How to protect a real estate commission from wire fraud
Every real estate transaction ends with money moving — and that moment is exactly when the most sophisticated financial criminals in the world are watching. Wire fraud in the real estate sector has grown from an edge case into an endemic threat, one that targets not just buyers and sellers but the professionals who orchestrate the closing. Agents, brokers, closing attorneys, and title professionals are all targets, both as conduits for diverting client funds and, increasingly, as direct victims whose own commission disbursements are intercepted. This article covers how these attacks work at the mechanics level, why the commission payout and disbursement flow is a specific target, and what you can do operationally to make sure the money that belongs to you and your principals actually lands where it’s supposed to.
Why real estate closings are the primary target
No other consumer transaction involves wiring six or seven figures to an account you’ve never used before, on a deadline, based on instructions in an email. A real estate closing concentrates every favorable element from a criminal’s perspective: large, time-sensitive money movements, a fixed closing date, and an agent, buyer, and seller all under pressure to close on schedule.
The sector remains a target for BEC attacks exploiting the high monetary values generally associated with real estate transactions and the various communications between entities involved. That’s the structural problem, and no procedural improvement changes the underlying arithmetic. When a $700,000 closing generates a gross commission of $21,000 split between two sides, each of those two commission disbursements is itself a wire of meaningful size — enough to be worth targeting on its own.
In real estate, the average business email compromise incident results in losses of $150,000 to $200,000. The American Land Title Association also reports that nearly 30% of title companies experienced an attempted BEC attack in the last year. Those numbers capture the scale of the buyer-side losses. But the commission payout, the seller-proceeds disbursement, and the referral split are all part of the same disbursement waterfall — and they are all in play once a criminal has access to the communication chain.
The FBI’s Internet Crime Report logged $275.1 million in real estate fraud losses across 12,368 complaints in a single year. Business Email Compromise — the primary mechanism for real estate wire fraud — accounted for $3.04 billion in total losses across all sectors, with the FBI’s Recovery Asset Team initiating 3,900 fraud incidents and freezing $679 million of $1.16 billion in attempted thefts. Even at those intervention rates, the losses that got through were permanent.
How the attack actually works: surveillance, timing, and impersonation
Professionals in this industry tend to think about wire fraud as something that happens to buyers. That framing is incomplete and dangerous. Understanding how the attack works from the inside — from the perspective of someone who runs multiple transactions simultaneously and generates a predictable, calendared stream of commission disbursements — is the starting point for building a real defense.
The reconnaissance phase
Once inside the communication thread, attackers monitor the transaction quietly — sometimes for weeks — learning the closing date, the title company, the lender, and the exact dollar amounts involved.
The entry point is almost always email. Cybercriminals gather information about the target organization and its personnel via public sources, social media, and data breaches. Attackers craft convincing phishing emails to trick victims into divulging login credentials. Once access is obtained, attackers either use the real account if it is not protected by MFA or create lookalike email addresses.
Fraudsters troll social media sites, look at review platforms, and pinpoint the real estate agents and escrow companies who are popular. If the agents are using a public domain like Yahoo, AOL, or Gmail to host their communications, or if the escrow company emails are not encrypted, it becomes easier to hack into their servers, park themselves there, and monitor the email conversations.
For an active agent running eight to twelve transactions a month, the email account isn’t just a communication tool — it’s a real-time ledger of every pending close, every commission split agreed to, every disbursement instruction sent. A criminal sitting inside that account knows your pipeline better than your brokerage does.
The timing of the strike
Most wire fraud happens in the final 24 to 48 hours before closing, when buyers are most focused and least suspicious. The attacker has been watching the transaction for weeks. They know the parties, the amounts, the timeline. They know when to strike.
Fraudsters tend to request wire changes on Fridays or before holidays, because the funds need time to move. Changes to wiring instructions are rare and should only come from the closing agent. Since it takes just 72 hours to move money, fraudsters often target those windows so the funds are gone by the time anyone notices.
The combination of tight deadlines, high pressure, and a built-in expectation that last-minute communications are normal is precisely the environment these attacks are designed for. Real estate professionals are trained to respond quickly. That training becomes a vulnerability.
The spoofed communication
When the time is right, the scammer sends a convincing message with “updated” wire transfer instructions. The email appears authentic, incorporating the correct logos, professional language, and accurate property details. But the wiring information directs funds to a fraudulent account. Once sent, that money often disappears within hours through a web of international accounts.
Spoofing involves creating email addresses that closely resemble legitimate ones — for example, replacing an “m” with an “rn” or using a different domain extension. The sophistication here has increased substantially. AI-generated emails eliminate the grammatical errors that historically identified fraudulent communications. Deepfake voice technology now impersonates real estate agents and title company representatives by phone, defeating the phone call verification step.
The message will almost always create a sense of urgency: “Please wire funds today to avoid a closing delay.” In some cases, fraudsters follow up with a phone call from a spoofed number — one that appears to be the legitimate title company’s number — to verbally confirm the instructions and increase confidence.
The commission as a direct target
Most wire fraud coverage focuses on the buyer’s closing funds because those are the largest single wire in a transaction. But the commission disbursement occupies a uniquely vulnerable position that is worth understanding precisely.
In a standard residential transaction, the gross commission is paid from closing proceeds. The closing agent — typically the title company or closing attorney — receives the disbursement instructions and wires the respective shares to the listing brokerage, the buyer’s brokerage, and, where applicable, directly to agents under split arrangements. Any referral fees or co-broker splits come out of that same waterfall.
Wire fraud happens when somebody tricks a buyer into wiring money to the wrong place, or when criminals pretend to be a realtor and have payments disbursed into the fraudster’s account. That second scenario — the impersonation of the professional to divert the commission itself — is how your payout gets stolen even when the buyer’s funds arrive correctly. A criminal who has been monitoring your email knows exactly what your commission will be, when the closing is, and which title company will handle disbursement. A spoofed email to the title company “from you,” providing updated wiring instructions for your commission, requires nothing more sophisticated than a lookalike domain and a plausible bank account.
In one real lawsuit, the loss sustained by First American Title was caused by a hacker who hacked into the email address of the seller’s real estate agent and sent a fake email to the title company to change the seller’s wire instructions for net proceeds. The lawsuit stated that the real estate agent failed to “implement and maintain reasonable security procedures and practices to protect the personal information of the seller.”
The professional is both a potential victim and, in the eyes of the law, potentially a responsible party. In California, your agent owes a fiduciary duty and a duty of reasonable care. An agent who runs a six- or seven-figure closing through a compromised email account may have fallen short of that duty. The brokerage that supervises the agent can share the liability. If the breach instead originated with the escrow or title company, or the mortgage broker, that party can face its own claim for negligence.
That dual exposure — as a victim who loses their commission and as a defendant who may owe damages for a client’s loss — is why the risk here isn’t just personal financial harm.
What makes recovery so difficult
Wire transfer fraud recovery is a race against a 72-hour clock. The FBI Recovery Asset Team reports a 66 percent recovery rate when incidents are reported within 72 hours of the fraudulent wire. After that window, recovery rates collapse.
The mechanics of why are straightforward. A typical BEC attack does not let funds sit in the receiving account. Within hours of receipt, the attacker initiates outbound transfers to break the funds into smaller chunks across multiple accounts, often across multiple banks and multiple jurisdictions. Each fragment is harder to trace and slower to freeze than the original wire.
Once fraudsters move money to cryptocurrency or offshore accounts, SWIFT recalls become ineffective, which is why the first two hours are crucial.
Unlike credit card transactions, wire transfers have very limited consumer protections. Once a wire clears a fraudulent account, recovery depends on the speed of response and the cooperation of international banking systems. Only 19% of victims fully recover their funds.
The recovery rate of 58% sounds high until you are on the wrong side of it: for every $100 wired to a fraudulent account, $42 is gone permanently. For a commission of $18,000 on a standard transaction, that means the realistic expected loss — even accounting for the FBI’s best efforts — is over $7,500. On a luxury deal where commissions run to six figures, the arithmetic is genuinely severe.
Operational defenses for the working professional
The standard guidance — “verify wiring instructions by phone” — is correct but insufficient on its own. Here is a layered approach that addresses the full attack surface, not just the final wire.
Lock down the email account first
Everything else in your defense depends on your email being secure. A criminal who has read-only access to your inbox has enough intelligence to run the attack without ever needing to send a message from your account. A criminal who has write access can impersonate you to every party in the transaction, including your title company and your own broker.
BEC attacks can include display-name spoofing, lookalike domains, domain spoofing, malicious inbox rules, forwarding rules, delegated access abuse, or OAuth-based persistence after the initial mailbox compromise. The inbox rule is particularly insidious: a criminal who has briefly accessed your account can set a rule that forwards all emails matching certain criteria — “wire,” “closing,” “commission,” “instructions” — to an external address, and then log out. You will never see the rule unless you go looking for it.
Minimum email hygiene for a professional handling transaction disbursements: multi-factor authentication on the email account itself, not just the brokerage CRM. A separate password that is not reused from other accounts. A monthly review of inbox rules and forwarding configurations. A business-grade domain with DMARC enforcement rather than Gmail or Yahoo for transaction communications.
DMARC prevents attackers from spoofing your domain in phishing emails. Set your policy to “reject” or at minimum “quarantine.” This protects clients from receiving fake emails that appear to come from your address.
Establish verification protocols before the transaction closes — not at closing
Every closing participant should complete a call verification before wiring any funds — calling the title company or closing attorney at a phone number obtained independently, not from the email providing wire instructions. Never call a phone number provided in the same email that provided the wire instructions, because the fraudster often includes a spoofed phone number in the fraudulent email.
The phone number used for verification must come from a source established before the transaction: the title company’s website as it appeared at the time of engagement, a business card, or a number confirmed in person. Not from any email received during the transaction.
Before any transaction begins, agree on a security protocol with your title company and lenders: what verification methods you’ll use, who calls whom, and what the escalation path looks like. Share this protocol in writing with every party to the transaction at the outset.
The pre-closing communication to clients should be explicit and in writing: “I will never send you updated wire instructions by email. If you receive an email that appears to be from me with wiring changes, treat it as fraud and call me immediately at this number.” Many brokerages build this directly into their buyer representation agreement or closing documents, making it explicit: “We will never change wire instructions via email. If you receive updated wiring instructions, call your agent and title company at known numbers before sending any funds.”
Treat any change to instructions as presumptively fraudulent
Any change to wiring instructions is a red flag, full stop. Legitimate title companies do not change bank accounts mid-transaction. Even if the email looks exactly like prior correspondence, call using a number from the company’s official website — not the email — and ask for your closing officer by name.
This extends to your own commission disbursement instructions. If you have ever provided your commission wiring instructions to a title company, and those instructions need to change, the change should be communicated through a channel that is separate from email — ideally in person or over a verified phone call with a follow-up on your official letterhead. A title company that receives a last-minute email “from you” with different banking information should be suspicious and should verify directly.
The timing pattern matters here. Attackers often monitor communications to insert themselves at crucial moments, such as just before a wire transfer. If a change to any disbursement instruction arrives in the final 48 hours before closing, the probability that it is fraudulent is substantially higher than at any other point in the transaction.
Protect your disbursement instructions upstream
The commission disbursement is not just about who sends money to whom — it is about whether the routing information the title company holds for you is legitimate in the first place. If a criminal has access to the transaction chain and can communicate “from” you or from the title company, they can poison the instructions before the closing wire is ever initiated.
The defensive posture here is to provide your commission wiring information directly, through a verified channel, early in the transaction — not by email reply, and not through documents that travel through multiple parties before reaching the closing agent. When you know at contract that you will be receiving a commission disbursement, communicate your banking instructions directly to the closing agent through a channel you have independently established as authentic. Confirm those instructions have been received and that the closing agent has them on file correctly.
If you are on the receiving end as a broker disbursing splits to agents or co-brokers, the same verification applies in reverse. An agent who provides commission wire instructions by email — even from a known address — should be verified by phone before those instructions are entered into the system. Once a BEC perpetrator gains access to a participant’s email account involved in a real estate transaction, they are able to monitor the proceeding and often time a fraudulent request for a change in payment type or a change from one bank account to a different bank account under their control. Your agent’s email being compromised is not your agent’s fault, but acting on unverified instructions from a compromised account is your problem.
The AI-era escalation: voice and document impersonation
The verification step that professionals have relied on — the phone call to confirm — is now less reliable than it was because of voice synthesis technology. Deepfake voice technology impersonates real estate agents and title company representatives by phone, defeating the phone call verification step. The counter-protocol: establish a verbal authentication code with the closing attorney and title company at the transaction’s outset.
This is the updated operating procedure: at the beginning of each transaction, establish a shared passphrase or code word with your title rep and, where applicable, with the buyer. Any call requesting changes to financial instructions that does not include that code should be treated as suspicious regardless of what caller ID displays.
The spoofed email address often looks legitimate — info@titlecompany.com versus info@title-c0mpany.com — and the wire instructions look professional, with routing numbers and account details that are plausible. Training your eye to catch character substitutions in email addresses takes discipline but is not technically difficult. The harder problem is that AI now generates communications that are contextually accurate — the fraudulent email may reference the correct property address, the correct legal description, the buyer’s name, the actual closing date, and the real commission amount, because the criminal has read all of that from inside the transaction thread.
What to do if a wire has already gone to the wrong account
Speed is the only variable you control after the fact.
If you catch the error within minutes, contact your bank’s wire department immediately — they may cancel it before processing (typically a 30-minute window). If the wire was already sent, request an immediate SWIFT recall and fraud freeze. Your bank contacts the receiving bank to freeze and return funds. Success rates drop dramatically after the first few hours as fraudsters quickly move money or convert it to cryptocurrency.
A typical BEC attack does not let funds sit in the receiving account. Within hours of receipt, the attacker initiates outbound transfers to break the funds into smaller chunks across multiple accounts, often across multiple banks and multiple jurisdictions. The window during which a financial institution can execute a recall is real but narrow.
Contact the FBI’s Internet Crime Complaint Center at ic3.gov immediately and simultaneously. The IC3 Recovery Asset Team coordinates with financial institutions through the Financial Fraud Kill Chain to freeze fraudulent accounts — but only when complaints are filed quickly with complete details.
Preserve every email, every text, every communication in an unmodified state. Do not delete, do not forward, do not reply. The email headers and metadata are evidence. Critical evidence in Microsoft 365 and Google Workspace has retention windows measured in days. Act before it’s gone.
Notify your E&O insurer and general counsel simultaneously with the law enforcement report. Notify legal counsel and your insurance carrier. Late notification can affect coverage. The question of liability — whether it falls on you, the title company, a lender, or some combination — will be determined partly by whose systems were compromised and partly by whether each party followed reasonable security procedures.
The architecture of a fraud-resistant closing
What separates a professional who loses a commission to wire fraud from one who doesn’t is not luck — it is the degree to which the payment routing for that specific deal was established, communicated, and verified through channels the criminal could not reach.
The traditional wire disbursement process at closing passes routing information through email threads, documents, and phone calls that all live in systems susceptible to compromise. The instructions are mutable: they can be changed at any point before the wire is actually sent, and the verification mechanisms for those changes rely on the same channels the fraud used to initiate the attack.
Shaka approaches this problem differently. When the professional setting up the deal creates the payment link — defining the recipient wallets, the split percentages, and the disbursement routing at the outset — those instructions are encoded onchain. They cannot be altered by an email. A criminal who has read every message in the transaction thread cannot change where those funds land, because the routing is not in the email thread. It lives on a public ledger, cryptographically settled at the moment the deal closes. There is no “updated wire instruction” for anyone to send, because the destination is set before the money moves — not by an email an hour before closing, but by the professional who structured the deal.
For agents and brokers who handle high volumes of closings, that architectural difference is significant. The attack surface for commission diversion is the gap between when the money leaves the closing and when it arrives in the right account — a gap that, in traditional wire processing, is filled with mutable, email-based instructions. Removing that gap doesn’t require changing how you practice. It requires changing how the payment routing is established.
The liability you carry that most agents underestimate
According to a survey of nearly 650 home buyers and sellers, 1 in 10 Americans have been targeted for real estate wire fraud, while 1 in 20 have suffered direct losses over the last three years.
CertifID’s State of Wire Fraud Report found that 73% of real estate professionals had received at least one suspected wire fraud attempt in the prior 12 months. That means the professional who has not yet encountered an active wire fraud attempt in their own transactions is in the minority. It is not a question of whether the attack will be directed at a deal you are involved in — it is a question of whether your protocols are sufficient to prevent it from succeeding.
In California, agents owe a fiduciary duty and a duty of reasonable care. An agent who runs a six- or seven-figure closing through a compromised email account may have fallen short of that duty. The brokerage that supervises the agent can share the liability. If the breach originated with the escrow or title company, or the mortgage broker, that party can face its own claim for negligence for failing to secure the systems the transaction ran through.
That liability calculus is why having documented security protocols matters beyond the operational benefit. If your email was compromised and a client’s funds were diverted, the question a court will ask is whether you maintained reasonable security procedures for a professional handling six-figure wire transactions. The answer to that question is shaped by what you had in place before the attack happened.
The commission belongs to you — make sure it lands there
Wire fraud in real estate is not a technology problem with a technology solution, not entirely. It is a social engineering problem that exploits the normal behaviors of professionals who are busy, deadline-driven, and reliant on email. The defenses are procedural, habitual, and architectural — and they have to be applied consistently across every transaction, not just the ones that feel suspicious.
The practical truth is that fraudsters are patient, contextually informed, and operationally sophisticated. They do not need a foothold in your system to attack your closing — they only need a foothold somewhere in the chain. Your discipline around verification, your security posture on email, your protocols for how disbursement instructions are established and confirmed, and your willingness to slow down at the moment when everyone else is pushing for speed are the concrete things that determine whether your commission ends up in your account or in someone else’s.