Cybersecurity for Property Agents: 3 Mistakes That Can Expose Your Data
Property agents handle sensitive data daily. Learn 3 cybersecurity mistakes that can expose your clients, reputation and business.
Most property agents don't think of themselves as a cybersecurity target. You probably don't have a big IT department. You're not running a bank. You're not sitting on a server full of corporate secrets.
But look at the information that passes through your phone every day:
-
IC numbers
-
Bank statements
-
Loan documents
-
Contact numbers
-
Addresses
-
Sale and purchase documents
-
Rental agreements
-
Payment details
-
Photos of properties
-
Sometimes even screenshots of a client's online banking transaction
That's a lot of information. And once you start thinking about it that way, cybersecurity stops being something that only concerns big companies. It becomes part of being a property agent.
The risk isn't only that someone hacks your account. Your data can also be exposed because you:
-
Bought information from the wrong source
-
Failed to notice someone impersonating you online
-
Used the same password across several platforms
The consequences can be serious. Between 2023 and 2025, Malaysia recorded 52 property agent scam cases involving RM6.49 million in losses. And when a scammer uses a legitimate agent's name, photos or REN details, the damage doesn't stop with the victim who lost money. The real agent can end up spending days explaining that they had nothing to do with it.
So let's look at three mistakes that agents should be particularly careful about.
Mistake #1: Buying or Using "Master Lists" of Personal Data
If you've been in the property industry for a while, you've probably heard of "master lists". Someone has a list of property owners. Maybe it's a new development that recently completed Vacant Possession. Maybe it's a particular condominium. Maybe it's thousands of names and phone numbers covering an entire area. And someone says they can sell the list to you.
It can sound tempting. You get hundreds or thousands of potential contacts without having to spend months building a database yourself. But where did that information actually come from? If you don't know the answer, that's already a warning sign.
What Exactly Is a "Master List"?
These lists are often marketed as a shortcut to finding property owners. They may contain names, telephone numbers, property information and sometimes other personal details. The person selling the list may tell you that everyone on it owns a property in a particular development or that the information came from a legitimate source.
That doesn't automatically make it legitimate for you to use. The fact that someone's phone number is available somewhere does not mean you have permission to use it for whatever purpose you want.
The Problem Isn't Just Getting Caught
There is a tendency to think about this as a simple marketing question: "Will I get a listing from this?" That's probably the wrong question.
The better question is: "Am I allowed to have and use this person's information?"
Malaysia's Personal Data Protection Act 2010 (PDPA) regulates the processing of personal data in commercial transactions. Depending on the circumstances, collecting, using or disclosing personal information without the appropriate basis can create legal problems.
There can also be reputational consequences. Imagine receiving a call from someone who says: "Where did you get my number?" Now imagine dozens of people asking the same question. Even if you thought you were simply buying a marketing database, the person receiving the call doesn't know that. From their perspective, a stranger has their name, phone number and information about their property. That doesn't exactly create confidence in the profession.
The Short-Term Gain May Not Be Worth It
Maybe the list helps you find two owners who are genuinely interested in selling. But what happens if:
-
The source of the data is challenged?
-
The owner complains?
-
The information was obtained through a leak?
The opportunity may be real, but so is the risk. There is also a wider issue. Every time people buy and resell personal information without proper authorisation, it encourages the market for leaked data to continue. You don't want your own client's information being treated the same way.
Build Your Database Properly
A good database takes longer to build. That's also why it is more valuable.
Do this instead:
-
Get contacts through referrals
-
Use legitimate marketing campaigns
-
Let people opt in to receive information
-
Build relationships with owners and buyers over time
-
When someone gives you their information, know why you collected it and what you intend to use it for
-
Keep the records properly—use a secure CRM rather than having sensitive client information scattered across WhatsApp chats, phone notes and random Excel files
It may feel slower at the beginning. But at least you know where your data came from.
Mistake #2: Not Checking Your Online Identity
Here's something many agents don't think about until there's a problem. Someone searches your name online and finds a property listing using your photo. Your name is there. Your REN number is there. The property is real. Everything looks legitimate. Except the phone number belongs to a scammer.
How Impersonation Works
Scammers don't need to invent everything from scratch. They can take information that is already available online:
-
Your profile photo
-
Your property photos
-
Your name
-
Your REN number
-
Your agency details
Then they create another profile or advertisement using their own phone number. Sometimes they'll even advertise a genuine property. That's what makes these scams convincing. A potential buyer sees a real property, a real agent's photograph and a valid-looking REN number. They assume everything is fine.
The scammer arranges a fake viewing or communicates with the victim through WhatsApp before asking for a deposit or payment. If the victim loses money, who do they blame first? Often, the name appears on the advertisement. Which could be yours.
Don't Assume the Platform Will Catch Everything
Property portals and social media platforms have systems for dealing with fake accounts and fraudulent listings. But no platform catches everything immediately. You might only find out after a potential buyer calls you and says: "I already transferred the deposit. Why are you saying you didn't receive it?" That's a horrible phone call to get. And by then, the scam has already happened.
Search for Yourself
Every now and then, search your own information:
-
Your name
-
Your REN number
-
Your agency name
-
Your phone number
-
Look at property portals and social media
You can also do a reverse image search on your professional photograph from time to time to see whether someone has copied it. Even a quick check every few weeks or once a month can help you notice something unusual.
If you find a fake profile or advertisement, report it immediately and keep screenshots of what you found. It is also useful to keep your professional information consistent across your legitimate profiles. If your agency name, REN number and contact details are clearly displayed, it becomes easier for clients to compare information.
Make Verification Easy for Your Clients
If you're communicating with a new buyer, particularly someone who found your listing online, make it easy for them to verify that they're dealing with you. Tell them where they can check your professional registration details through the official channels. The goal is not to hide your identity. It's to make the genuine version easier to distinguish from the fake one.
Mistake #3: Weak Passwords and Ignoring Breach Alerts
This one is less exciting than a fake property listing. It's also one of the easiest problems to fix. If you're using the same password for your email, property portal, CRM, cloud storage and other accounts, you are making things much easier for an attacker.
The AuctionGuru Example
In March 2026, AuctionGuru.com.my was reportedly targeted in a major data breach. Reports indicated that names, email addresses, phone numbers, passwords, location information and payment history may have been exposed. For anyone involved in property, this is particularly concerning. Property-related information can be extremely useful to scammers.
A scammer who knows your name, phone number, email address and some details about your property activity can create a much more convincing message than someone who knows nothing about you. Instead of a random "Your account has a problem. Click here," they can make the message look like it relates to something you actually do. That's where things get dangerous.
Password Reuse Makes One Breach Much Worse
Suppose you use the same password on five different websites. One of those websites suffers a breach. The attackers now have your email address and password. They may try those same credentials on other services. This is called credential stuffing, and it's one reason security professionals keep telling people not to reuse passwords.
The problem becomes even more serious if the same password is connected to an email account. Your email is often the key to resetting other accounts. If someone gets access to it, they may be able to reset passwords elsewhere.
What You Should Do Instead
Start with these basics:
-
Use unique passwords for every important account
-
Use a password manager to generate and store strong passwords—you only need to remember one main password
-
Turn on multi-factor authentication (MFA) wherever it is available—a password alone is no longer enough to access the account
-
If you receive a warning that a service you use has suffered a data breach, don't ignore it—change the affected password immediately
-
If you've used that same password anywhere else, change it there too
Be Careful With What Comes After the Breach
After a data breach becomes public, scammers may use the leaked information to make follow-up scams look more convincing. You might receive a call from someone who already knows your name and some basic details about you. That doesn't prove they're legitimate.
Remember:
-
Never give someone your OTP simply because they know your name, IC number or other information
-
Don't click unexpected payment links
-
If someone is pressuring you to transfer money immediately, stop and verify through another channel
Cybersecurity Is Part of Being a Professional Agent
Cybersecurity can sound like an IT department problem. For property agents, it really isn't. You don't need to become a cybersecurity expert. You do, however, need to take reasonable steps to protect the information that comes into your hands.
That means:
-
Thinking twice before buying a database of personal information
-
Checking whether your name and REN number are being misused online
-
Using proper passwords and MFA instead of one password that you've been using since 2019
-
Taking breach notifications seriously
There is no perfect security system. What you can control is how exposed you are and how much damage can happen if something goes wrong. Your clients trust you with a lot more than the keys to a property. They trust you with information about their finances, their homes and sometimes their personal lives. Protecting that information isn't an optional extra. It's part of the job.