Real Estate Wire Fraud Is a Cyberattack — Here’s How It Works

Key Takeaways

  • Real estate wire fraud is a sophisticated cyberattack – not just a scam – that combines email hacking, psychological manipulation, and precise timing to steal closing funds.
  • Attackers can silently monitor a real estate transaction for weeks before making their move, often striking on a Friday afternoon when everyone is distracted and rushing to close.
  • The single most effective defense is also the simplest: always verify wiring instructions by phone using a number you already have on file – never trust contact details from an email.
  • If a fraudulent wire is sent, recovery is possible but only within a very narrow window – you must call your bank and file with the FBI within hours, not days.
  • Understanding exactly how these attacks work is the first step to stopping them – keep reading to see the full playbook scammers use from start to finish.

Most people think of wire fraud as a clever con – someone pretending to be a lawyer or title company and asking for money. That is part of it. But the reality is more technical, more patient, and far more dangerous than a simple impersonation. Real estate wire fraud is a structured cyberattack, and the people behind it follow a deliberate, step-by-step process to pull it off.

Real Estate Fraud Is a Growing Slice of a Multi-Billion Dollar Problem

Business Email Compromise (BEC) – the category of cybercrime that drives real estate wire fraud – generated over $2.9 billion in losses across all sectors in 2023, according to the FBI’s Internet Crime Report. Real estate and rental transactions are among the most targeted, and the numbers continue to worsen. FBI data shows real estate-specific losses reached $145.1 million in 2023, climbing to $275.1 million by 2025 as complaints continue to rise year over year.

Loss figures per real estate BEC incident vary by fraud type and year. CertifID’s 2026 State of Wire Fraud report shows a median loss of $239,850 for buyer cash-to-close fraud and $343,497 for seller net proceeds fraud – in either case, often representing a buyer’s or seller’s entire savings wired to a fraudster’s account in a single transaction. CertifID’s 2026 data shows nearly 1 in 4 (22%) homebuyers reported receiving a fraudulent or suspicious communication during their closing process, with roughly 1 in 20 becoming actual victims.

For small real estate businesses – independent agents, title companies, small law firms – the stakes could not be higher. If you want to know where your own transaction workflow is exposed, TechEd Shield’s free cybersecurity health check is built specifically to help non-technical small business owners understand and defend against exactly these kinds of attacks.

Bar charts showing rising real estate wire fraud losses and BEC complaint counts
Real estate wire fraud losses and BEC complaints are both climbing year over year.

BEC vs. EAC: Two Ways Scammers Hijack a Deal

There are two distinct attack types behind most real estate wire fraud, and understanding the difference matters because they require different defenses.

BEC: Impersonating a Trusted Party From the Outside

Business Email Compromise (BEC) is when an attacker pretends to be someone in the transaction without actually accessing their account. They register a look-alike domain – swapping an “l” for a “1,” or “rn” for “m” – and send emails that appear to come from a title company, attorney, or agent. The sender’s display name looks right; only the actual email address gives it away, and most people never check.

EAC: Operating From Inside a Legitimate Email Account

Email Account Compromise (EAC) is more dangerous. Here, the attacker has actually broken into a real email account belonging to someone in the transaction. Every email they send comes from a legitimate, verified address. There are no spoofed domains to spot. This is why EAC attacks are so much harder to detect – the threat is operating from the inside.

How Attackers Break Into Email Accounts

Getting into someone’s email account is not as hard as it sounds, even when two-factor authentication (2FA) is turned on.

AiTM Phishing Defeats Two-Factor Authentication

One well-documented technique is called Adversary-in-the-Middle (AiTM) phishing. The attacker sets up a fake login page – a convincing copy of Microsoft 365 or Google Workspace – and sends a phishing link to the target. When the victim enters their credentials, the attacker’s server quietly relays everything to the real login service in real time. The real service sends back an MFA challenge (a push notification or SMS code), which the fake page passes along to the victim. The victim completes it. The real server issues an authenticated session cookie. The attacker intercepts that cookie and uses it to log in independently – completely bypassing MFA. Tools like EvilProxy automate significant portions of this process — the same MFA-bypass technique behind most modern account takeovers used across email-based fraud, not just real estate transactions..

Hidden Inbox Rules That Forward and Delete Evidence

Once inside the account, the attacker does not immediately do anything visible. Instead, they create hidden inbox rules programmed to scan for emails containing words like “wire,” “closing,” “routing,” or “deposit.” Matching emails are silently copied to an external address the attacker controls. A second rule moves the originals straight to trash, so the real account holder never sees them. These rules are often named with a single period or semicolon to avoid detection during any manual review. From this point, the attacker can read the entire transaction – without the victim knowing.

The Attack Unfolds in Three Quiet Stages

Reconnaissance: Identifying the Target and the Transaction

Before any phishing email is sent, the attacker does research. Public MLS listings, property transfer registries, and social media provide everything needed: the parties involved, the property value, and the expected closing date. This is open-source intelligence gathering – no hacking required at this stage.

Monitoring: Weeks of Silent Observation

After gaining email access, the attacker watches and waits. They read every message, studying the communication style of the agent or title officer, learning the transaction timeline, and identifying the exact moment when wiring instructions will be needed. This monitoring phase can last for weeks.

The Strike: Fake Wiring Instructions at the Worst Moment

When the closing date arrives, the attacker injects fraudulent wiring instructions into the active email thread – either from the compromised account itself or from a spoofed look-alike domain. The email looks like a routine update. The account number and routing number are changed. Everything else – the tone, the formatting, the sign-off – looks exactly right.

In one case reported by a title insurance industry publication, a Texas real estate agent had her email account compromised, and scammers used it to send a buyer fraudulent wiring instructions that resulted in $80,000 being transferred to a fraudulent account.

Why Victims Almost Always Comply

Manufactured Urgency That Shuts Down Verification

The message rarely arrives calmly. It arrives with a deadline: “The wire window closes in 45 minutes – if funds are not received, you will lose your earnest money.” That kind of artificial pressure triggers a psychological response where the brain focuses entirely on completing the task and stops looking for warning signs. The urgency is manufactured specifically to prevent the victim from pausing to verify.

Fraudulent Instructions Embedded in a Trusted Thread

The fake instructions do not arrive in a cold, out-of-nowhere email. They appear inside an existing, legitimate conversation thread – the same one the buyer has been reading for weeks. Attackers frequently impersonate real estate agents, title or settlement agents, and loan officers. When the message comes from a familiar thread, in a familiar voice, with familiar formatting, the brain reads it as safe.

Why Friday Closings Carry the Highest Risk

The timing of these attacks is not random. Real estate closings are widely reported by title and escrow professionals to cluster on Friday afternoons, driven by buyer preference to move over the weekend. Attackers know this and deliberately target Friday windows – not just because that is when the money moves, but because a fraud committed Friday afternoon will not be discovered until Monday morning. That two-day gap gives criminal networks time to move stolen funds through secondary accounts and into cryptocurrency before any bank or law enforcement can intervene. High cognitive fatigue at the end of the week also makes transaction coordinators and buyers more likely to skip verification steps under pressure.

Recovery Is Possible – But Only If You Act Within Hours

Step One: Call Your Bank. Step Two: File With the FBI IC3

The moment a fraudulent wire is discovered, two actions need to happen simultaneously – not one after the other. Contact the sending bank’s fraud department to request an emergency wire recall, and file a formal complaint at ic3.gov (the FBI’s Internet Crime Complaint Center). Both must happen in parallel, ideally within the first two to four hours.

Timeline of steps to recover wired funds within the critical 72-hour window
Recovering stolen wire funds requires action within hours — not days.

The Financial Fraud Kill Chain: Conditions and Limits

Filing with the IC3 triggers the FBI’s Financial Fraud Kill Chain (FFKC) – a coordination process between federal law enforcement, FinCEN, and financial institutions designed to freeze diverted funds, particularly those transferred internationally, before they are dispersed. In 2023, the FBI’s Recovery Asset Team initiated the FFKC on 3,008 incidents involving $758 million in potential losses and successfully placed holds on $538 million – a 71% success rate. The FFKC has strict requirements: it generally applies to international wire transfers of at least $50,000, and a SWIFT recall notice must be initiated within 72 hours of the wire being sent — so filing your IC3 complaint and contacting your bank immediately is essential. After that window, recovery becomes significantly harder.

Who Bears the Loss When Funds Are Gone

In the United States, liability for wire fraud losses is not automatically assigned to the bank. Under the Uniform Commercial Code (UCC) Article 4A, if a bank follows reasonable security procedures and executes a transfer based on the sender’s actual instructions, the bank is generally protected – leaving the victim to absorb the loss, a gap made worse by the “voluntary parting” exclusion that lets insurers deny wire fraud claims outright. Civil cases increasingly target the title companies, brokers, or law firms whose poor security practices allowed the compromise. Cyber insurance can help, but the coverage gap between policy limits and actual wire fraud losses is often wider than owners expect, and some policies include verification clauses that deny coverage if the policyholder cannot document that they verbally confirmed wiring instructions out-of-band before sending the wire.

According to the American Land Title Association (ALTA), a significant share of title companies have experienced attempted BEC attacks – and only about 60% of successful compromises are even reported to the FBI, meaning real losses are almost certainly higher than the data shows.

Always Verify Wiring Instructions by Phone – Never Email

The single most effective countermeasure against real estate wire fraud costs nothing and requires no technical expertise: call to confirm. Before sending any wire transfer, call the title company, attorney, or agent using a phone number already saved on file – not a number from the email in question. Confirm the account number and routing number verbally. Do not rely on contact details provided in a last-minute email, even if the email looks completely legitimate.

If instructions change mid-transaction – especially close to the closing date – treat that as a red flag, not a routine update. Any change in banking details should be re-verified from scratch, using a trusted number established early in the transaction.

Before you send a wire — or if one just landed in your inbox — run it through this 60-second check. Answer honestly. If more than one of these applies to the email in front of you, stop and pick up the phone.

Wire Request Red Flag Checker

Check every box that applies to the email or wire request you’re looking at right now.

This checklist won’t catch every scam, and it isn’t a substitute for verbal verification. But it takes the instincts you just read about and turns them into a habit you can use under pressure — which is exactly the moment fraudsters are counting on you not to have one.

Wire fraud works because it blends in. The emails look real, the timing feels right, and the pressure makes verification feel inconvenient. That is exactly what the attacker is counting on. Breaking that pattern – with one quick phone call – is the most powerful defense available.

Newsletter Updates

Enter your email address below and subscribe to our newsletter