S.01Notaries and notarial offices

Penetration testing for notaries who move completion funds.

A notarial office holds the three things a fraudster needs: the date a large payment is due, the identity documents of the parties and the authority to make a deed authentic. Darkmoon tests the email accounts, deed-drafting software, remote-signing chain and remote access of the office the way an attacker would, then proves which paths lead to the funds or the files. Managed end to end by ASC-IT's security experts, legal framework included.

72 h
GDPR Art. 33 window to notify a personal-data breach
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools
OTP
secure client space for the report

S.03Professional services
Why notarial offices are a payment-fraud target first.

Civil-law notaires and notaries public differ by country, but the attacker's view is the same: a trusted intermediary whose email announces when money moves and whose files contain everything needed to impersonate the parties.

New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Completion-day payments are announced in advance

Buyers wire the price, sellers wait for the proceeds, lenders release the loan: every amount and date sits in the office's mailbox weeks ahead. A substituted account number sent from the right thread the day before completion is the most profitable email an attacker can write. Whether the office handles a conveyancing completion in England or a real-estate closing with escrow in the United States, the pattern is identical.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Identity documents and deeds enable impersonation

Passports, proof of address, powers of attorney, title documents and estate inventories let a fraudster pose as a seller or heir elsewhere, or forge a deed. The exfiltration itself is quiet; the damage appears months later.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Electronic deeds depend on a signing chain

Deeds signed on tablets, remote-appearance sessions over video, electronic archives: each link (certificate, session invitation, document upload) is a new place where the authenticity of an act can be attacked.

Attack surfaceexposure

A profession rated weak by the national cybersecurity agency

In January 2025 the director general of ANSSI, the French national cybersecurity agency, described notarial offices' security level as 'globalement faible' and warned about forged deeds, according to trade-press reports. The pattern is not specific to France.

S.04Attack surface
Six systems where an office loses funds or files.

Darkmoon starts from the identity of the notary and the clerks and follows every system that trusts it: the mailbox, the deed software, the signing session, the ledger.

Email
Office mailboxes and payment instructions

The mailbox that announces completion dates and account numbers: MFA gaps, forwarding rules, look-alike domains, and the absence of a second channel to confirm payment details.

Deed software
Deed-drafting and case-management software

The software families that draft deeds, store client files and feed electronic archives: web front ends, local servers, update channels and the shared accounts clerks use.

Remote signing
Remote-signing and remote-appearance sessions

Video-appearance platforms, electronic-signature services and the session invitations sent by email: identity checks, link handling, document upload and the certificates behind the signature.

Office accounts
Client-funds ledger and banking access

The accounting system that holds client funds and issues transfers, the banking portals it connects to, and the approval steps between a payment instruction and the wire.

Remote access
VPN, remote desktop and home working

Clerks and notaries working from home through VPN appliances or remote-desktop gateways, often with a single factor kept for an older application.

Third parties / cloud
Third-party services and cloud storage

Video providers, electronic archiving, cloud file storage, IT providers with standing access: tokens, shared folders and accounts that outlive the matter they served.

S.05Attack paths

From a clerk's mailbox to a diverted completion payment.

The chains we walk in an engagement, each step kept as evidence. Client names, hostnames and credentials are tokenized before anything reaches the model.

01
Mailbox compromise to substituted account details

A phished clerk password and a forwarding rule on the words 'completion' and 'wire'. The attacker learns the date and amount, registers a look-alike domain and sends the buyer 'updated' account details from the thread they already trust. Darkmoon tests the MFA coverage, mailbox rules and domain hygiene this chain depends on.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests in a notarial-office engagement.

Fifty specialist agents and 142 tools behind a build-enforced allow-list, on the scope you authorize. Every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED with the request, payload or screenshot that proves it.

M365 / identity
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Identity and email

MFA coverage and bypass paths, legacy protocols, forwarding rules, look-alike domain exposure, OAuth grants and the privileged roles of the office tenant.

Web / API
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Deed, signing and client-facing web applications

Deed-software front ends, client portals, remote-signing and appearance platforms under the office's control, document upload and session handling, API endpoints and integrations.

VPN / AD / cloud
Attack surfaceexposure

Remote access, internal network and third parties

Exposed VPN and remote-desktop services, Active Directory paths to the deed and file servers and backups, cloud storage shares, standing access of IT and archiving providers.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your data stays on your side of the line.

The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, and rehydrates it locally. Self-host the whole engine with a local LLM, or let our experts run the managed engagement: in both cases the evidence stays in a space you control.

S.10Regulatory context
Not a NIS2 sector, bound by an absolute secret.

Notaries are not a sector listed in NIS2 Annex I or II. Their security duties come from professional secrecy, from the rules governing electronic deeds, from GDPR and from the expectations of lenders, insurers and the profession's own bodies, which publish cybersecurity guidance.

Professional secrecy: the French example

For French notaires, art. 23 of the loi du 25 ventôse an XI restricts disclosure of deeds to the interested parties, and art. 8 of décret n° 2023-1297 (code de déontologie) states that professional secrecy is general and absolute and binds everyone working under the notary's authority. Most jurisdictions impose a comparable duty on notaries by statute or professional code.

Electronic authentic acts

In France, décret n° 2005-973, modified by décret 2020-395, governs deeds drawn up on electronic support, their signature and their conservation, including remote appearance. The authenticity of an act now depends on an IT chain whose weakest link can be tested.

GDPR Articles 32 and 33

Article 32 requires appropriate technical and organisational measures proportionate to the risk; Article 33 requires breach notification to the supervisory authority within 72 hours. Identity documents, estate and matrimonial data are among the most sensitive files an office holds.

NIS2 reaches offices only through others

Where a lender, institutional client or public body is itself a NIS2 entity, Article 21(2)(d) obliges it to manage supply-chain security, and a notarial office may receive questionnaires or contractual requirements. The directive itself does not list notaries.

This section describes the legal context as of October 2026 and is not legal advice: confirm your obligations with your professional body and counsel. Darkmoon does not certify compliance; it produces documented, reproducible findings you can present to partners, insurers or your chamber as part of your evidence base.

S.11Use case
A notarial office after a near-miss on a completion payment.

A buyer calls the office to confirm 'new account details' received by email the day before completion. The payment is stopped in time, but the partners want to know how the attacker read the thread. They order a managed engagement on the office mailboxes, the deed software's web front end, the remote-desktop gateway and the cloud storage. Darkmoon finds a clerk account without a second factor, a forwarding rule created from an unknown location, and a cloud folder of identity documents shared by public link.

Outcome

Exploited findings with evidence, a debriefed report in the secure client space, a fix plan for the IT provider, and a payment-confirmation procedure the office can show to lenders and its insurer.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What a notary asks first.

Can a penetration test touch systems that hold deeds and identity documents?

Yes, within a signed authorization. The engagement starts with a test authorization, scope and liability clauses signed electronically, and the office decides which systems are in scope. Exposure is confirmed on test matters and test accounts, the evidence stays in a client space you control, and the Privacy Gateway tokenizes hostnames, emails and credentials before anything reaches the model.

Does NIS2 apply to notaries?

Notaries are not a sector listed in NIS2 Annex I or II. The directive reaches an office indirectly when a lender, institutional client or public body that is itself an essential or important entity passes supply-chain requirements down under Article 21(2)(d). Your direct duties come from professional secrecy and GDPR Article 32.

Do you test the remote-signing platform?

We test what the office controls: the accounts, invitations, document uploads and integrations of the signing and appearance platforms it uses, on test matters. The platform provider's own infrastructure is outside the scope unless the provider authorizes it.

Can you test the completion-funds workflow, from exchange to the wire?

Yes, on the part the office controls. Whether you call it a conveyancing completion or a real-estate closing with escrow, the chain is the same: the mailbox that announces the date and the account details, the approval steps between a payment instruction and the wire, the banking portal access and the second channel used to confirm a change of account. We test MFA coverage, mailbox rules, look-alike domain exposure and the approval logic on test matters; the bank's own systems stay out of scope. The report documents the path and the control that was missing.

How much does it cost and how long does it take?

The Pentest on Demand flat rate is €799 per engagement, shown upfront and adjusted to the final scope after the scoping call. The timeline is set in the contractual framework and typically runs a few business days after scoping.

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Find the path to the completion funds before a fraudster does.

Order a managed engagement on your mailboxes, deed software and remote access, or talk to the team about the scope first.