Penetration testing for letting agents and property management companies in the UK
Letting agents and property management companies occupy an increasingly digital position in the UK property market. Tenant applications, referencing, tenancy agreements, rent collection, deposit management, and maintenance coordination are all conducted through web-based platforms — many of them custom-built or lightly configured third-party systems that have not been security reviewed.
What data letting agents hold
Tenant data is particularly sensitive. Applications collect proof of identity, employment details, salary information, bank statements, previous landlord references, and credit check results. This is exactly the dataset that enables identity fraud, and it is held in volume.
Landlord data includes bank account details for rent transfers, property valuations, mortgage information, and personal contact details. The combination of tenant and landlord banking information makes letting agent systems attractive targets for financial fraud.
The fraud risk specific to property management
Rental fraud targeting tenants is a documented threat. Criminals who compromise a letting agent's email or website can impersonate the agent, advertise properties at attractive prices, collect holding deposits and advance rent from multiple victims, and disappear. The letting agent's domain and brand are used to make the fraud credible.
Payment redirection fraud targeting landlords is a growing problem. Attackers who compromise communications between letting agents and landlords can intercept rent payment instructions and redirect funds.
GDPR obligations for letting agents
Letting agents are data controllers for both tenant and landlord personal data. The volume of financial information processed — bank statements, salary details, credit check results — means letting agents handle data that the ICO considers sensitive.
GDPR requires letting agents to implement appropriate technical security measures, maintain records of data processing, and report breaches involving personal data within 72 hours.
Common vulnerabilities
Tenant portal applications are the primary external attack surface. Applications that accept file uploads — payslips, bank statements, passports — need to be tested for file upload vulnerabilities and injection attacks in the surrounding form fields.
Email systems without SPF, DKIM, and DMARC records enable the domain spoofing that facilitates rental fraud and payment redirection attacks.
Property management software accessed through web browsers may have authentication weaknesses, particularly where multiple staff members share credentials.
How Yrzo AI helps
Yrzo AI runs 44 automated security checks against your letting agency's web presence, identifying vulnerabilities in tenant portals, email authentication gaps, and authentication weaknesses. Starting at £399 with a full plain-English report in under 20 minutes.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →