How to keep a large payment private and secure
When a deal closes at seven figures, the payment itself becomes a target. Not just a target for the obvious fraudster watching email threads, but a source of exposure that can ripple outward in ways most professionals underestimate — reputation risk, competitive intelligence leakage, operational disruption, and liability that can land squarely on the professional who organized the transfer. Brokers, closing attorneys, advisors, and dealmakers sit at the center of these payment flows and carry more responsibility for how money moves than any contract clause typically acknowledges. Getting paid correctly and getting clients paid securely are not separate problems. They are the same problem, and the professional in the middle owns both.
What “privacy” and “security” actually mean for a large payment
These two words get used interchangeably, but they describe distinct risks that require distinct responses.
Privacy is about who knows the deal happened, who knows the amounts, and who knows where the money landed. In most deals, more people have access to that information than anyone realizes. The wire instructions travel by email. The bank routing numbers pass through multiple systems. The commission split gets discussed over the phone on a Tuesday and ends up in a text thread by Wednesday. Before the ink is dry, the deal’s financial architecture has been exposed to a half-dozen parties who didn’t need to know it.
Security is about whether the funds actually arrive at the intended destination in the intended amount. That sounds like the obvious part. It is the part most professionals take for granted right up until it isn’t.
The reason both matter together is that a privacy failure often enables a security failure. The attacker who knows a $2.3 million closing is happening next Thursday does not need to crack a bank system. They just need to send a convincing email. And they almost certainly already know about the closing, because the information was sitting in an unencrypted thread.
How the threat actually works
Cybercriminals hack into email accounts, monitor the progress of a transaction, and wait for exactly the right moment — when the transfer of funds is necessary for the closing. Then they move. They send an email with a change in payment type or a change from one bank account to the criminal’s account, using fraudulent emails that mimic the real person’s identity with company logos and email addresses that are off by a single letter or number.
This is not a random crime of opportunity. Attackers identify a pending transaction, and then — using public records information or, in more severe cases, breaching title or broker systems — build profiles of the parties involved. They then send emails to agents, attorneys, title professionals, or buyers, getting that person to click on a malware link or offer up login credentials. Then they assume the identity of that trusted party and forge communications, including other details about the transaction.
In many successful cases, the emails are well written, cleanly formatted, and devoid of technical red flags — no links, no attachments, no misspellings. There is nothing technically suspicious to catch. The email reads exactly like correspondence from the closing attorney or the co-broker because it was written by someone who has been reading that correspondence for days.
The median dwell time is five days before the attacker initiates a fraudulent action after inbox compromise. Five days inside the thread. Five days reading the deal terms, learning the parties’ communication styles, noting who defers to whom and when. By the time the fraudulent instruction goes out, it is indistinguishable from the real thing.
The financial scale of this is not marginal. According to the FBI’s Internet Crime Report, Business Email Compromise scams resulted in losses exceeding $2.9 billion across all sectors, with real estate and rental sectors among the most affected. In real estate specifically, the average BEC incident results in losses of $150,000 to $200,000. Those are averages. In high-value transactions, the numbers go much higher. In one documented case, a real estate brokerage in Manhattan lost over $1 million when a hacker gained access to an agent’s email and redirected closing funds.
The recoveries are limited. Wire fraud happens when somebody tricks a buyer into wiring money to the wrong place, and once the money has been wired to criminals, it is usually gone forever. The FBI can help with a Financial Fraud Kill Chain process in some international cases, but the window is narrow and the success rate is not guaranteed. In the event of a fraudulent transfer, the FBI has been successful in certain instances stopping fraudulent transfers reported within 72 hours of initiation. After that window, options narrow dramatically.
Where the exposure actually lives
Most professionals instinctively think the exposure lives in the wire itself. The wire is the last step. The exposure usually lives much earlier.
The email thread
Business email compromise is a frequent tactic in wire fraud schemes, and protecting access to sensitive email accounts with strong, unique passwords and multifactor authentication is vital. But that framing — protect your email — understates the structural problem. Email is not a secure channel for transmitting financial instructions. Email is not a secure way to send financial information, and real estate professionals and title companies should know that. Policy should discourage the use of email for sharing wire instructions. If email is used, the information should be encrypted and directly verified with the payee.
The problem is that deal communications almost always live in email. The back-and-forth on timing, the confirmation of amounts, the distribution schedule for co-brokers — all of it. That thread is a roadmap for anyone who gets into it.
The wire instructions themselves
Last-minute modifications to wire instructions are a common tactic for fraudsters. Any such request should be treated with caution, and changes should be confirmed using a verified phone number or another secure method before proceeding. This is standard advice, and it is routinely ignored under closing-day pressure.
With multiple transactions happening simultaneously and pressure to meet deadlines, fraudsters know exactly when to strike. A large deal closing on a Friday afternoon, with parties traveling and time zones involved and a buyer anxious to confirm — that is the environment in which professionals make the mistake of not picking up the phone to verify.
The public record
In real estate specifically, deal information is not always private once recorded. Transaction amounts appear in public filings. Tax records reflect sale prices. This creates a secondary exposure problem: the privacy of the deal at closing does not automatically translate into privacy of the deal afterward. A sophisticated attacker does not need to be in the email thread to know a large transfer occurred. They need only to look at the record — and then work backward to understand who the professionals involved were and how to approach the next transaction.
The disbursement chain
One dimension that rarely gets discussed openly: in deals with multiple payees — co-brokers, referral partners, advisors — the disbursement instructions multiply the attack surface. Each additional payee is another email thread, another set of banking details in motion, another person whose identity can be spoofed. BEC scams target all participants in real estate transactions, including buyers, sellers, real estate attorneys, title companies, and agents. Once a BEC perpetrator gains access to a participant’s email account involved in a real estate transaction, they are able to monitor the proceeding and time the fraudulent request for a change in payment type or a change from one bank account to a different bank account under their control.
The more parties are getting paid, the more communications are required. The more communications, the more opportunities for interception. A deal with four payees settled over two days via four separate wire instructions is not four times as hard to secure — it is disproportionately harder, because each communication event is an independent attack vector.
The professional’s dual liability problem
There is a dimension here that goes beyond the obvious financial risk to clients: the professional who organized the payment instructions carries real liability when something goes wrong.
ACH and wire transfer payment fraud could cost a business financially and damage its reputation. While the money can often eventually be recovered, damage to integrity and reputation will be much harder to repair. In practice, when a client’s funds go to the wrong account, the first question is always: who sent the wire instructions? If those instructions came from a spoofed version of a broker’s email, the broker’s firm is under the microscope — regardless of fault.
Businesses encounter monetary loss, reputational harm, potential litigation, and regulatory scrutiny. In some instances, victims have been unable to finalize purchases, lost earnest money, or suffered emotional distress due to a breach of trust. That breach-of-trust framing matters. The professional relationship is what the fraudster weaponizes, and the damage to that relationship — regardless of fault — is real.
For advisors and broker-dealers, the regulatory exposure compounds the client harm exposure. Financial advisors are required by federal law to protect client financial information, and the core regulation governing advisor privacy obligations has been significantly strengthened. A data breach or a compromised email account through which payment information was transmitted is not just a client service failure — it can trigger regulatory reporting requirements and examination scrutiny.
Building a privacy and security posture for large payment events
None of this requires extraordinary technology. It requires consistent discipline applied before the payment is in motion.
Treat payment communication as a separate channel from deal communication
The deal negotiation happens over email, by phone, in documents. That is normal. But the moment you are conveying banking information, routing numbers, or payment instructions, that communication should happen through a verified, out-of-band channel — a phone call to a number already on file, an in-person confirmation, or a secure encrypted portal. Not a follow-up email. Not a text thread.
Always verify the authenticity of each wire transfer request by implementing a two-step verification process. Verify the request by calling the requestor using a number you have previously called — not the number from the current wire transfer request. Ask for the person to verbally repeat requests to ensure that the information received is legitimate.
Establish the verification protocol at the beginning of the engagement, not at closing. By the time you are days out from a transfer, everyone is under pressure. The protocol needs to be a habit, not a last-minute checklist.
Separate the people who receive requests from the people who approve them
Implementing a dual control system with duty segregation for transfer approval — making one person responsible for receiving a request and a second person responsible for authorizing the release of funds — adds a critical layer of protection. In a small brokerage or solo practice, this may mean involving a second trusted party in the confirmation step. The point is that no single inbox and no single person should be the sole checkpoint for a seven-figure transfer.
Lock down the accounts that touch deal communications
Since business email compromise is a frequent tactic in wire fraud schemes, protecting access to sensitive email accounts with strong, unique passwords and MFA is vital. Enforcing strong password policies and requiring MFA for all accounts used to handle financial transactions significantly decreases the risk of unauthorized access.
Use a dedicated, secure computer for any online banking activity, such as sending electronic wire transfers. This computer needs to be up to date with security patches and antivirus protection — steps that help protect it from malware, which can lead to compromised login credentials.
These are baseline controls. They are not sufficient on their own, but skipping them makes every other precaution irrelevant because the attacker already has access to the account.
Address the disclosure problem, not just the interception problem
A payment can be fully secured against interception and still be too exposed from a privacy standpoint. Consider what information about a large transaction is circulating among parties who do not need it. Does the buyer’s agent need to know the split between the listing broker and the co-broker? Does the lender’s assistant need the full disbursement schedule? Does any party outside the closing need to know which attorneys are receiving what amounts?
Privacy hygiene around a large payment means auditing who has access to what information, and at what point. When information is managed with discipline, only parties who are genuinely interested and properly qualified receive it, and only after the appropriate agreements are in place. That principle — which experienced brokers apply to deal marketing — applies with equal force to payment logistics.
Create a closing-day security checklist that is non-negotiable
A closing-day security system acts as a safety net. Setting specific guidelines that cover each stage of the transaction — verifying contact information, confirming the identities of all parties, especially those who might be more vulnerable in the chain — provides structure under pressure.
The pressure environment at closing is not going to get less intense. What changes is whether the professional has built a routine that holds regardless of the pressure. A checklist is not bureaucracy — it is the thing that prevents a six-second decision made under stress from costing a client $400,000.
Minimize the surface area of the disbursement
In deals with multiple payees, the disbursement structure itself is a security design question. Every additional wire instruction sent to a different destination is another event that requires verification, another communication that can be intercepted, and another point of failure. Simplifying the disbursement architecture — concentrating the outbound payment flow — directly reduces exposure.
This is one of the genuine operational advantages that payment technology built for deal professionals can provide. When a professional creates a structured payment link through a tool like Shaka, the split logic is embedded in the payment itself: the recipient wallets, the percentages, and the routing are all defined upfront before any funds move. The disbursement does not require a separate chain of emails to each payee confirming amounts and routing details. Funds move directly to each wallet in one transaction, settled immediately. The attack surface that exists in a multi-step, multi-email disbursement process is replaced by a single, pre-configured settlement event. The professional closes the deal; the payment infrastructure handles where the money lands and in what proportions, without additional communication events that can be spoofed.
When recovery is still possible
If a fraudulent transfer is discovered quickly, options exist — but they close fast.
Upon realizing that a cybercrime involving a fraudulent wire has taken place, a victim should immediately contact the victim’s bank and ask for a recall notice to be issued, contact the recipient bank and ask for an immediate freeze on the recipient account, report the cybercrime to the IC3, and contact the nearest regional FBI field office.
If you discover a fraudulent transfer, time is of the essence. Contact your financial institution and request a recall of the funds along with any necessary indemnification documents. Different financial institutions have varying policies, and it is important to know what assistance your financial institution will provide when attempting to recover funds.
The honest reality is that the recovery process is uncertain and often unsuccessful. Sending money internationally carries more risk — once money leaves the United States, it is likely gone forever. The procedural steps above give you the best available chance, but they are not a substitute for the prevention posture that makes them unnecessary.
What the professional’s responsibility actually is
There is a version of this conversation where the professional’s job is to disclaim responsibility — to hand the client a fraud warning sheet and note that wire instructions were provided in good faith. That is a legal posture. It is not a professional one.
The broker, the closing attorney, the advisor, the dealmaker — each of these roles carries real authority over how a deal’s financial mechanics are organized. That authority is the reason clients pay for professional representation in the first place. A client who loses $275,000 to a spoofed wire instruction sent from a lookalike of their agent’s email address does not experience that as someone else’s problem. They experience it as a failure of the professional relationship that was supposed to protect them.
The privacy and security of a large payment is not a technology question and it is not a legal question. It is a practice question. How the professional manages communication about money, how they structure verification, how they organize disbursement, how they close the information gap between what parties need to know and what is actually circulating — these choices determine whether a large payment lands safely and discreetly, or becomes the kind of story that ends a professional relationship and occasionally a career.
Getting this right is not a differentiator. It is the floor. But the professionals who have internalized it — who treat payment security as a core competency rather than a closing-week concern — are the ones clients trust with the next deal, and the deal after that.