How to make sure a wire to your brokerage isn't intercepted

How to make sure a wire to your brokerage isn’t intercepted

Every real estate professional knows that commissions are earned long before they are paid. Weeks of negotiation, inspections, contingencies, and financing hurdles all collapse into a single wire that moves at closing — and that wire is increasingly a target. The threat here is not the general closing fraud that buyers worry about; it is something more specific and, in some ways, more insidious: a fraudster impersonating your brokerage, intercepting the commission disbursement itself, and rerouting it to an account you will never recover funds from. This article explains exactly how that attack works, where the vulnerability lives in the commission payment chain, and what it takes to close it.

The commission payment chain and where it breaks

To understand the interception risk, you have to understand the mechanics of how commission flows. The transaction closes, the title company or closing attorney disburses funds per the settlement statement or Commission Disbursement Authorization (CDA), and a wire travels — typically to the brokerage’s trust or operating account, not directly to the agent. Legally, commission must be paid to the Broker of Record, not the agent directly. The broker holds the license that allows agents to operate, ensures legal compliance, and assumes liability for transactions. That single wire to the brokerage is the chokepoint — and it is exactly what sophisticated fraudsters have learned to target.

The CDA, which specifies the brokerage’s bank account and wiring instructions, is transmitted by email in the overwhelming majority of transactions. All transactions must have a Commission Disbursement Authorization completed and sent out to the closer. The CDA is used to document all commissions and fees and make sure all parties are paid the correct amounts. The CDA contains payment instructions for closing, including the brokerage’s bank account and wire information, along with a reference number to include in all wires so accounting can match the funds to the transaction. That document, moving through standard email, is exactly the document a criminal wants to intercept and replace.

The attack does not require the fraudster to break into a bank. It requires only getting into one email account — yours, the title company’s, the closing attorney’s, or an assistant’s — and watching the transaction develop until the CDA goes out.

How the intercept actually happens

Business email compromise is one of the most common ways real estate wire fraud happens. When a hacker gets into the email account of someone involved in the deal, they can sit quietly and watch the transaction unfold. They learn who the parties are and how much money is moving. This patience is what makes these attacks so damaging. There is no obvious footprint. The criminal is simply reading.

A criminal gets into an email account connected to the closing and watches the deal in silence. At the last moment, they send wiring instructions that route the funds to an account they control. Every home sale generates a chain of emails connecting the buyer, the seller, the agents, the closing or title company, and the lender. A criminal only needs to get into one of those email accounts.

Once they have enough information — the name of the brokerage, the name of the agent, the approximate commission amount, the closing date — they move. The most straightforward method is email spoofing or phishing. Scammers create messages that closely mimic those from closing attorneys or title agents, copying logos, signatures, and transaction-specific details, to solicit sensitive information or redirect funds.

In the commission-intercept scenario, the attack direction is usually reversed from the buyer-fraud playbook. Instead of a fraudster sending fake wiring instructions to the title company impersonating the brokerage, they more commonly send fake instructions from the brokerage — either replacing the legitimate CDA already in transit or sending an “updated” version with substituted bank account details. The title officer, running dozens of simultaneous transactions under deadline pressure, often has no reliable way to detect the swap. The commission wire goes out. It lands in the wrong account.

Fraudsters commonly use spoofing tactics to make email addresses, phone numbers, and websites appear as legitimate ones, substituting or transposing characters — a number or letter off — which is very easy for anyone to overlook.

What makes the commission wire particularly vulnerable is precisely its professional context. Business email compromise attackers frequently use social engineering to build trust and urgency. They may pose as a buyer, seller, realtor, or broker requesting a change in payment instructions, and leverage fear, time pressure, or confidentiality to override normal verification processes — tactics that are particularly effective in real estate, where transactions involve tight deadlines and high stakes.

There is also an institutional gap that attackers exploit. Real estate transactions are increasingly conducted online, and the industry has not kept pace with the security posture of the financial institutions it interfaces with. Title companies, brokerages, and agents are not banks — they don’t have the same regulatory requirements or security infrastructure. But they handle the same dollar amounts.

The three entry points into your commission disbursement

You cannot protect against what you cannot locate. There are three primary entry points attackers use to intercept the brokerage-inbound commission wire.

Entry point one: your own email

If your email account is compromised — through phishing, credential stuffing, or malware — an attacker can intercept the CDA after you’ve drafted and sent it, and substitute their own version before it reaches the closer. They can also set up forwarding rules that silently copy every communication you send or receive, giving them a complete picture of the deal without any visible sign of intrusion.

Attackers often monitor communications to insert themselves at crucial moments, such as just before a wire transfer. It is not uncommon for attackers to create mail rules upon entry to provide filtering or backdoor capabilities.

This means that even if you take every precaution in how you send the CDA, a pre-existing compromise of your inbox renders those precautions meaningless. The document you believe you sent is not the document that arrived.

Entry point two: the title company or closing attorney’s email

Business email compromise scams target all participants in real estate transactions, including buyers, sellers, real estate attorneys, title companies, and agents. Once perpetrators gain access to a participant’s email account involved in a real estate transaction, they are able to monitor the proceeding and often time the fraudulent request for a change in payment type or a change from one bank account to a different bank account under their control.

When the title company’s system is the entry point, the problem is especially hard to detect. The fraudster operates from inside a trusted account. The email requesting updated disbursement instructions or “confirming” new wire information for the brokerage appears to come from a legitimate address — because it does. There is no spoofed domain to catch, no visual anomaly to spot. The closing officer believes they are receiving legitimate instructions; in reality, they are receiving instructions created by someone who has full access to their colleague’s inbox.

Entry point three: the chain of forwarded communications

Each time an electronic message is forwarded, the risk that the transmission may be intercepted increases. In a typical transaction, the CDA might travel from the agent to the brokerage’s transaction coordinator, then to a closing department contact, then to the title company’s closer, then to an assistant covering for the closer that day. Every forward is another potential exposure point. Every reply that includes the original wire instructions is another copy of that data sitting in another inbox.

This is not hypothetical exposure — in Bain v. Platinum Realty, a criminal was intercepting emails exchanged between the title company, agent, and buyer. The buyer was sent hacked wiring instructions that directed funds to the criminal’s account. Once the funds were sent, they could not be recovered, and the buyer sued the agent, the broker, and others. That case resolved with the agent’s brokerage bearing significant liability. The commission wire itself was not the target in that case, but the mechanism — email interception across a chain of forwarded communications — is identical to what targets brokerage disbursements.

What the financial exposure actually looks like

The scale of this fraud is not trivial. In only a two-year period tracked by the FBI, the number of real estate wire fraud victims went from 1,796 in one year to 2,284 in another, and the money lost went from $258,400,000 to $446,100,000. This is a drastic amount of money lost considering the seemingly small number of victims, which highlights that the loss per victim is significant.

Think about what a brokerage-targeted interception looks like in dollar terms. A residential deal closing at $900,000 with a 2.5% commission generates $22,500 to the brokerage side. After the brokerage-agent split, the agent may see $14,000 to $18,000 of that. If the commission wire is intercepted and the fraudster’s account receives the full $22,500, the brokerage is out real money — and the immediate dispute is not with the title company, it’s about who bears the loss.

On a commercial deal, the exposure compounds dramatically. A $3 million commercial sale at 3% generates $90,000 in gross commission. If that wire is rerouted, the brokerage is not looking at a recoverable error — they are looking at a potential complete loss. The people being defrauded sometimes do not realize it for days, often too late to get the money back.

Recovery from wire fraud is structurally difficult. Nearly 88% of all incidents involved initial transfers of fraudulent funds to accounts at U.S. depository institutions. In several incidents, illicit funds quickly moved from bank accounts to online payment platforms, or were used to purchase convertible virtual currencies, most commonly bitcoin. The velocity of movement once funds hit the fraudster’s receiving account means that by the time anyone notices the commission did not arrive — typically when the agent follows up a day or two later — the money is already several transactions away from where it landed.

The liability question brokers don’t want to face

When the commission wire to a brokerage is intercepted, the liability question is genuinely murky. There is no clear answer on who is responsible when wire fraud occurs. Sometimes, the consumer is liable because they willingly authorized a transaction — even if under false pretenses. Real estate agents, brokers, and escrow companies have also been found liable if a court finds them negligent.

Liability can fall on either the individual agent, the supervising broker or brokerage firm, or both — depending on the circumstances. Because a supervising broker typically oversees and supervises the actions of sales agents, the brokerage firm can also be held responsible for misconduct or negligence committed by its agents. This is known as vicarious liability. Even if the broker personally did not commit the wrongdoing, liability may still attach if the agent was acting within the scope of their authority or under the broker’s supervision.

This creates an uncomfortable reality for the broker: if an agent’s email account is the entry point through which a fraudster intercepts the commission wire, the brokerage’s own cybersecurity posture is now a factor in litigation. The standard for reasonable care is moving, and courts are applying it with increasing rigor to professionals who handle large money movements.

An agent who runs a six- or seven-figure closing through a compromised email account may have fallen short of the duty of reasonable care. The brokerage that supervises the agent can share the liability.

There is also the escrow law dimension. Sending commission funds to third parties may violate real estate law, escrow law, and federal RESPA rules. Commission payments should go directly to the broker. Brokers must not direct payments to unlicensed individuals or businesses. This matters for interception cases because it narrows the authorized disbursement path — and any deviation from that path should, theoretically, trigger verification. In practice, it rarely does.

The operational controls that actually work

There is no single control that eliminates interception risk. Protection comes from layering procedures that create independent verification checkpoints — specifically at the moments when wire instructions are transmitted and when a title or closing company acts on them.

Out-of-band verification of every CDA

The single most effective procedural control is requiring a phone call to verify receipt and accuracy of the CDA — made using a number that comes from a source independent of email. Do not click on any email or text links, or send money online without verifying the wire instructions with a live person on the phone from a phone number that is known to you, and that you have previously verified as belonging to the title or lending company you are using for your transaction.

This sounds elementary. It is elementary. It is also the control most frequently skipped, because closers are running multiple files and agents are already moving to the next deal. The phone call feels like an interruption; it is actually the only checkpoint that cannot be spoofed by someone who has already compromised your email thread. A fraudster who has substituted a false CDA cannot intercept a phone call made to a number pulled from a prior contract, a business card, or the brokerage’s own website.

The protocol should be formalized: your brokerage sends the CDA, a person at your brokerage calls the closer to confirm receipt of the exact document — not a version of it, the exact document — and the closer confirms the bank name, the last four digits of the account number, and the reference number. This takes four minutes. It closes a vulnerability that can cost six figures.

DMARC, SPF, and DKIM on your brokerage domain

DMARC prevents attackers from spoofing your domain in phishing emails. Setting your policy to “reject” or at minimum “quarantine” protects clients from receiving fake emails that appear to come from your address. If your brokerage email domain does not have these authentication records published, any reasonably competent attacker can send a message that appears — in every recipient’s inbox — to be from your exact email address. The fraudulent CDA lands looking indistinguishable from the real one.

Configuring these records is a technical task, but it is not complicated, and it is something your IT provider or domain registrar can implement in an afternoon. The return on that afternoon is that your domain cannot be impersonated with a spoofed sender.

Mandatory multi-factor authentication on all email accounts

CISA’s phishing-resistant MFA guidance names FIDO2 security keys and passkeys as the only methods that fully block adversary-in-the-middle style email interception attacks. SMS-based two-factor authentication is better than nothing, but it is susceptible to SIM-swapping. A hardware security key or a device-bound passkey is the meaningful upgrade. If your agents’ email accounts are protected by only a password, every CDA they send is transmitted through a system that a single credential theft can compromise entirely.

The brokerage should enforce MFA as a condition of using brokerage email systems. This is not an optional hygiene recommendation — it is the foundational control that determines whether your entire disbursement process can be hijacked from outside.

Audit inbox rules after any anomalous event

If an attacker accessed your email, they may still be in your system or have access to your contact list. Change credentials, enable MFA, and audit mailbox rules immediately. A common attacker tactic after gaining access is to create inbox rules that forward copies of transaction emails to an external address, or that delete incoming replies so you never see a bounce or a warning. These rules persist silently even after a password reset, because many email platforms keep rules tied to the account rather than the session.

Any agent who notices anything unusual — a closed deal they don’t remember, an email reply that doesn’t match what they sent, a closer mentioning they resent instructions — should have their inbox rules audited immediately. This is a five-minute check in any email admin console, and it can reveal an active intrusion.

Treat any last-minute change in wire instructions as fraudulent until proven otherwise

Fraudsters send false bank account details just before closing, redirecting funds to their accounts. Last-minute changes to wire instructions are a primary red flag. Your standing protocol, communicated in writing to every closer and title officer you work with at the outset of every transaction, should be explicit: the brokerage’s wire instructions do not change. Any communication claiming they have changed should be treated as potentially fraudulent until the change is verified by a phone call to a known number, confirmed by a second person at the brokerage, and documented.

If you receive updated wiring instructions at any point in the process, treat them as suspicious by default and confirm directly with your broker or closing attorney before acting.

This protocol should be mutual. The closing attorney or title company should be told, at the start of the file, what your brokerage’s verification procedure is, so that if they receive a “change” instruction they know to call before acting on it.

The disbursement model that closes the interception window

The controls above address the email-based attack surface. They are necessary. But there is a structural vulnerability that even careful email hygiene cannot fully eliminate: the commission payment process requires your bank account information to travel through a chain of parties — any one of whom can be a point of interception — before the money moves.

The fundamental exposure is not that your email might be read. It is that the destination account for the wire is communicated through the same channel that the fraudster is watching, and the disbursement is an instruction executed by a third party based on that communication.

When a broker uses Shaka to set up how the commission lands, the payment routing is established in advance — wallet addresses and split percentages are encoded into the payment link before the deal closes, not transmitted through email at the closing stage. The closer executes against a pre-verified endpoint. There is no CDA traveling through an inbox for a fraudster to intercept and replace, because the destination of the funds is already locked and visible onchain. The closing professional closes the deal; Shaka handles exactly how the money lands — and the handling happens before the moment of greatest vulnerability, not during it.

What to do if you believe the wire has been intercepted

Speed is everything. The critical role of timely reporting to FinCEN and law enforcement is to interdict, freeze, and recover funds stolen through cyber-enabled fraud through FinCEN’s Rapid Response Program. The window for freezing a fraudulent wire is measured in hours, not days.

Call your bank immediately and request a wire recall. Provide the receiving bank’s name, the account number, the routing number, the amount, and the exact timestamp of the transfer. Then call the FBI’s Internet Crime Complaint Center at ic3.gov and file a complaint the same day. The FBI’s Recovery Asset Team may be able to assist financial institutions in attempting to freeze fraudulent transfers when reports are made quickly.

Do not wait to confirm your suspicion before making these calls. The cost of being wrong is a brief administrative inconvenience. The cost of waiting to be certain is that the funds have already moved. Since the inception of FinCEN’s Rapid Response Program, the program has aided in the identification and freezing of more than $1.3 billion for U.S. victims of fraud. That number exists precisely because some victims acted fast enough for intervention to matter.

Preserve every communication connected to the transaction without alteration. Do not delete, move, or archive emails. Do not reply to any communications from the suspected fraudster — doing so may alert them to move the funds faster. Change your email credentials and audit your inbox rules immediately, because if your account was the entry point, it may still be actively monitored.

The professional standard is rising

The NAR’s push toward cybersecurity checklists and ALTA’s wire fraud prevention guidance are a start, but the industry still has significant ground to cover. Until wire verification becomes standard practice — not optional — these attacks will continue to succeed.

That trajectory matters professionally, not just operationally. Courts are beginning to evaluate brokerage liability for fraud losses using the same lens they apply to any professional duty — did you take reasonable precautions commensurate with the risk? A brokerage that can document a formalized verification protocol, a written communication to all closers at the outset of every file, mandatory MFA on all agent accounts, and proper domain authentication is in a materially different legal position than one that relied on email and trusted things would go right.

The commission wire to your brokerage is not a secondary payment detail to handle after the deal closes. It is a high-value target that sophisticated attackers understand far better than most of the professionals who send it. Treating it accordingly — with formal verification protocols, email security infrastructure, and disbursement architecture that reduces the window between payment instruction and payment execution — is the professional standard the industry is moving toward. Getting there ahead of the attack is considerably easier than recovering from it after.