# How to respond after a payment fraud attempt

What to do immediately after spotting a fraud attempt, how to contain it, and how to harden the deal so it can't happen again.

---


## How to respond after a payment fraud attempt
Payment fraud in a deal doesn't end the moment you catch it. For brokers, closing attorneys, title agents, and advisors who move money at the finish line, the attempt itself — whether the funds moved or not — triggers a sequence of obligations that most professionals have never rehearsed. What you do in the first four hours determines whether the money comes back, whether your client sues you, and whether the deal survives. This article is the incident response manual that most firms don't have written down.

## The first thing to understand: there are two completely different situations

The response path splits immediately based on one question: did the funds actually move, or did you catch the attempt before the wire was sent?

These are not the same event. One is a near-miss that requires documentation, communication, and protocol hardening. The other is an active financial emergency where every minute of delay shrinks the probability of recovery. Confusing the two — treating an executed fraudulent wire with the calm of a blocked attempt, or panicking over a blocked attempt as if money is already gone — is itself a mistake that costs you.

### When the wire has not yet been sent

If you or your client recognized fraudulent instructions before acting on them, you are in a significantly better position than most fraud victims ever reach. The attempt itself is still a serious event, but the response is methodical rather than frantic.

Your first obligation is to freeze the transaction. Do not forward those instructions to anyone. Do not reply to the fraudulent email, and do not use any phone number or contact information embedded in the fraudulent communication. Call the real person — not the alleged sender of the instructions — using a known, trusted phone number you had before the transaction started. Never use any contact information from the fraudulent communication itself.

Once you have confirmed through an independent channel that the instructions were fake, preserve everything exactly as it is. Do not delete the email. Do not move it to trash. Take a screenshot that captures the full email header, the sender address, and the timestamp. The metadata in that header is evidence — it can help law enforcement trace the origin, and it documents your due diligence if a dispute arises later.

Have a prearranged plan for alerting the appropriate internal parties. This can be through a group text or group email that includes the appropriate members of management, accounting, IT, legal counsel, and underwriters. If you are a solo practitioner or small shop, that still means your E&O carrier and your insurer — not just the parties to the deal.

Notify everyone in the transaction chain using contact information you independently hold: the other broker, the lender, the title company, the attorney on the other side. A fraud attempt targeting one node of a transaction often means the attacker has access to the entire email thread. The bad actor who committed the fraud may attempt to contact the transaction parties to create confusion and ward off recovery efforts. All parties should be on alert for any attempt to delay or redirect proceedings.

Regardless of whether the attempt resulted in fraud losses or not, report it to your IT department, local law enforcement, the FBI's Internet Crime Complaint Center (IC3), and any related bank or financial institution. A blocked attempt that goes unreported is a missed intelligence opportunity — and in some states, an unreported breach of a compromised email account may carry its own legal consequences.

Finally, get your email security audited immediately. The reason an attacker knew to send fraudulent wire instructions for your specific deal, with the right parties named and the right dollar figures, is almost never a lucky guess. Most real estate wire fraud schemes follow a predictable pattern. Criminals identify upcoming transactions through public records, hacked email accounts, or data breaches of real estate software systems. They learn the parties involved, closing dates, and approximate transaction amounts. If they knew enough to target your deal, someone's inbox was compromised — and that inbox is still compromised until you find and close the access point.

### When the wire has already been sent

This is the scenario where speed is the only variable that still matters. If a buyer or seller discovers that a wire has been sent to a fraudulent account, the recovery timeline is measured in hours, not days.

## The recovery sequence: what to do in the first four hours

All of the following steps should happen within four hours of the wire fraud. Every minute that goes by lessens your chances, exponentially, of recovering any money.

### Step one: Call the wire operations department of the sending bank — not customer service

This distinction matters more than most people realize. Call your bank's wire department immediately — not the bank's main customer service line, but the specific wire operations department — and request a wire recall. Customer service representatives do not have the authority or the access to initiate a recall. You need wire operations specifically.

Banks can sometimes recall wires within the first 24 to 72 hours if the funds have not yet cleared the receiving bank. The window is narrow and the outcome is not guaranteed, but recall requests that arrive while the funds are still in transit at the receiving institution are far more likely to succeed. Tell the wire operations representative exactly what happened, give them the full wire details — account number, routing number, amount, timestamp — and use the word "fraud" clearly and directly. You are not making a complaint. You are initiating an emergency procedure.

Contact the bank that received the funds as well. Have a fraud alert sent to the receiving bank and demand that they place a fraud freeze on the account. Insist the bank confirm whether your funds are still in that account. If the funds are not in the account, do not get off the phone until you have been assured the bank will alert any other banks that received your funds to place a fraud freeze on those accounts as well.

### Step two: File with the FBI's Internet Crime Complaint Center

Report the fraud to the FBI via IC3.gov within 24 hours. This is not bureaucratic formality. Your IC3 complaint number is the activation key for the FBI's Recovery Asset Team — the unit that coordinates directly with financial institutions to freeze funds before they exit the domestic banking system.

The Internet Crime Complaint Center's Recovery Asset Team was established to streamline communication with financial institutions and assist FBI field offices with the freezing of funds for victims who made transfers to domestic accounts under fraudulent pretenses. The RAT functions as a liaison between law enforcement and financial institutions supporting statistical and investigative analysis.

Include all transaction details, email headers, and evidence of the fraudulent communication. While the FBI typically prioritizes cases exceeding $1 million, your IC3 complaint number becomes essential for working with local field offices and coordinating recovery efforts. Even if your case falls below that threshold, file immediately — the FBI can link your case to others involving the same accounts or actors, and that aggregated intelligence can trigger action that a single case would not.

### Step three: Initiate the Financial Fraud Kill Chain if the wire qualifies

If the fraudulent transfer is $50,000 or more, was sent internationally, a SWIFT recall notice has been initiated, and the transfer occurred within the last 72 hours, you may be eligible for the FBI's Financial Fraud Kill Chain process. The Financial Fraud Kill Chain is a process for recovering large international wire transfers stolen from victim U.S. bank accounts. Created by the FBI, it utilizes the Financial Crimes Enforcement Network's relationship with the Egmont Group, as well as law enforcement placements in countries around the world, to try to prevent the successful withdrawal of funds by criminal actors.

The FFKC must involve a transfer equal to or greater than $50,000. If the wire transfer was international, a SWIFT recall notice must have been initiated. Additionally, the wire transfer must have occurred within the last 72 hours.

Your sending bank initiates the FFKC process with your local FBI field office. They will need the victim's name and location, the originating bank's name and account numbers, the recipient's details including the SWIFT code, and the full amount and transaction details. Even if the wire does not meet the FFKC criteria, it should still be reported to the FBI as soon as it is detected. The FBI may be able to tie the matter to other investigations to recover funds or hold the responsible parties accountable.

Wire fraud recovery is not guaranteed — the 58% recovery rate the FBI achieved reflects funds frozen before they left the US banking system. Once funds exit to international accounts, recovery rates drop to near zero. That is why the first four hours matter so disproportionately.

### Step four: Contact legal counsel — not just to file, but to protect your position

An attorney can help you determine if you need a temporary restraining order filed. Such an order would name all the banks that received your funds and prevent them from allowing any further transfer of funds. This step is often overlooked in the chaos of the first few hours, but it is critical when funds may be bouncing between domestic accounts.

One common mistake is assuming a cyber event is not a claim-worthy incident and waiting too long to notify the insurer. Cyber policies generally require notice when an event is first discovered regardless of whether the insured decides on claim worthiness. Carriers have the right to associate in an investigation to mitigate or recover a loss.

If you have cyber liability, errors and omissions, or commercial crime coverage, notify your carrier now — not after you have assessed whether the loss is "real enough." Late reporting is one of the most common reasons for coverage denial, and delayed reporting significantly impairs the ability of carriers and their law enforcement partners to assist with active recovery.

### Step five: Notify all parties in the transaction by verified phone contact

Once all financial institutions and law enforcement agencies have been notified, any affected parties — such as buyers, sellers, real estate agents, brokers, attorneys, and underwriters — should be made aware of the fraud.

Do this by phone, using numbers you independently verified. Do not use email to communicate about the fraud investigation — if an attacker still has access to any inbox in the chain, you are handing them a live intelligence feed about your recovery efforts.

## The liability question no one wants to have but everyone needs to understand

Fraud doesn't just cause a financial loss. It causes a liability dispute. And in that dispute, you may be a defendant even if you were a victim.

Emerging case law points to liability for the party that was better able to prevent the fraud. Courts have developed what amounts to a "least cost avoider" test: when two innocent parties split a loss that a fraudster caused, the burden tends to fall on whoever had the clearest opportunity to stop it.

Some courts have found the sender liable if it was negligent in maintaining its email accounts or knew about red flags and failed to notify the other party. Other courts have found that the recipient of the fraudulent wire instructions is liable for failing to verify the instruction's validity, especially in situations where conflicting emails were sent over a short period of time or where the nature of the wire information should have raised suspicion.

For the professionals in this space — brokers, attorneys, title agents — this creates a specific exposure. Attorneys have duties of competence, diligence, communication, and safeguarding client property. Many jurisdictions now interpret technological competence to include understanding common cyber threats and implementing reasonable protective measures. Failure to implement reasonable verification safeguards may expose firms to claims that losses were preventable through industry-standard controls.

The practical takeaway is this: your incident response documentation is simultaneously your recovery evidence and your legal defense. Document every action you took, when you took it, who you called, what they said, and what reference numbers you received. Document everything meticulously from the moment you discover the fraud. Your paper trail — including timestamps, contacts, actions taken, and communications — becomes vital for law enforcement investigations, insurance claims, and potential legal proceedings.

Courts frequently examine whether policies were realistic and actually followed. If the policy required employees to call a known, verified number to confirm instructions, did the organization provide that number in an accessible way and train people to use it? If the policy required two approvals for certain transfers, did supervisors regularly approve wires without real review to meet closing deadlines? The gap between what your written procedures say and what your team actually does under closing-day pressure is where liability lives.

## Hardening the deal after an attempt: the protocol changes that matter

Whether or not the fraud attempt succeeded, the underlying vulnerability still exists until you close it. There are specific, concrete changes that you implement after an incident — not general best practices, but specific responses to what the attacker actually exploited.

### Audit the compromised email account thoroughly

Do not simply change the password and move on. The most dangerous post-compromise mistake is assuming that a password change is sufficient containment. Attackers who penetrate an inbox frequently set up mailbox rules to intercept, hide, and reply to case emails, posing as the account holder. These rules survive a password change. Every email rule, every forwarding address, every connected app with inbox access needs to be audited and cleared.

Fraudsters have been known to hack the personal email accounts of clients associated with business email compromise. Change all passwords immediately and set up two-factor authentication, whenever possible, for services accessed through the internet, such as email, banking, and social media.

### Establish a verbal authentication protocol for the rest of this transaction

The deal that was targeted is still active. It still needs to close. Every payment instruction for the remainder of that transaction must be confirmed by voice, using a phone number that was established before the incident — not any number shared in email after the attack was discovered.

Establish a verbal authentication code with the closing attorney and title company at the transaction's outset. If you didn't do this before the attempt, do it now. Agree on a specific phrase or code word that both sides will use when confirming any wire detail over the phone. This defeats the threat of deepfake voice impersonation — an attacker who intercepts the call still doesn't know the agreed-upon code.

### Rebuild your disbursement architecture for future deals

The incident should prompt you to examine the structural question underneath the fraud attempt: why is your disbursement process dependent on email-transmitted wire instructions in the first place?

Wire fraud is a transaction protocol problem, not an IT problem. The most sophisticated email security tools in the world do not address the fundamental issue, which is that unverified wire instructions sent through open channels are inherently attackable. The practical answer is to establish the payment destinations — the actual wallet or account details for each party — before the deal is in motion, in a verified session, so there is nothing to intercept or impersonate at closing.

This is precisely what Shaka is designed for. When a broker or closing professional builds a payment link on Shaka, the recipient wallets and the split percentages are set at deal creation — before urgency enters the picture, before closing-day pressure, before anyone is rushing. When the deal closes, funds move directly and automatically to each party's wallet in a single transaction. There is no instruction set to intercept because the payment architecture is already locked. An attacker who controls the email thread has nothing to redirect.

### Get your written incident response plan in place now

When wire fraud is discovered, it can be easy to panic. Having a clearly defined response plan with step-by-step instructions and contact information for all parties who should be notified can help closing agents keep a cool head when time is of the essence.

That plan should identify, specifically: who in your organization has authority to initiate a wire recall, where your bank's wire operations direct number is stored, what your IC3 login credentials are, what your E&O and cyber liability carrier's after-hours emergency lines are, and who your legal counsel is before you need them. The middle of a fraud event is not the time to look any of this up.

According to a nationwide survey conducted by the American Land Title Association, 46% of title agents report a wire fraud attempt per month. That means if you work in this space, this is not a theoretical event you are preparing for. It is the frequency of your work. A plan that exists only in someone's head, or that applies generically to "cyber incidents," is not a plan. It is a comfort artifact.

### Consider your disclosure obligations

Law firms and title companies across the country face significant financial, reputational, and professional liability risks from business email compromise scams — not just from the loss itself, but from how the incident is handled.

Depending on your state and your professional licensing requirements, a compromised email account in your firm may trigger disclosure obligations to clients whose transaction data was exposed. This is a legal question for your counsel, not a judgment call made unilaterally by the person who discovered the breach. Ask the question the same day.

## What professional responsibility actually requires of you

The standard is not perfection. No professional in this business is expected to defeat every attack. The standard — and what courts, licensing boards, and E&O carriers will measure you against — is whether you implemented the controls that a reasonably careful professional in your position would have had in place, and whether you responded to the incident with the speed and thoroughness that recovery required.

If an attorney has actual knowledge that a malicious third party is targeting one of their cases with fraudulent intent, they must notify opposing counsel or bear the loss. Wire fraud schemes expose lawyers to financial liability and risk of violating their ethical duties of technological competence and confidentiality. Lawyers must authenticate wire transfer requests through independent verification and avoid email-based requests in order to prevent fraud.

The same principle applies to brokers, title agents, and advisors. The professional who can demonstrate a documented incident response — who called whom, at what time, with what result, and what protocol change followed — stands in a fundamentally different legal and regulatory position than the professional who responded ad hoc, remembered some steps but not others, and never filed with IC3 because they didn't know it existed.

Your clients trust you to know how money moves in a deal. That trust extends to knowing what to do when someone tries to steal it.