Donation pages take card details and donation fraud is common, because a fake appeal from a real-looking charity address is unusually persuasive. Charities also run on small teams and donated time, which is exactly where certificate and DNS drift goes unnoticed.
See the numbersWe publish sector averages only. Individual results are never shown, named or linked, and we do not publish findings about any specific organisation.