How business email compromise diverts a payment

How business email compromise diverts a payment

Every professional who moves money in a deal — broker, agent, closing attorney, title agent, advisor — is a named target in the most financially damaging form of cybercrime operating today. Business email compromise does not smash a window or trip an alarm. It slides into the most ordinary-looking part of a transaction: the email thread everyone is already reading. By the time the payment lands in the wrong account, the fraud is finished, and the professional left explaining what happened is the one whose name was on the email. This article pulls apart the full BEC playbook — exactly how attackers get in, how they wait, how they strike, and what defenses actually break the chain before a payment leaves.

What BEC actually is, and why it works so well on deal professionals

Business email compromise is a targeted social engineering attack that exploits trust in corporate email systems to manipulate people into initiating unauthorized transactions or disclosing sensitive information. That description is technically accurate but understates the craft involved. A BEC attack on a real estate transaction or a commercial deal closing is not a generic phishing blast. Attackers research the organization to identify executives, finance staff, vendors, payment patterns, and ongoing projects. Much of that information is publicly available or for sale on the dark web as a result of a prior breach, and cybercriminals use it to craft bespoke messages that look routine and expected.

This is why the threat lands so hard on deal professionals specifically. The sector remains a target for BEC attacks exploiting the high monetary values generally associated with real estate transactions and the various communications between entities involved in the title and closing processes. A closing attorney, a title agent, or a broker is at the center of a communication web that includes buyers, sellers, lenders, co-brokers, and advisors — all of them exchanging wire instructions, account numbers, and deal timelines over email, under time pressure, often across multiple transactions simultaneously.

The uncomfortable truth is that traditional defenses — spam filters, malware detection, domain checks — were never designed to catch business email compromise. Most BEC emails don’t carry attachments or malicious links. They are clean, well-written text messages that leverage existing relationships, accurate deal details, and plausible authority. In many successful cases, the emails were well written, cleanly formatted, and devoid of technical red flags — no links, no attachments, no misspellings. That is what makes the attack so difficult to intercept: it looks exactly like legitimate business communication because it has been engineered to.

The scale of the problem

The numbers are not hypothetical. The FBI’s IC3 logged 24,768 BEC complaints in one year alone, with $3.05 billion in reported losses. According to the FBI, only 15% of all wire fraud incidents are reported — meaning the real exposure is a multiple of what the federal data shows. Within real estate specifically, there were 9,359 real estate and rental fraud complaints in one year, resulting in losses exceeding $173.6 million. In real estate, the average business email compromise incident results in losses of $150,000 to $200,000.

From one measured period to the next, there was a 27% increase in victim reports of BECs with a real estate nexus, and in that same period, there was a 72% increase in victim loss from those attacks. The attacks are growing in frequency and the per-incident losses are growing faster. The American Land Title Association reports that nearly 30% of title companies experienced an attempted BEC attack in the last year. One in three. That is not a tail risk. That is a near-certainty across any meaningful book of business.

The most common victims of impersonation were individuals and entities involved in the title and closing processes within a real estate transaction. Title agents, closing attorneys, and escrow professionals are not collateral damage in these attacks. They are the primary impersonation target, precisely because everyone else in the deal trusts them.

The full attack sequence: how BEC actually unfolds

Understanding that BEC attacks are targeted and sequenced is the first step toward disrupting them. The attack does not start the moment the fraudulent wire instruction appears. By that point, the attacker has been working the transaction for days, sometimes weeks.

Phase 1: Reconnaissance

Fraudsters exploit the fast-paced, detail-oriented nature of property transactions to infiltrate communication chains and redirect financial transactions for personal gain. Cybercriminals gather information about the target organization and its personnel via public sources, social media, and data breaches. For a deal professional, reconnaissance means the attacker is reading public records to identify pending transactions, monitoring LinkedIn to map out which broker works with which title company, and cross-referencing any breached credential databases that contain email and password pairs from prior incidents.

In a typical scenario, cybercriminals identify a pending transaction and then build a profile of the parties — including the title company, real estate agents, and the buyer and seller. By the time reconnaissance is complete, the attacker knows the deal: the parties, the approximate closing timeline, the dollar amount, and who communicates with whom. This is the intelligence that makes every subsequent step convincing.

Phase 2: Initial access — compromise or spoof

The attacker now needs to get into the email thread. There are two fundamentally different methods, and each has distinct defense implications.

Account takeover (Email Account Compromise): Credential theft remains the most common entry point. Phishing campaigns harvest login credentials for email accounts that lack strong authentication. Once attackers have valid credentials, they operate from legitimate infrastructure, and every email they send passes SPF, DKIM, and DMARC checks. This is the most dangerous variant because there is no technical signal that anything is wrong. The email comes from the real account, with the real signature, from the real server.

Once inside a legitimate account, attackers move quickly and quietly. Once inside, attackers often set up elaborate email rules to conceal their activities and maintain persistent access. A common post-compromise tactic is creating inbox rules that automatically move certain replies — particularly any messages from the target’s bank, clients, or co-professionals — to a folder the legitimate user never sees. Creating inbox rules to hide security alerts or vendor replies is a signature behavior of account takeover. The legitimate user continues receiving most of their email and notices nothing unusual while the attacker reads, monitors, and waits.

Attackers may deploy malicious OAuth applications with delegated permissions that allow persistent API access without credentials. OAuth tokens maintain access even after password changes, surviving standard credential reset remediation. A forced password reset — the default incident response action — doesn’t actually remove the attacker. This is a critical operational detail: if you discover a compromise and simply reset a password, the attacker may still be inside via persistent token access.

Domain spoofing and lookalike domains: Where account takeover isn’t available, attackers manufacture the appearance of legitimacy. Spoofing involves creating email addresses that closely resemble legitimate ones — for example, replacing an “m” with an “rn” or using a different domain (.biz or .net instead of .com). Attackers now employ sophisticated techniques like typosquatting, homograph attacks using international characters, and subdomain abuse to create convincing domain variations.

Dozens of domains look like yours; it’s hard to track them all. Attackers take this opportunity to buy these lookalikes and appear legitimate to unsuspecting users. Display name manipulation compounds the problem further. A spoofed display name — a familiar name masking an external address — or a personal email substitution where an “internal” request comes from Gmail or Yahoo instead of the corporate domain, both work because many email clients emphasize the display name, and many recipients scan rather than verify.

On a mobile device, the problem is worse. Most mobile email clients show only the display name by default. A professional checking their phone between meetings sees “Sarah Cline — First American Title” and nothing else. The actual sending address — sarahcline@firstamerican-title.net, registered three days ago — is invisible.

Phase 3: Surveillance and timing

Whether via account takeover or lookalike domain, the attacker’s next move is to wait and watch. Once inside the communication thread, they monitor the transaction quietly — sometimes for weeks — learning the closing date, the title company, the lender, and the exact dollar amounts involved.

Once BEC perpetrators gain access to a participant’s email account involved in a real estate transaction, they are able to monitor the real estate proceeding and often time the fraudulent request for a change in payment type — frequently from check to wire transfer — or a change from one bank account to a different bank account under their control.

This timing is deliberate and surgical. Many incidents occur at quarter-end, during tax season, or while executives are traveling. Attackers often use social events, public travel plans, or industry-wide reporting deadlines to time their fraud. In the deal context specifically, the moment of maximum pressure is the days immediately before closing — when the buyer is anxious, the agent is coordinating final details, and everyone has normalized the urgency of last-minute instructions. That is exactly when the fraudulent wire instruction appears.

Phase 4: The fraudulent instruction

Right before closing, the attacker sends a message with “updated” wire transfer instructions that appears to come from the title company or closing attorney. The email contains the correct property address, transaction amount, and professional language because the fraudster has been reading the actual transaction thread.

BEC emails typically include a sense of urgency, employing words like “quick,” “urgent,” or “important” to prompt swift action. They often impersonate authoritative figures, using tactics like mimicking the person’s writing style or spoofing their email address with minor modifications to trick recipients. If they request a fund transfer, they specify an exact amount and provide a reason for the request to enhance its credibility. Additionally, BEC emails may instruct recipients not to contact the sender or verify the request with others to avoid detection.

That last detail — the instruction not to call — is the single clearest signal that something is wrong. No legitimate wire instruction comes with a request for silence.

Phase 5: Funds movement and laundering

Once trust is established, attackers execute their endgame, which may include fraudulent wire transfers, credential theft, or data exfiltration. They often use multiple accounts and money mules to quickly move and obscure stolen funds.

Within hours, the money moves through a web of international accounts and is effectively unrecoverable. Based on financial data reported to the IC3, banks located in Hong Kong and China were the primary international destinations of fraudulent funds, followed by the United Kingdom — which often acts as an intermediary stop — Mexico, and Singapore. The sophistication of the layering means that by the time anyone realizes the legitimate payee never received the funds, the money has already cleared the first domestic hop and is en route to a jurisdiction where U.S. law enforcement coordination is slow.

Where professional liability enters the picture

The innocent parties of BEC fraud scams are forced into the unfortunate position of not only losing money to the fraudster but also having to determine legally which party — the payor or the intended, legitimate payee — should bear the loss of that fraud.

The payor, as the party who transferred funds to the fraudulent account, may sue the intended payee under theories of liability including negligence — failure to warn or protect from fraud, failure to secure network or email systems, and failure to train employees to detect, report, and delete phishing emails.

This is what BEC means for a closing attorney or title professional beyond the immediate loss: civil exposure, regulatory scrutiny, and reputational damage — even when the professional was the impersonation victim rather than the negligent actor. Businesses encounter monetary loss, reputational harm, potential litigation, and regulatory scrutiny. The standard of care courts apply in these situations has been moving steadily toward requiring verifiable security practices, not just good intentions.

How the attack varies by role in the deal

Not all BEC attacks on deal transactions take the same shape. The vector and the target shift depending on who the attacker needs to impersonate and who they need to deceive.

Impersonating the title company or closing attorney: This is the most common scenario in residential and commercial real estate. The most common victims of impersonation were individuals and entities involved in the title and closing processes within a real estate transaction. The attacker sends a “final” wire instruction to the buyer, purportedly from the closing attorney, with updated banking details. The buyer, who is already expecting to wire funds, does so. The legitimate professional never receives anything.

Impersonating the seller’s attorney or broker: In commercial transactions, the seller’s wire instruction for net proceeds is the target. The attacker compromises the seller’s counsel’s email, waits for closing, and substitutes fraudulent wiring instructions for the proceeds — sometimes hundreds of thousands, sometimes millions of dollars. In one documented case, a real estate brokerage in Manhattan lost over $1 million when a hacker gained access to an agent’s email and redirected closing funds.

Impersonating a co-broker or referral partner: In a multi-party deal, the attacker may target the commission split itself. If a co-broker is owed a commission and sends wiring instructions by email, an attacker with access to either side’s inbox can substitute different wiring details before the instructions are logged. The funds settle; the co-broker calls asking where their money is; and the disbursing party is certain they paid.

Impersonating a lender: Instructions from lenders — payoff letters, disbursement accounts — carry high authority and are rarely second-guessed. An attacker who has compromised a lender’s outbound email can redirect the payoff wire on a refinance or purchase transaction to a fraudulent account.

Attorney impersonation with urgency and confidentiality: In one documented case, a real estate firm was defrauded out of €38 million by fraudsters who impersonated lawyers and gained the victim’s trust by requesting a confidential and urgent wire transfer. The instruction to keep the request confidential — a supposed legal sensitivity — is what overrides the instinct to verify. Deal professionals who operate in high-pressure environments where sensitive instructions occasionally come with confidentiality requests are particularly exposed to this variant.

What makes a defense actually work

The defenses that matter fall into two categories: technical controls that block or flag the attack before the email is acted on, and procedural controls that stop the payment from moving even if a fraudulent instruction gets through.

Technical controls

Multi-factor authentication on every email account. Account takeover is the primary enabler of BEC, and MFA is the primary defense against it. Without MFA, a stolen password is sufficient to own an inbox. With it, credential theft alone is not enough. Multi-factor authentication should be mandatory for all users, with particular emphasis on admins, executives, and finance teams.

Email authentication protocols — SPF, DKIM, DMARC. These three protocols work together to prevent domain spoofing. SPF specifies which servers are authorized to send email from your domain. DKIM cryptographically signs outgoing messages. DMARC tells receiving servers what to do when messages fail authentication — and critically, it sends reports back to the domain owner showing what’s happening. Email authentication protocols make it much harder for attackers to spoof your domain and give far better visibility into how your domain is being used. SPF, DKIM, and DMARC stop impersonation from the outside. They do nothing when the attacker is already inside. Both technical layers — authentication and account protection — are necessary because they address different vectors.

Disable automatic email forwarding to external addresses. Disabling automatic forwards to external email addresses helps prevent data exfiltration in the event of a compromised account. Many BEC attackers configure forwarding rules immediately after account takeover, so they can continue reading correspondence even after being locked out.

Treat inbox rule changes as a security signal. Behavioral anomalies from a legitimate account often indicate account takeover, making BEC attempts significantly harder to detect. Attackers commonly gain access via credential phishing or session theft, then use the trusted mailbox to orchestrate fraud from within your organization. Unexpected new inbox rules — especially ones that move or delete email matching financial or transaction-related keywords — should trigger an immediate review.

Procedural controls

No technical control is sufficient without a hard procedural rule on payment instructions. The rule is simple and absolute: any wire instruction received by email must be verbally confirmed using a phone number obtained independently — not from the email itself, not from the email signature, not from a number you found in the same thread.

Before wiring any funds, call the title company or closing attorney at a phone number you obtained independently (not from the email providing wire instructions) and verbally confirm the wire instructions match exactly. This one step stops the vast majority of BEC attacks. An attacker can fake an email. They cannot fake a phone call to the real professional’s real number — the one stored in your own contacts from before the deal started.

Any request to change previously established wire instructions should be treated as a red flag requiring independent verbal confirmation regardless of how the request arrives. Last-minute changes to wiring instructions, especially close to the transaction deadline, warrant suspicion. Timing pressure is part of the attack design; it is not a reason to skip verification.

Establish payment instructions at the start of the relationship, in person or via verified channel, and document them. Every subsequent communication that purports to change those instructions should be treated with skepticism proportional to the dollar amount at stake.

The 72-hour window: if it happens anyway

Even a well-protected professional can be the victim of a sophisticated account compromise at a counterparty. If a payment diverts, the recovery window is brutally narrow.

Wire transfer fraud recovery rates collapse after 72 hours. The FBI Recovery Asset Team reports a 66% recovery rate when fraud is reported within 72 hours, and a fraction of that after. Funds get split across multiple accounts, moved across borders, or converted to cryptocurrency, and the trail goes cold faster than most victims realize.

The Rapid Response Program (RRP) and the Financial Fraud Kill Chain (FFKC) are critical to recovery efforts when funds stolen through cyber-enabled fraud are wired internationally. Through the RRP, the Financial Crimes Enforcement Network helps victims and their financial institutions recover stolen funds. The RRP is a partnership between FinCEN, U.S. law enforcement including the FBI, the Secret Service, Homeland Security Investigations, and foreign partner agencies.

If you discover a fraud, the sequence is: call your bank’s fraud line immediately and request a wire recall; simultaneously file with the FBI’s Internet Crime Complaint Center at ic3.gov; call the receiving bank’s fraud department and request an account freeze. To initiate the FBI’s Financial Fraud Kill Chain, the wire transfer must be $50,000 or above, international, accompanied by a SWIFT recall notice, and must have occurred within the last 72 hours. Do not change passwords, delete emails, or alter the account before digital evidence is preserved — changing passwords before digital evidence is preserved will destroy the forensic record.

Wire transfers are generally considered final and irrevocable once the receiving bank accepts the funds. In most cases, a fraudulent wire cannot be reversed — only recalled, and only within a narrow window of hours. Once funds are moved or withdrawn, recovery depends on law enforcement, not your bank.

Where payment certainty changes the risk profile

The mechanics of BEC tell you something useful about where in a transaction the attack actually lives: it lives in the gap between instruction and payment. An attacker inserts themselves into the instruction chain — the email thread where wiring details are communicated — because payment in a traditional closing follows instruction by hours or days, across that gap.

When the professional controls how the money lands from the start — with payment details confirmed, locked, and disbursed on-chain in a single transaction the moment a deal closes — the instruction gap closes. Shaka is built for this: the professional sets the recipient wallets and split percentages before the deal closes, and funds route directly and automatically the moment they move. There is no “updated wire instruction” email that can intervene, because the payment path is set before closing, not communicated through email during it.

This does not replace the verification practices described above. It adds a layer where the mechanics themselves are resistant to late-stage substitution — the attack surface that BEC specifically exploits.

A note on AI-accelerated BEC

BEC attacks have surged by 1,760% from one period to the next, largely due to the widespread adoption of generative AI tools that enable attackers to craft more convincing and personalized fraudulent emails. The writing quality that once distinguished a sophisticated attack from a bulk phishing attempt is no longer a reliable signal. AI-generated BEC emails are grammatically perfect, stylistically matched to the impersonated professional, and contextually accurate. Modern BEC attacks have evolved beyond simple email spoofing to incorporate sophisticated social engineering tactics, AI-generated content, and multi-channel approaches that combine email, phone, and video communications.

Voice cloning is now being deployed alongside email. An attacker can send a fraudulent email and follow it with a phone call that sounds exactly like the counterparty. Verifying via phone using a number from your own contacts — not from anything the attacker has provided — is the only check that remains reliable when both email and voice can be fabricated.

Deal professionals who move real money in real transactions are the highest-value targets in BEC because they sit at the intersection of trust and large dollar flows. Understanding that this attack runs a deliberate sequence — reconnaissance, access, surveillance, substitution, movement — is what allows you to interrupt it. The substitution step is the attacker’s only moment of exposure: the instant they send the fraudulent instruction, they need the recipient not to call. That phone call, made to a number you already had, is the single most reliable break in the chain they’ve spent weeks building.