You have a closing Thursday at 2:00. The buyer is a first time purchaser who has been emailing you at 11 p.m. for six weeks. The lender cleared conditions yesterday. Your coordinator is chasing a survey, the title company is chasing a payoff, and there are forty seven messages in that thread with everybody copied. This is a normal week, and it is exactly what a specific kind of criminal counts on.
Wire fraud in real estate is not a general internet threat that happens to touch your industry. It is a targeted attack built around how closings work, aimed at the one moment when a large sum moves on instructions sent electronically. The defense is not technical and it costs nothing. It is a habit, practiced every time, by everyone in your office. Here is how the attack works and what stops it.
How the Attack Actually Works
The FBI calls this business email compromise, and every step is designed to look ordinary. Its own published example is precisely your business: a homebuyer receives a message from his title company with instructions to wire his down payment, and the message is fraudulent.
- They get inside a mailbox first. Usually a phishing message that harvests a password. The FBI notes criminals use spearphishing to appear to come from a trusted sender, and malware to reach billing threads and account details.
- They read and wait. People underestimate this part. The intruder sits quietly in an agent’s mailbox for weeks, learning the deals, the dates, and the tone everyone writes in.
- They pick the moment and send instructions that look right. They know your closing date and roughly the number, because it is in the thread they have been reading. The message often comes from a lookalike domain. The FBI names the technique: slight variations on legitimate addresses, the kind where one letter changes and nobody notices.
- They create urgency. A bank issue, a request to wire today so the closing does not slip. The FBI advises being especially wary if the requestor presses you to act quickly.
Then the money leaves, fast. The FBI’s Internet Crime Complaint Center reported in 2023 that from October 2013 through December 2022 it recorded 277,918 business email compromise incidents worldwide with more than 50.8 billion dollars in exposed losses. That same 2023 alert stated that between 2020 and 2022, victim reports involving real estate rose 27 percent and losses rose 72 percent, and that targets include buyers, sellers, real estate attorneys, title companies, and agents.
Why Closings Are the Target
Consider what makes a closing unusual compared to any other transaction a consumer will ever do.
- Large amount, public timing, hard to reverse. Closing dates are known to many parties, the figure is predictable from the contract, and no chargeback process exists to save it.
- Many independent parties. Buyer, seller, two agents, two brokerages, a lender, a title company. Any one compromised mailbox gives a view into the deal.
- The consumer is inexperienced by definition. A buyer does this once every several years, so an unusual request does not feel unusual.
- Everyone expects last minute changes. Things genuinely do change on closing day, and that normalcy is what the attacker borrows.
The Verification Ritual That Stops It
This is the part that matters most, and it is almost aggressively simple. The defense is a phone call, made the same way every time, with no exceptions for busy days. The FBI’s guidance is direct: verify payment requests by calling the person to confirm it is legitimate, and look up the company’s phone number on your own rather than using the one a potential scammer provides.
- Call before every wire, not just suspicious ones. The attack works because the message does not look suspicious. If verification only happens when something feels off, it will not happen on the day it matters.
- Use a number you already had. From the title company’s website, the contract, or your contacts. Never the number in the email requesting the wire.
- Treat any change to instructions as a stop sign. Legitimate wiring instructions rarely change. The FBI’s Internet Crime Complaint Center recommended in 2023 using secondary channels to verify any requested change in account information.
- Verify the account details out loud. Read the routing and account numbers back. Do not just ask whether the email is real, because a compromised mailbox answers that too.
- Examine the sending address every time. The FBI advises carefully examining the email address, URL, and spelling in any correspondence. Lookalike domains are the whole trick.
Warn Your Clients in Writing, Early
Your buyer holds the money and is least equipped to spot the attack. Warning them once at a busy signing is not enough. Put it in writing early, before there is anything to steal.
- Send the warning at contract execution, not at closing. By closing week the buyer is overwhelmed and skimming everything you send.
- State the rule in one plain sentence. We will never send wiring instructions by email, and you should call our office at a number you look up yourself before sending money to anyone.
- Repeat it in your signature and at the walkthrough. A standing notice costs nothing, and repetition is the point.
- Tell them what to do if it happens anyway. Contact their bank immediately and report it to the FBI’s Internet Crime Complaint Center at ic3.gov. Speed matters enormously in whether funds are stopped.
The Everyday Basics Underneath All of It
The verification call is the last line of defense. Attackers get that close because of a compromised mailbox, so close that door too.
- Multi factor authentication on every agent email account. The highest value thing you can do. CISA states in its Cyber Guidance for Small Businesses that users who enable multifactor authentication are much less likely to get hacked, and recommends enforcing it rather than asking people to opt in. Our comparison of keys, passkeys, and app codes covers which to pick.
- Agents on company email, not personal accounts. If an agent runs the business from a free personal mailbox, you cannot enforce settings, see a compromise, or shut off access the day they move brokerages.
- Train the office on phishing without shame. The people who fall for these are not careless. The messages are good. We wrote about why phishing is so hard to block: filters help but do not finish the job.
- Stop sending client documents as plain attachments. Licenses, bank statements, and tax returns move through your office constantly. A portal keeps them out of mailboxes that may later be compromised.
The Bottom Line
Wire fraud is the rare risk where the fix is cheaper than anything technology can sell you. Call the title company at a number you looked up yourself, before every wire, every time. Treat any emailed change to wiring instructions as false until a call proves otherwise. Warn clients in writing early and again out loud. Then close the door behind it with multi factor authentication on agent email.
An office where the verification call is simply what everyone does, without discussion, is an office where this attack fails. That is not a purchase. It is a decision you make this week.
One note on scope: this article is general information, not legal or compliance advice. Requirements that apply to your brokerage, license, or handling of funds depend on your circumstances, and a qualified advisor should confirm what applies.
We work with real estate offices across Denton County. We can get multi factor authentication in place, tighten up email, and give your team a document workflow that does not rely on attachments. If you want someone to review how your office handles closing communications and say plainly where the gaps are, we are glad to help. Contact us today.
Sources:
Comments are closed