Real estate and title firms
Wire fraud at closing: how it happens and how to stop it
· PS ProTech · 4 min read
A real estate closing has everything a fraudster wants. A large sum moves on a known date. The people involved are strangers to each other. The instructions travel by email. And once a wire is sent, it's very hard to get back.
This article walks through how the fraud is run, so you can see where it can be broken.
The playbook
Step one: get into a mailbox. The attacker needs to read one person's email: the agent, the title officer, the closing attorney, or sometimes the buyer. A reused password or a convincing sign-in page is enough. Nothing visible happens next.
Step two: watch. For days or weeks, they read. They learn which deals are pending, who the parties are, what the amounts are and when each closing is scheduled. They may set a forwarding rule so messages reach them even after a password change.
Step three: strike at the right moment. A day or two before closing, the buyer receives an email that looks exactly like the ones before it. Same names, same signature, same file number. It says the wiring instructions have changed.
Step four: the money moves. The buyer wires their down payment, or the lender wires the loan proceeds, to an account the attacker controls. It's forwarded onward within hours.
Nobody notices until the real closing, when the funds aren't there.
What AI has added
The playbook isn't new. Two things about it are.
The emails are flawless. AI writes in the exact style of the person being impersonated, because it has their real messages to learn from. The old tells, awkward phrasing and odd formatting, are gone. We cover this shift in how AI changed phishing.
The phone call can be faked too. A careful buyer who calls to confirm may reach a number from the fraudulent email and hear a cloned voice confirm the new account. The FBI has warned that criminals clone voices to impersonate people and get access to money (FBI public service announcement). We explain the defense in the call-back rule.
Payoff fraud works the same way in the other direction. A forged payoff letter sends the seller's mortgage payoff to the wrong account.
Where to break it
Each step can be stopped. The more of these you have, the less depends on any one of them.
Keep attackers out of the mailbox
- Multi-factor authentication on every email account, including agents who use personal addresses for business. A stolen password alone then isn't enough. See why this comes first.
- Email filtering that catches impersonation and fake sign-in pages before they reach anyone. See email security.
- Alerts on suspicious account activity, such as a sign-in from another country or a new forwarding rule. These are the signs of step two.
- Dark web monitoring, so you know when a staff password has leaked. See dark web monitoring.
Make the fake instruction fail
- Send wiring instructions once, through a secure method, and tell every party at the start that they will not change.
- Put the warning everywhere. In the first email, on the instructions themselves and in every signature: "We will never change wiring instructions by email. Call us on a number you have verified before sending funds."
- Verify by phone, using a known number. Before any wire goes out, someone calls the recipient on a number taken from an earlier, trusted source. Never from the message that contains the instructions.
- Confirm receipt. Call when the wire should have arrived. Fraud caught within hours can sometimes be reversed. Fraud caught at closing usually can't.
Train the people in the chain
Everyone who handles a closing needs to know this playbook, including part-time and seasonal staff. Short, regular sessions work better than an annual one. See security awareness training.
If it happens
Speed decides whether the money comes back.
- Call the sending bank immediately and ask for a wire recall. Then call the receiving bank's fraud department.
- Report it to the FBI at ic3.gov as soon as you can, with the transaction details.
- Tell your underwriter and your insurer.
- Change the passwords on every mailbox involved and check for forwarding rules you didn't create.
Who carries the loss
Buyers and sellers who lose closing funds often look to the professionals involved to make them whole. Whether your errors and omissions coverage responds depends on your policy, and some limit or exclude this kind of loss. Read yours before you need it, and ask your insurer which controls they expect. We cover that conversation in what cyber insurers ask.
This is general information, not legal advice.
Where to start
If you run a brokerage, a title agency or a closing practice, three controls do the most: multi-factor authentication on every mailbox, a written call-back rule, and the warning line in every email. Our page for real estate and title firms covers the rest.
To see where your firm stands, book a free IT and cybersecurity review.
