# How to recognize a payment scam in a high-value transaction

The red flags of a payment scam in a big deal, the pressure tactics fraudsters use, and how to slow down and settle safely.

---


## How to recognize a payment scam in a high-value transaction
You are one of the most targeted professionals in the fraud ecosystem. Brokers, closing attorneys, escrow agents, title professionals, and advisors sit at the exact moment when large sums of money are in motion and decisions need to be made fast — which is precisely where fraud operates best. The dollar amounts are large enough to justify serious criminal investment, the number of parties involved creates communication noise, and the closing timeline creates a natural pressure that scammers exploit before anyone has time to think twice. This article is about pattern recognition: how to read the signals across every tactic currently deployed against deal professionals, so that you can separate urgency that is real from urgency that is manufactured.

## Why high-value transactions attract professional-grade fraud

Criminals invest considerable time, effort, and resources into perpetrating these scams — and they do so for very good reason: the payoff can be enormous. A residential closing worth $800,000 in earnest money, a commercial deal with a $2 million disbursement, a business acquisition with a seven-figure broker fee — these are not targets of opportunity. They are planned attacks.

The first step in a well-executed scam is gathering intelligence. Scammers research their targets, gathering details — full names, job roles, vendors, digital services used — from social media, data broker sites, data breach dumps on the dark web, and company pages. By the time a fraudster makes contact, they may already know the names of every party in the deal, the approximate timeline, and who controls the wire. They are not guessing. They are operating on researched information, which is what makes their approach feel so plausible from the inside.

The FBI's Internet Crime Complaint Center attributed 73% of all reported cyber incidents to business email compromise, with cumulative losses exceeding $55 billion over the past decade. That number does not include unreported cases, which security researchers consistently note are a significant undercount. Business email compromise alone accounted for about $2.8 billion in losses in one measured period. These are not fringe events. They are the dominant threat vector in high-value commercial and real estate transactions, and every professional who handles disbursements needs to be able to read the signals.

## The anatomy of how a scam enters a deal

Before looking at individual red flags, it helps to understand the structural pattern that nearly all payment scams in high-value transactions share. The mechanics differ — email compromise, phone impersonation, document forgery — but the underlying architecture is consistent.

After gathering intelligence, the scammer creates a believable story — a pretext — explaining why they're contacting you and why the action they require is justified. Then they make contact through a suitable channel, often creating a sense of urgency, fear, or exclusivity to make you lower your guard and respond with the desired action.

Attackers either spoof or take over legitimate email accounts, study normal communication patterns, and then send messages that appear routine, urgent, and authentic. The goal is typically financial — redirecting payments or authorizing fraudulent wire transfers.

The reason this works is not stupidity on the part of the target. Business processes incentivize speed of payments; payment teams are often trained to avoid processing delays and maintain vendor relationships. Perpetrators of BEC fraud exploit this operational pressure. In a competitive deal environment, where a missed wire can derail a closing and cost a professional their commission or their client, the pressure to act fast is a design feature of the work — and an exploitable weakness.

At the end of that chain sit the wiring instructions that move the money. Parties may send initial instructions days in advance, then send updated or corrected versions by email as details change. Attackers study this pattern. They know when to send the fraudulent message because they've been watching the thread.

## Red flag one: urgency that exists only in the communication

The single most reliable marker of a scam is manufactured urgency — a pressure to act now that serves the fraudster's timeline, not yours.

Scammers often create a false sense of urgency, pushing you to "act now" without giving you time to review details or consult with legitimate advisors, and communicating things like "this is your only chance." In a real transaction, urgency is almost always explainable and verifiable. The wire needs to go out because the seller's bank has a cut-off time at 3 p.m. The disbursement needs to happen today because the lender's funding window closes. You can check these things. You know who to call.

Scam urgency is different. It exists in the message itself, not in the underlying transaction mechanics. Three effective levers are urgency, emotion, and habit. The sense of urgency can trick otherwise rational targets into handing over personal information or releasing funds without verification. The message tells you the deal will fall through if you don't act in the next thirty minutes. But when you pick up the phone to verify — not using the number in the email, but the number you already have — you often find that the timeline is entirely fabricated.

These requests often occur when the executive is unavailable or difficult to contact, increasing the pressure to comply without proper verification. The attorney is "in court." The lender contact is "traveling internationally." The party you need to verify with is conveniently unreachable through normal channels. This is not coincidence — it is architecture. A scam that can be verified in thirty seconds through a known phone number dies immediately. So the fraudster pre-eliminates that option.

After monitoring news accounts and press releases and performing other "due diligence" on an unsuspecting employee, sending a feigned wire instruction just when a transaction is about to close and indicating that payment needs to be made by a certain time for the deal to close often works with great effectiveness to cause payment to be made to the bad actor. Timing is not accidental. If you receive payment pressure at the precise moment a deal is approaching close — from an unexpected direction — that timing itself is a signal.

## Red flag two: last-minute changes to payment instructions

The FBI reports that last-minute wire instruction changes are scammers' most common tactic. If you understand one pattern in payment fraud, make it this one.

Once attackers compromise an account or set up a spoofed address that looks nearly identical to a trusted party, they wait for the right moment. A carefully timed message that appears to be from the title company, a lawyer, or an internal executive, changing account numbers or confirming "revised" instructions, can slip into an already busy thread without raising suspicion.

If you're deep into a transaction and receive a sudden request to change wiring instructions or payment details, slow down. Verify the change directly with your trusted contact before doing anything. And critically: verify using contact information you already have, not the contact information in the email that delivered the change request.

To verify wire instructions properly, call the title company or lender using a phone number you already have. Never use the contact information in the email that contains the wire instructions. Real businesses give you wire instructions early in the closing process, not at the last minute.

The common pattern is this: a fraudster hacks into an entity's email system and sends new wiring instructions to a payor. The payor, thinking the payee sent the new instructions, complies with them and unknowingly wires the payment to the fraudster. There is often nothing in the message itself that looks wrong. The domain may be off by one character. The sender name may be correct. The subject line may be a continuation of a legitimate thread. The only reliable defense is out-of-band verification — a phone call to a number you independently know is real.

This applies not just to instructions sent by email. Some scammers send fake purchase offers to gain your trust, then follow up with a "payment update" to reroute funds. The initial contact is clean and legitimate-looking. The fraud is introduced later, once trust is established, in the form of a "correction" or "update" to payment details. Deals that have moved smoothly through negotiation and documentation are not immune. The attack often arrives after goodwill has been built.

## Red flag three: identity that cannot be independently verified

Key characteristics of scam attempts include impersonation: scammers often impersonate high-level executives, employees, or business partners. They might use email addresses similar to legitimate ones, sometimes differing by just one letter or symbol.

In a multi-party deal, the cast of characters is large and the introduction of new names is normal. A lender's operations contact. A co-counsel. A referral party's representative. A counterparty's advisor. Cybercriminals will register a domain similar to that of the company and set it up for mail delivery, mimicking a high-priority employee such as a CEO, company attorney, or trusted vendor.

Attorney impersonation in particular exploits trusted relationships with large, well-known law firms to increase credibility. Payment redirection to an illicit bank account occurs once agreement on payment terms is reached. The fraudster does not announce themselves as a fraudster — they show up as "outside counsel" or "the transaction attorney" or a named partner from a recognizable firm. Groups have been documented putting considerable research into M&A-specific scams, crafting detailed email campaigns and setting up secondary email chains that appear to be from a major law firm facilitating the deal. Average transfer requests in these attacks have reached USD 1.27 million, with the highest nearly USD 3 million.

The marker here is that legitimate parties in a deal can always be verified through channels that predate their involvement in your specific transaction. A law firm is findable in state bar records. A lender is licensed. An advisor has a public footprint. You should be able to verify any agent, buyer, or company involved. Can't find their license? No online reviews? No local business address? That's a red flag. Real estate is a regulated business — anyone legitimate won't hesitate to prove it.

## Red flag four: confidentiality used as a control mechanism

One of the more sophisticated pressure tactics is the request for secrecy. The transaction is described as sensitive, confidential, or subject to regulatory restrictions that prevent you from discussing it with colleagues or other parties. You're told not to mention it to your compliance contact, your assistant, your manager, or anyone else until the wire is confirmed.

A finance team member receives a call that sounds exactly like their CEO, CFO, or General Counsel, complete with familiar speech patterns, verbal mannerisms, and contextually accurate references to real company business. The caller creates urgency around a time-sensitive payment, requests that the employee not discuss the matter with colleagues until it is resolved, and applies the kind of authority pressure that most employees are psychologically conditioned to comply with quickly and without challenge.

In a legitimate deal, confidentiality requirements are real but narrow. They govern what you say externally about deal terms. They do not govern your ability to run a payment through your normal verification process, confirm instructions with a known contact, or get a second set of eyes on a wire. Any instruction that tells you to skip your own internal controls in the name of confidentiality is designed to eliminate exactly the friction that would have caught the fraud.

Never let urgency override security. This is not just general advice — it is the specific anatomy of why sophisticated scams succeed. The urgency and the confidentiality request work together to create a window in which normal verification feels impossible or inappropriate. That window is manufactured.

## Red flag five: payment structure that deviates from deal norms

Scams do not always arrive in the form of a changed wire. Sometimes the deviation is in the structure of the payment itself — who is being paid, in what amounts, through what method, and in what sequence relative to the deal milestones.

If someone asks for money before you've reviewed and signed documents, that's a clear signal that something's wrong. In high-value deal work, payments follow documentation. Earnest money follows a signed purchase agreement. Commissions follow a closed transaction. Disbursements follow a funded deal. Any request to move money ahead of the document sequence that normally precedes it is worth a hard pause.

Fraudsters often use high-pressure tactics to get you to sign documents or transfer funds before you have had the opportunity to do due diligence. For instance, a seller might try to create pressure by suggesting many other buyers are interested in the property and that if you do not act fast, you will lose the deal. In a real transaction, the existence of competing interest does not remove the professional's right — and obligation — to verify payment mechanics before disbursing.

Investors need to be cautious of transactions involving splitting payments across multiple financial institutions, which makes it difficult to track the origin of funds. Unusual disbursement structures — routing funds through unfamiliar intermediaries, splitting a single payment into multiple wire tranches, or requesting payment to an account in a jurisdiction that has no relationship to the deal parties — are structural red flags. In clean transactions, money follows a predictable path. When the path is complicated for no explained reason, ask why.

## Red flag six: the new threat surface — voice and video impersonation

For years, the markers of a scam were textual: a slightly misspelled domain, an unnatural phrase, an email that arrived from a free account. Professionals learned those signals. Old-school wire fraud attempts arrived via email with recognizable tells: slightly misspelled domains, unnatural phrasing, and an air of urgency. Recipients had learned to spot them. AI voice cloning removes those signals entirely.

With just three seconds of audio, AI can convincingly clone a voice — CEO speeches, podcast appearances, and LinkedIn videos all provide ample source material. The voice on the call can sound precisely like the person you've been working with for weeks. The inflection is right. The name references are right. The context is right. Deepfakes extend social engineering from text into voice and video, defeating verification methods that once provided meaningful assurance.

The canonical deepfake case involved a Hong Kong employee who transferred $25.6 million after attending a video conference where the CFO and all other attendees were deepfake recreations. This wasn't a traditional cyberattack of the kind that compromises a company's digital systems. This attack used psychology and sophisticated deepfake technology to gain the employee's confidence. The employee had suggested a video call as a verification step — a step that security experts recommended — and the attackers had prepared for exactly that.

In one documented case, the attackers even introduced a fake lawyer to the call to boost credibility. The combination of authority, urgency, and apparent consensus helped overcome the victim's skepticism.

What this means practically is that a voice call or video call is no longer a reliable verification channel on its own. If a call "from the CEO" or "from the attorney" comes in, verify via a separate, independent channel — call back on a known mobile number, or speak in person. The attacker may fake one channel, but not all simultaneously. The verification method has to use a communication pathway that the attacker cannot have pre-staged. A phone call to a number you have independently confirmed, placed by you rather than received by you, is the baseline.

## Red flag seven: the deal itself is too clean, too fast, or too perfectly structured

Not every scam targets the payment mechanics of an existing deal. Some scams construct the deal itself. A new client appears with unusually motivated terms: they'll pay above ask, they don't need financing, they want to close quickly with minimal conditions. This pattern is worth reading carefully.

Too-good-to-be-true promises — like guaranteed approval with no checks, zero closing costs, or uniquely favorable terms — are significant alarm bells of fraud. If something sounds too perfect, take a close look at the deal and its terms.

Criminals frequently use straw buyers — individuals who make purchases on behalf of others — to conceal their identities. Payments from unrelated third parties also suggest attempts to obscure the true beneficial owner. In a legitimate deal, the person or entity signing is the person or entity whose name is on the payment. When there is a gap between those two — when the wire originates from a party whose name never appeared in the transaction documents — it should prompt questions, not just a cleared payment.

Scam contracts often skip key details, like closing dates, buyer and seller information, or exact payment terms. An offer that creates energy and urgency but is vague in the places where legitimate contracts are precise is an incomplete document being used to generate momentum. Momentum that benefits someone. Before a payment goes anywhere in a deal with documentation gaps, those gaps should be closed.

## The compound threat: when multiple red flags appear together

Individual red flags are useful. But the most dangerous scam scenarios are the ones where multiple signals arrive together in a context designed to make each one feel explainable.

The urgency is explained by a real deadline. The changed instructions are explained by a "bank account update." The new contact is explained by a "firm restructure." The request for confidentiality is explained by regulatory sensitivity. Each element, in isolation, has a surface-level explanation. Together, they form a pattern.

Many organizations have policies requiring payment verification — but lack segregation of duties and auditability. As a result, policies fail to prevent fraud precisely when urgency is introduced. The moment when a verification process feels most like an obstacle — when the pressure to release funds is greatest and the justifications for skipping steps are most plentiful — is the moment to apply the process most rigorously.

Real estate and deal fraud thrives in complexity. The more parties involved, the more communications flying around, the more participants are expected to trust without knowing who is doing what — the easier it is for bad actors to find a way in. As the professional responsible for how money moves in the deal, your role is specifically to hold that complexity in check at the moment of disbursement.

## What the pattern of recognition actually looks like in practice

Understanding red flags conceptually is one thing. Applying them under closing-day pressure is another. The professional response to any payment scenario that contains even one significant flag is not to delay indefinitely — it is to verify out-of-band before moving money.

No single call or video conference should trigger a payment — regardless of who it appears to be from. This is the operational standard that defeats the widest range of tactics, from BEC email to AI voice cloning to deepfake video. The payment instruction and the payment authorization should travel through different, independently verified channels.

It is almost impossible to get money back once it has been sent through a wire transfer. The asymmetry between the cost of a thirty-minute verification and the cost of an unrecoverable seven-figure loss is so extreme that speed of payment should never be weighed against certainty of payment. A deal that genuinely cannot survive a thirty-minute verification call was not structured soundly to begin with.

When payments are set up through a transparent system where every recipient wallet and split percentage is confirmed before the deal closes — and where all parties can see the disbursement structure in advance — there is far less surface area for a fraudulent instruction to slip in at the last moment. This is the core advantage of tools like Shaka: when the routing is agreed upon and locked before the wire, a late-stage "payment update" from an unknown email thread has no mechanism to alter where the money goes. The deal's payment architecture is set, not subject to last-minute instruction.

Professionals who prioritize constant vigilance, who regularly discuss evolving scams, and who foster a culture where it is appropriate to slow down, question unfamiliar individuals, and approach every interaction with professionalism before taking action — those are the ones who do not become case studies. The fraud environment will continue to evolve, and the technical tools it deploys will continue to improve. But the logic underneath every scam remains the same: create urgency, impersonate trust, and eliminate the verification window before the target has time to use it. Your job is to keep that window open every single time.