How to verify you are paying the right person

How to verify you are paying the right person

When large sums move at the close of a deal, the question of whether money is actually going to the right person is not a formality — it is the central operational risk every broker, agent, closing attorney, and advisor carries. The payment instruction you act on may look exactly like every other instruction you have ever received, and it may still be wrong. Impersonation at the point of payment has become one of the most damaging and most avoidable threats in professional deal-making, and the professionals who route money — not just the principals who send it — are the ones the law looks to when something goes wrong. This article is about the mechanics of confirming the identity of a payee before money moves: what verification actually means in practice, where it breaks down, and how to build certainty into the process rather than relying on hope and habit.

Why payee identity is hard to establish from a payment instruction alone

A payment instruction — a wire detail, an account number, a routing number, a wallet address — tells you where money will go. It tells you nothing about who controls the destination. Those are two entirely different facts. The confusion between them is where fraud lives.

Banks generally do not verify the purpose or legitimacy of wire transfers. They process the instructions as given. Your bank will send the wire to whatever account you specify, even if it belongs to a fraudster. That is not a failure in the system — it is how the system is designed. The payment rails execute instructions; they do not audit the identity of the people who wrote them. The verification burden falls entirely on the professional directing the transfer.

This matters more in deal-making than almost anywhere else in commercial life, because the real estate and deal sector remains a target for attacks exploiting the high monetary values generally associated with transactions and the various communications between entities involved. A single disbursement at close — commission splits, seller proceeds, deal fees — can represent more money moving in thirty seconds than many professionals earn in a year. The average business email compromise incident in real estate results in losses of $150,000 to $200,000. That is a single event. And according to the FBI’s IC3, there were 11,677 complaints related to real estate wire fraud in one year, with total losses exceeding $446 million — a figure believed to be significantly higher, as many victims do not report the crime.

The verification problem is not that professionals are careless. It is that the attack is specifically engineered to look exactly like a legitimate instruction from a trusted party. These are not clumsy phishing emails from strangers. They are surgically targeted attacks where fraudulent instructions often come from the actual compromised email account of a title company, real estate agent, or closing attorney. The email looks legitimate because, in many cases, it technically is.

The anatomy of a payee impersonation attack

To verify a payee correctly, you have to understand precisely how impersonation works. There are several distinct attack patterns, and they require different defensive responses.

Business email compromise via account takeover

The scam is carried out by hackers who send phishing emails containing malware to employees of title companies and real estate professionals. When employees click on the links provided, it gives the hacker access to email accounts. Once inside the compromised system, the hacker obtains information about upcoming transactions. After determining the closing dates, the hacker poses as the real estate professional or the title company representative and sends a payment instruction to the parties.

The distinguishing feature of this attack is that the email actually comes from the real email account. There is no spoofed domain to catch, no subtle misspelling in the sender address. With control over a person’s real email address, the attacker can obtain knowledge specific to the transaction, information about all the parties, various timetables, and has usually already had enough access to previously exchanged emails in the transaction to seem convincing. An instruction that arrives in the middle of a legitimate email thread, uses the correct names, references the correct property, and comes from the correct email address is indistinguishable from a genuine instruction without a second verification channel.

Domain spoofing and display-name fraud

Spoofing involves creating email addresses that closely resemble legitimate ones — for example, replacing an “m” with “rn” or using a different domain. Impersonation may also include hijacking legitimate accounts, which makes it difficult for even vigilant users to detect fraud. In display-name fraud, the attacker sets the visible sender name to “Jane Smith – ABC Title” while the actual sending domain is something entirely different. On mobile devices, where the sending address is often hidden by default, this is almost impossible to spot.

Seller proceeds diversion

Home sellers are targeted for proceeds diversion. After closing, the criminal impersonates the seller to redirect disbursement of sale proceeds to a different account. It is less common than buyer-targeted fraud, but increasingly reported. For the closing attorney or title agent handling disbursements, this means the verification task does not end when wiring instructions are received before closing — the identity of the disbursement recipient must be confirmed at the point of payment, not just at intake.

The last-minute change instruction

Homebuyers and parties in the process of closing on a property can be targeted specifically by scammers who impersonate the real estate agent, mortgage broker, or closing agent and change the wiring instructions at the last minute. The last-minute change is the most reliable signal that something is wrong. Treat all last-minute changes as fraudulent until proven otherwise. Do not act on any change to wiring instructions received via email without a verbal confirmation call. The urgency framing that accompanies these changes — “the deal closes in two hours,” “the account was flagged, use this one instead” — is not incidental. One of the most common red flags of wire fraud is when the requester applies urgency tactics. The goal is that the payee does not take the time to question whether the payment is legitimate.

What confirmation actually means — and what it does not

The phrase “verify the wiring instructions” is standard advice, and it is also largely inadequate because it conflates two separate acts: confirming the accuracy of the payment details and confirming the identity of the person who sent them. You can verify every digit of an account number and still send money to a fraudster, if the instruction was injected by an attacker who controls a compromised email account.

Real verification has a specific meaning: you must reach the actual human you believe you are paying, through a communication channel the attacker does not control, and confirm that they submitted the instruction you received. Everything else is process theatre.

Out-of-band confirmation is the only reliable method

Instruct all parties to always verify wire instructions either in person or through a call to a trusted phone number. “Trusted” is the operative word. The phone number you use to call back cannot come from the same email that delivered the payment instruction — if the email was sent by an attacker, the phone number in the email belongs to the attacker. Before wiring any amount, call your title company or real estate attorney using a phone number you obtained independently — not from the email containing the instructions.

This means you need a pre-established contact record for every party in the transaction, built at the beginning of the engagement before any payment discussion happens. The number should come from a prior verified interaction, a publicly listed business number confirmed through an independent search, or an in-person exchange. It cannot be refreshed by any inbound communication at the time of payment.

The person responsible for confirming the legitimacy of the request should use the telephone number on file for the requesting party or look up the party’s number from an independent, reliable source. If a wire transfer request seems suspicious even after calling the requesting party, the professional should verbally confirm the request with a second person at the requesting party’s company or firm.

Confirming the instruction back across the channel is not sufficient

A common but flawed practice is to reply to the payment instruction email and ask for confirmation. If the payor confirms the instructions back to the company’s email, the attacker simply intercepts the confirmation email from the compromised account and confirms the bogus instructions. The reply-and-confirm approach does not add any security — it is equivalent to asking the attacker whether they are legitimate. They will say yes.

The verification has to happen out-of-band: a channel the attacker cannot intercept and cannot redirect. Phone is the standard. A documented in-person confirmation is better. An encrypted messaging platform where identity is separately established works. An unsecured email thread does not.

The specific verification tasks for each professional role

The verification obligation differs depending on where you sit in the deal. Understanding your specific exposure sharpens your protocol.

Closing attorneys and settlement agents

You are handling the largest single disbursement in the transaction — the seller proceeds. You are also the party most commonly impersonated in buyer-targeted fraud, which means you face the threat from both directions simultaneously: someone may be impersonating you to redirect funds your way, and someone may be impersonating the seller to redirect the disbursement out the back.

According to FinCEN’s analysis of BEC incidents specific to real estate, the most common victims of impersonation were individuals and entities involved in the title and closing processes within a real estate transaction. Your name and your firm’s name are the ones being used. That means your verification procedures are also the ones that clients and counterparties need to see and trust — they determine whether your instructions reach the right people intact.

For every outbound wire — seller proceeds, commission disbursements, lender payoffs — you need a verified payment instruction on file that was received through a documented channel and confirmed by a callback before any funds move. Any change to that instruction, no matter how plausible the explanation, resets the verification clock to zero. You confirm again from an independently sourced number.

Where a party received conflicting sets of wiring instructions — one legitimate and one fraudulent — courts have found that the party was responsible for the loss because they were in the best position to prevent it. This is the legal doctrine that governs professional liability in wire fraud cases: losses attributable to fraud should be borne by the party in the best position to prevent the fraud. As the professional orchestrating the payment, you are almost always that party.

Real estate brokers and agents

Title company impersonation is the most common attack vector in buyer-targeted wire fraud. Real estate agents and brokers are targeted because their email accounts provide transaction intelligence and are used to redirect earnest money deposits. Agents often use personal email accounts or have weaker security practices than institutional title companies.

The broker’s exposure here is not just operational — it is legal. If an agent’s email account was compromised, or the agent passed along fraudulent wiring instructions without verifying them, that can be a breach of fiduciary duty, and the broker who supervises the agent can share the liability. Courts examining these cases generally apply a negligence standard: liability will likely depend on whether the agent, broker, or title company employed commercially reasonable security procedures.

For the broker, this means two things practically. First, your own systems — email, file-sharing, communication platforms — need to be secured with strong authentication so that your identity cannot be used to carry an attack into the transaction. Second, you should never be the conduit for payment instructions. There is no reason that a broker, as opposed to the closing agent, should confirm or even forward wiring instructions. Any interference — even a well-intentioned confirmation of the validity of an email — could result in liability. Route payment questions directly to the closing attorney or settlement agent every time.

Advisors, dealmakers, and M&A intermediaries

Commercial deal closings carry a different profile. There is no centralized title company standing between the parties and the wire; payment instructions for purchase consideration, advisory fees, and earnest deposits may flow directly between the parties’ counsel, with your client acting on the instruction you or opposing counsel provides. In the deal sector, where transactions involve large sums of money and complex coordination among multiple parties, BEC attacks represent a particularly serious threat. Fraudsters often exploit the fast-paced, detail-oriented nature of transactions to infiltrate communication chains and redirect financial transactions.

In a commercial closing, the verification chain needs to be established explicitly — because no one else is managing it by default. Identify at the outset of the engagement whose payment instructions govern each disbursement, confirm those instructions through a documented channel, and make it a written practice that any change to those instructions requires a fresh out-of-band confirmation regardless of the explanation offered.

Verification at the wallet level: why onchain payments change the calculus

When payments move onchain rather than through bank wires, the impersonation threat shifts in two important ways. One way makes things better; one makes them worse.

The better part: a blockchain address is a permanent, immutable identifier. Once a legitimate party has provided their wallet address through a verified channel and that address has been confirmed, every subsequent payment to that same address carries the same identity assurance. You do not re-verify a bank account number every time you send a wire — but with a bank wire, the routing can be altered at the point of transmission, and you cannot observe that. With an onchain payment, the address the funds reach is exactly the address that was specified. There is no clearing house that can be intercepted mid-flight.

The worse part: many crypto payment fraud cases begin with social engineering, not with a technical exploit. Attackers impersonate vendors, support agents, founders, or even clients. They send fake invoices, swap payout addresses, or pressure staff into acting quickly. A fraudster impersonating your co-broker does not need to hack anything — they simply need to convince you that their wallet address is your co-broker’s wallet address. And because in crypto, even a minor mistake can be expensive because transactions are generally irreversible once confirmed, the cost of a single address-swap deception can be total and unrecoverable.

The verification task with onchain payments is therefore concentrated entirely at setup: confirming, through a reliable channel, that the address you are about to pay actually belongs to the person you believe it belongs to. Once that confirmation is documented and the address is locked in, the payment itself is safer than a bank wire in one meaningful sense — it cannot be redirected in transit, and the blockchain provides a permanent, publicly auditable record of exactly where it went.

This is where Shaka’s structure provides a concrete safeguard. When the payment link is created and the recipient wallet addresses are set by the professional managing the deal, that setup is a deliberate, documented act — not a runtime instruction that can be swapped out by an attacker who compromised a thread. The addresses are encoded in the deal at creation, not passed through a communication channel at the moment of payment. An impersonator who sends fraudulent last-minute instructions to a party has nothing to intercept: the disbursement was already determined before the payment conversation began.

Building a payee verification protocol that actually holds

Knowing that you should verify is not a protocol. A protocol specifies who does what, through which channel, at what point in the timeline, with what documentation. The following is a framework built on how this actually works in practice.

Establish identity before the deal reaches payment stage. Every party who will receive money — co-broker, co-counsel, advisor, seller, lender — should have their identity and payment details confirmed in a dedicated, non-rushed interaction at the beginning of the engagement. This is not a five-minute conversation at closing. It is a structured intake: the payment details arrive through a direct exchange, are confirmed by a call to an independently verified number, and are documented with a record of who confirmed, how, and when. A verification record should include who performed the check, the date, the method of verification, and the contact information used. Storing call logs, confirmation emails, and screenshots of validated instructions helps maintain an audit trail and supports internal controls or future investigations.

Treat any payment instruction received by email as unverified until independently confirmed. This applies even when the email comes from a known sender, an established thread, and a correct address. Attackers often monitor communications to insert themselves at crucial moments, such as just before a wire transfer. The instruction that arrives when a deal is in its final hours is precisely when your guard is most likely to be down and when an attacker is most likely to strike.

Confirm changes with heightened scrutiny. A change to payment instructions is the single most reliable indicator of a potential attack. It is not necessarily fraud — account changes happen legitimately — but every change should be treated with the same skepticism as a first-time instruction. Once an attacker gains access to a participant’s email account, they are able to monitor the proceeding and often time the fraudulent request for a change in payment type or a change from one bank account to a different bank account under their control. Your verification protocol for a change should be more rigorous than for an initial instruction, not less.

Never verify through the same channel as the instruction. Confirmation of the payee cannot be relied upon alone to validate that a payment request is genuine, and should be used in conjunction with strong verification controls such as conducting verbal checks on payment requests using a trusted number held on file. The trusted number is one you already have — not one that came with the instruction.

Document your verification and keep the record. This is both a professional practice and a legal protection. Courts apply the principle that losses attributable to fraud should be borne by the party in the best position to prevent the fraud. If you followed a documented, commercially reasonable verification protocol and were still deceived, your position is defensible. If you acted on an unverified instruction, the analysis runs against you regardless of how legitimate the instruction appeared. Documentation is the difference between professional standard-of-care and negligence in hindsight.

In multi-party deals, the verification challenge compounds. You may personally have confirmed the identity of your co-broker, but you are relying on the closing attorney to have confirmed the seller’s identity. You are relying on the buyer’s counsel to have confirmed the lender’s payoff. Each link in that chain carries the same impersonation risk, and a break anywhere in the chain puts every subsequent payment at risk.

BEC scams target all participants in real estate transactions, including buyers, sellers, real estate attorneys, title companies, and agents. That means your counterpart at any node in the deal has the same exposure you do. A compromised email at one party’s office can be used to attack every other party in the deal. The verification protocols you maintain protect you; they do not protect you from instructions that passed through someone else’s compromised system before they reached you.

For deals with multiple disbursement recipients — multiple brokers, multiple advisors, a seller and a lender, a commission split with a referral party — each recipient’s identity should be separately confirmed. The fact that three of five parties have verified payment details does not mean the fourth is verified. The verification is per-payee, not per-deal. There is no shortcut here. A deal that closes cleanly for four of five recipients while the fifth was compromised is not a partially successful closing — it is a fraud event with recoverable and unrecoverable components, a client who was harmed, and a professional who will spend the next two years in litigation.

Shaka’s architecture maps directly onto this multi-payee problem. Because the split and the recipients are set at deal creation — by the professional who controls the deal, using addresses confirmed before the link is ever shared — there is no window at close when a last-minute substitution can be injected. The payment link executes against fixed, pre-verified destinations. Each recipient wallet was placed there intentionally, not transmitted through a channel that could be compromised between setup and settlement.

The professional obligation this imposes

There is a version of this conversation that treats payee verification as a best practice — a sensible precaution, worth doing when time allows. That version misrepresents what the law actually holds and what professional responsibility actually demands.

Agents and brokers owe clients a set of duties including loyalty, confidentiality, full disclosure of material facts, reasonable care and diligence, and honest dealing. If a professional fails to perform due diligence — including failing to verify critical information — they may be liable under claims such as negligence, misrepresentation, fraud, or breach of fiduciary duty. Courts examining wire fraud cases have, with increasing consistency, found that liability rests with the professional who was in the best position to prevent the fraud and did not.

A Kansas federal court upheld a jury verdict that determined a real estate licensee was 85% responsible for a buyer’s losses, which occurred when the buyer transferred purchase money to a fake account after the licensee allegedly forwarded email containing fake wiring instructions to the buyer. The licensee was not the fraudster. The licensee simply forwarded an instruction without verification. That is the exposure every professional in this article faces, every time they transmit a payment instruction without independently confirming the payee’s identity.

Payee verification is not bureaucracy. It is not friction. It is the act of confirming that the money you are directing will actually reach the person who is entitled to it. Every professional in the payment chain — the broker splitting a commission, the advisor taking a success fee, the closing attorney disbursing proceeds, the dealmaker routing a finder’s fee — is both a potential target and a potential vector. The discipline of verification protects your clients, protects your professional standing, and protects you personally. At the scale of deals where these professionals operate, the stakes of getting it wrong are not recoverable from a single event. They are career-defining. Treat verification accordingly.