# How wire fraud targets a real estate or deal closing

How business email compromise and spoofed instructions divert closing funds, the warning signs, and how to make diversion impossible.

---


## How wire fraud targets a real estate or deal closing
Wire fraud at closing is not a technology problem. It is a trust problem engineered by people who study your transaction in detail before you know they are watching. Brokers, closing attorneys, title agents, and settlement professionals sit at the center of exactly the threat — they coordinate the communication, they hold the relationships, and they are the names a fraudster most wants to impersonate. The real estate sector remains a target for BEC attacks specifically because of the high monetary values generally associated with transactions and the volume of communications between title companies, title agents, closing agents, and other individuals involved in the closing process. This article breaks down exactly how a diverted-wire attack is constructed, what the warning signs look like in the middle of an active deal, what the legal aftermath means for the professionals involved, and how to make the attack structurally impossible.

## The scale of what is actually happening

Before dissecting the mechanics, the numbers need to land properly. The FBI's Internet Crime Complaint Center recorded $2.77 billion in losses from Business Email Compromise attacks across 21,442 reported incidents in 2024. Real estate transactions accounted for over 2,100 of those cases, with losses exceeding $312 million. Those figures cover only reported incidents. The real number is higher.

In real estate, the average BEC incident results in losses of $150,000 to $200,000. In a residential deal, that is a buyer's down payment or the seller's entire net proceeds. In a commercial closing, it can be an earnest money deposit, a partial disbursement, or a commission wire. The American Land Title Association reports that nearly 30% of title companies experienced an attempted BEC attack in the last year. And the attacks are not random — they are targeted, researched, and timed.

CertifID's State of Wire Fraud Report found that 73% of real estate professionals had received at least one suspected wire fraud attempt in the prior 12 months. Only 31% of those attempts were reported to law enforcement. That gap between exposure and reporting is itself part of the problem: the professionals who are seeing this daily are not systematically sharing intelligence that would help others recognize the same patterns.

## How the attack is built

The diverted-wire attack — formally called Business Email Compromise, or BEC — is not a random phishing campaign. It is a patient, researched operation. Understanding the stages is how you recognize it before the wire moves.

### Stage one: Reconnaissance

Cybercriminals identify a pending sale transaction and then build a profile of the parties, including the title company, real estate agents, and the buyer and seller. They do not need to hack anything to accomplish this. Attackers research their target before sending a single message. LinkedIn, company websites, press releases, regulatory filings, and real estate records all reveal upcoming transactions, organizational hierarchies, and who holds payment authority.

Public records filings, MLS data, deed recordings, and even social media posts announcing a pending sale are enough for a professional to build a transaction profile — who is the listing agent, who represents the buyer, which title company was named in the contract, and roughly when the closing is scheduled. That is all the attacker needs to move to the next phase.

### Stage two: Access or impersonation

There are two routes into a transaction: compromise a real account, or build a convincing fake one. Spoofing involves creating email addresses that closely resemble legitimate ones — replacing an "m" with "rn" or using a different domain. Impersonation may also include hijacking legitimate accounts, which makes it difficult for even vigilant users to detect fraud.

Title companies and real estate agents are the most common targets because they handle multiple transactions and often lack enterprise-grade email security. A single compromised mailbox gives the attacker visibility into dozens of active closings.

When the attacker gets inside a real account, the level of credibility they gain is difficult to overstate. Once inside the mailbox, the attacker sets up inbox rules to forward specific emails — anything containing "wire," "closing," "settlement," or "funds" — to an external address. They study the communication patterns: who emails whom, what the standard wiring instruction format looks like, how the sender signs off.

If cybercriminals have been keeping a close eye on the deals you have pending for some time via email communications, they will know enough about the vendors, Realtors, and lenders you work with as well as their style of communication and travel schedule. This is why the fake emails feel so real: they were written by someone who has read every email in the thread.

### Stage three: The redirect

Once a BEC perpetrator gains access to a participant's email account involved in a real estate transaction, they are able to monitor the real estate proceeding and often time the fraudulent request for a change in payment type — frequently from check to wire transfer — or a change from one bank account to a different bank account under their control.

Hours before the scheduled wire, the attacker sends modified wiring instructions. The email comes from the compromised account or a spoofed lookalike domain, uses the correct formatting, references the correct property address and closing date, and changes only the routing and account numbers.

The manufactured urgency is deliberate. A common variation involves last-minute changes to wiring instructions sent just before closing. The message typically claims an unforeseen complication has arisen, or that the original bank account was compromised and funds must be sent to a new account immediately. The manufactured urgency is designed to discourage the recipient from pausing to verify.

After a successful email compromise, attackers sometimes follow up with a phone call or text purporting to be from the title company, confirming the wire instructions. The timing is deliberate: the buyer is expecting a call from their agent or title rep. The attacker spoofs the caller ID to match.

### Stage four: The cash-out

Once the wire executes, the clock runs against recovery almost immediately. Once the wire executes, criminals move immediately. Funds hit a mule account, are transferred out, and may be converted to cryptocurrency within hours — each step compressing the recovery window.

Nearly 88% of all incidents involved initial transfers of fraudulent funds to accounts at U.S. depository institutions. In several incidents, illicit funds quickly moved from bank accounts to online payment platforms or were used to purchase convertible virtual currencies, most commonly bitcoin.

The domestic first-stop is tactical: it passes scrutiny, clears faster, and then moves offshore before anyone in the transaction realizes something is wrong. As one wire fraud expert told a conference audience: "You have minutes to hours to act once you have knowledge that either your company sent money where it wasn't supposed to go." Likelihood of recovery drops to 15% after 24 hours, and to approximately 2% after 48 hours.

## Why closing professionals are the primary target

There is a reason the attack is almost always built around impersonating someone in your seat — the broker, the title agent, the closing attorney, the advisor orchestrating disbursement. The most common victims of impersonation were individuals and entities involved in the title and closing processes within a real estate transaction.

Think about what your position represents from the attacker's perspective. You are the single point through which all parties expect to receive payment instructions. Everyone in the deal has already established email communications with you. Your name, your firm, and your typical communication style are well-documented in the transaction thread. When you send wiring instructions, people comply — that is exactly how your role is supposed to work.

Real estate deals make attractive targets because they tick every box a scammer looks for: a lot of money changing hands, a tight closing deadline, and several people emailing sensitive financial details back and forth. On top of that, it is easy to find out who is involved.

The closing environment also strips out the verification behaviors that might exist in other business contexts. No standard verification protocol exists. In financial services, dual authorization and callback verification are standard. In real estate, wire instructions arrive by email, and it is normal to act on them without a separate confirmation call. Attackers count on this.

## The variants you will see in practice

The attack framework is consistent, but it surfaces differently depending on which party's account or identity is being exploited. Knowing the variant shapes how you defend against each one.

### Buyer-directed fraud

The most common pattern: the buyer receives spoofed wire instructions from what appears to be the title company or closing attorney, and sends their down payment or full purchase funds to the fraudulent account. A couple in Washington State lost $272,000 intended for a home purchase after receiving a spoofed email from their title company with fraudulent wire instructions. The buyer believed they had done everything right. The email looked legitimate, the amount matched the closing disclosure, and the deadline created pressure to move quickly.

First-time homebuyers are victimized at three times the rate of experienced buyers. This makes sense — experienced buyers have been through enough closings to notice when something feels different. First-timers simply do not have the baseline to compare against.

### Agent account takeover

Agents are high-value targets because their email accounts link to active transaction chains. A phishing email impersonating a Matrix or Dotloop notification harvests the agent's Microsoft 365 or Google credentials. The attacker logs in, maps the transaction communications, and executes the wire fraud from inside the agent's own email account.

When fraud originates from the real account, the attack is nearly invisible. The buyer, the title company, and the lender all receive emails that pass every technical check. The sender is who they say they are. The email thread is real. Only the routing and account numbers are fake.

In one case, a real estate brokerage in Manhattan lost over $1 million when a hacker gained access to an agent's email and redirected closing funds.

### Seller proceeds diversion

Here the attacker targets the other side of the disbursement. After a legitimate closing, wire instructions for the seller's net proceeds are intercepted and redirected. The seller — often expecting funds within hours of closing — does not realize the funds went to a fraudulent account until they check with the closing attorney or title company about where the money is. By then, it has moved.

This pattern is particularly dangerous in commercial transactions where net proceeds are large, multiple disbursements are happening simultaneously, and the seller may not be monitoring their email closely during the final hours of a complex deal.

### Payoff and lender impersonation

In a transaction involving an existing mortgage payoff, the attacker impersonates the lender and sends updated payoff instructions. The title company wires payoff funds to the fraudulent account. The original lender — whose loan was never paid — remains a lienholder on the property. The buyer closes thinking the title is clean. It is not.

This variant is particularly vicious because the buyer, the seller, and the closing professional may all be unaware that anything went wrong until the lender contacts them about a missed payoff, sometimes weeks after closing.

## What warning signs actually look like mid-deal

Most wire fraud prevention guidance talks about warning signs in the abstract. Here is what they look like inside an active transaction.

**An email arrives with changed instructions after instructions were already delivered.** Any change to wiring instructions is a red flag, full stop. Legitimate title companies do not change bank accounts mid-transaction. If you receive a change, treat it as hostile until proven otherwise through independent verification.

**The email domain is slightly different from every prior communication.** Domain spoofing makes it convincing. Criminals register domains nearly identical to real ones — a capital "I" in place of a lowercase "l" — which passes spam filters because it is legitimately registered and looks identical to prior correspondence. On a mobile device, you will not see this without actively inspecting the sender address.

**The message creates urgency and discourages verification.** Attackers leverage fear, time pressure, or confidentiality to override normal verification processes. "The bank account changed due to an audit — please don't call the old number" is a classic construction. Any instruction that actively discourages a callback is an instruction to comply without verifying.

**Formatting or signature is slightly off from what you know.** If cybercriminals have been monitoring communications, they will know enough about communication style and formatting to mimic it closely — but often not perfectly. The signature block might have a phone number that is one digit off. The font may have shifted slightly. The logo may be pixelated. These are easy to miss when you are two hours from a closing.

**A follow-up call comes in confirming the new instructions.** This one catches professionals off guard. They apply the right instinct — call to verify — but the call they receive is the attack. The number was included in the fraudulent email, the caller ID is spoofed to match the legitimate firm, and the call reinforces the redirect.

## What happens after the wire goes to the wrong account

Recovery is technically possible, but the odds collapse quickly and are never guaranteed. Recovery is possible, especially in the first 24 to 72 hours, but not guaranteed. The majority of BEC funds not intercepted within the initial window are never returned. Speed of response is the single most important factor.

FinCEN has had greater success rates in identifying and freezing funds when victims or financial institutions report unauthorized and fraudulent BEC wire transfers to law enforcement within 72 hours of the transaction. The FBI's Recovery Asset Team operates a Financial Fraud Kill Chain specifically to coordinate rapid response between financial institutions — but it only functions when someone activates it fast.

The moment you suspect a misdirected wire: call your bank's fraud department, not the help line. Ask specifically for wire operations and the ability to initiate a recall. File an IC3 complaint immediately with the receiving bank's routing number, the fraudulent account number, the exact wire amount, and the time of the transfer. Do not delete any emails, do not change passwords on the suspected compromised account, and do not modify any inbox rules — that evidence is how investigators reconstruct the attack chain.

Once sent, money often disappears within hours through a web of international accounts. The bank cannot guarantee recovery even with a same-day recall request. The receiving bank may hold cooperative obligations, or it may not. International transfers complicate jurisdictional recovery further. Cryptocurrency conversion makes recovery functionally impossible in most cases.

## The liability that lands on the professional

The downstream legal consequences of a diverted wire do not stay with the attacker — because the attacker is gone. The proximate cause of these losses is the scammer who diverted the wire transfer and disappeared, but courts are left with the unenviable position of determining and allocating legal fault among the remaining parties, all of whom are victims to some extent.

Liability for losses stemming from fund misdirection often hinges on either the terms of contracts between the parties or a deceptively simple rule: the party best positioned to prevent the fraud should bear the loss. In a real estate or deal context, that analysis points directly at the closing professional.

Analysis of over 100 wire fraud cases reveals a trend: title companies, law firms, and real estate professionals are increasingly being held liable for losses when client funds are diverted to fraudulent accounts. Despite the criminals being the primary perpetrators, courts are holding these professionals to higher standards of care, expecting them to implement robust security measures and educate their clients about the risks of wire fraud.

For closing attorneys, the exposure is compounded by fiduciary duty. Failure to verify instructions — accepting emailed wiring directions without an independent check — can result in malpractice claims if funds vanish. Lawyers handling transaction funds owe clients a fiduciary duty higher than mere reasonableness. Failing to use encrypted communications, two-factor authentication, or secure portals for wiring instructions could be seen as falling below the standard of care. Several state bar associations have warned lawyers that email-only confirmations of wiring instructions are malpractice traps.

Even when the professional is also a victim, courts may still assign liability. An estate's executor sued attorneys for negligence, legal malpractice, breach of contract, and breach of fiduciary duty, claiming that their failure to verify transactions directly caused financial harm. The case highlights how law firms, acting as fiduciaries, can face direct legal liability when failing to implement basic verification and cybersecurity protocols. Even if a firm is also a victim, clients can still hold attorneys accountable for failing to protect entrusted funds.

Insurance is not a reliable backstop. In *Helms v. Hanover Insurance*, a couple wired $120,000 to fraudsters and sued their broker and real estate agent, alleging negligence. Seeking defense from Hanover Insurance, the agent's E&O policy claims were flat-out denied. According to the court, the agent's E&O insurance was never designed to cover wire fraud, containing unambiguous fund misappropriation and fraudulent transfer policy exclusions.

In *Hoffman v. Atlas Title*, the court allowed negligence and breach of fiduciary duty claims to proceed against a title company that sent unencrypted wire instructions despite previous security breaches, resulting in intercepted communications and a loss of nearly $290,000.

The pattern is consistent: professionals who did not implement independent verification, who transmitted wire details through unsecured email without secondary confirmation, or who failed to warn clients about the risk are being held to account — not because the law is harsh, but because their position in the transaction gave them the greatest ability to prevent it.

## How to construct a transaction that resists diversion

The attack has a structural weakness: it depends entirely on a recipient acting on wire instructions received through a single channel without independent verification. Remove that dependency and you remove the attack's power.

**Establish the verification protocol at the start of the transaction, not at closing.** Every party — buyer, seller, their counsel, the title company — should receive in writing, at the time of engagement, a single sentence: wire instructions will never be changed by email alone. Any change requires a callback to a number established outside of email correspondence.

**Call to verify every wire before it moves, using a number you already hold.** If you get any unexpected change to wiring instructions, account numbers, or routing numbers, stop and verify it before doing anything. Call the person using a phone number you already have, not one from the new message. This is not a complicated protocol. It is a 90-second call that collapses the entire attack.

**Treat any change to instructions as hostile until verified.** The change may arrive from a legitimate-looking email. It may arrive with a follow-up call. It may arrive with the correct property details and a plausible explanation. Last-minute urgency around "updated instructions" or "emergency changes" is itself the signal. Urgency is not a reason to skip verification — it is a reason to demand it.

**Implement domain-level email authentication on your own systems.** DMARC, SPF, and DKIM prevent attackers from spoofing your domain when targeting your clients. This does not stop a lookalike domain attack, but it removes one of the most common vectors and protects your clients from receiving fraudulent emails that appear to originate from you.

**Warn your clients in writing before they are close to wiring anything.** Many closings go wrong because buyers have never been told, in plain terms, that this attack exists and that they should expect it. A short written disclosure at the time of engagement — what the process will look like, how instructions will be delivered, what a change request would never look like — shifts the buyer's awareness at the moment when it costs nothing to do so.

The deeper structural answer is to remove wire instructions from email entirely. When payment destinations are set in advance, encoded into a transaction protocol before the closing pressure begins, and confirmed through a channel other than the one attackers have compromised, there is no opportunity for a spoofed instruction to land. Shaka works precisely this way: the payment routes — who receives what, in what proportion — are defined when the deal is structured, not when it closes. The funds move to those verified destinations automatically at execution, with no email carrying routing numbers at all. The attack surface that BEC depends on simply does not exist.

## The professional standard is moving

The complexity of these cases and the evolving standards of care are pushing courts towards favoring greater protections for consumers. These cases suggest a novel fact pattern and an evolving standard of care, indicating a trend toward imposing more stringent duties on real estate professionals.

What was considered reasonable practice a few years ago — sending wire instructions via standard email, relying on a single confirmation call, assuming the buyer would notice a domain discrepancy — is increasingly being treated as insufficient. Courts are looking at what technology and protocols were available, whether the professional used them, and whether the failure to use them put the client in a position they could not protect themselves from.

Generative AI is making BEC lures more convincing and easier to create. By mid-2024, an estimated 40% of BEC phishing emails were AI-generated. The emails that were once identifiable by awkward phrasing or formatting inconsistencies now read as genuine. The burden on the recipient to catch an error that was never planted has never been higher.

The professionals who understand this threat deeply — who set the protocol at the start, who run the verification call without exception, who put the warning in writing before the buyer is close to wiring anything — are the ones who will not be in a courtroom explaining why they did not. That is not a compliance exercise. It is how serious people manage the most concentrated moment of financial exposure in their clients' lives, and protect their own standing in the process.