Sector briefing · real estate
The closing wire is the target. Everything else is setup.
A brokerage runs on email, deadlines, and one wire that has to arrive on time.
That combination is why real estate has become one of the most reliable
fraud channels there is — the attacker does not need to break into
anything. They need one thread, one reply, and one person who trusts the
instructions already in the message.
By the time the wire leaves, the money is gone. Verification has to happen
before the client is at the table.
monitoring
Weighted from closing-wire fraud reporting and real-estate sector
keyword monitoring across brokerages, title and escrow workflows.
Why real estate specifically
One-shot deadline
Closing day does not reschedule
Every party is under time pressure and everyone is reachable by email.
A message that arrives at the right moment with the right matter number
does not need to be convincing for long — it needs 20 minutes.
Credentials, not exploits
The mailbox is the way in
An agent’s inbox already contains every counterparty, every
instruction and the thread history that makes the next message look
routine. Stealing it is a login, not a hack.
Identity density
The file is a complete dossier
Identification documents, Social Security numbers, loan details,
account information, signatures. A transaction file is everything an
identity thief needs, assembled and signed.
Where the money actually leaves
Real-estate fraud is rarely a break-in. It is a change to a document that a
human being then follows correctly.
A · Wire instructions
Changed in transit
An intercepted thread produces a revised instruction sheet, forwarded
from a real participant’s real address. The buyer sees continuity;
the bank sees a valid request.
B · Coordination
Escrow and title by email
Every hand-off between agent, lender, title and escrow is an email. Each
hop is an opportunity to substitute one document, and none of it looks
unusual at the time.
C · Reputation
The loss outlasts the money
Recovering funds is rare. Recovering a client’s confidence, and
the referral it carried, is rarer — and a brokerage’s licence
and insurance position depend on how it responded.
The control that works is dull: an out-of-band confirmation, on a number you
already had, before any instruction change is acted on. We build that into
the workflow rather than leaving it as advice.
What we do for brokerages and teams
Mail authentication
SPF, DKIM and DMARC configured and enforced so your own domain cannot be
impersonated to your clients, your agents or your escrow partners.
Account takeover defence
Session-theft resistant authentication and alerting on mailbox rule
changes — the two signals that fire before a wire fraud attempt
does.
Closing-day procedure
A written verification step for instruction changes, with the callback
rule and the escalation path your team can actually follow under
deadline pressure.
Breach readiness
A tested plan for the first 72 hours: what is preserved, who is notified,
how the transaction is protected while the investigation runs.
Find out where your transactions are exposed
A brokerage security review starts with a conversation, not a contract. We will
show you how a closing thread could be redirected before it happens.