.png)
Arpitha Gadag
4
Wire Fraud
Jul 30, 2026
Aug 7, 2026
Business email compromise (BEC) in real estate cost victims $446 million in 2022, the last year the FBI's Internet Crime Complaint Center published a real estate breakout. Total BEC losses across all sectors hit $3 billion in 2025. Hold real estate's share constant and that's roughly $500 million today. Attackers sit inside a compromised inbox, study the closing timeline, then send new wire instructions right before funds move. The key takeaway: awareness training and callback verification catch some attempts, but both depend on one person making the right call under deadline pressure. Identity and account verification built into the closing workflow removes that dependency.
BEC has become the leading way criminals steal closing funds. Today's attackers skip the obvious phishing scams and the malware. Instead, they watch a live closing, learn how the parties communicate, and wait. When money is about to move, they strike with instructions that look exactly right.
That patience is what makes BEC so hard to catch. Careful staff is not enough on its own. Instead, stopping it requires stronger, purpose-built identity verification at the point funds are released.
This guide walks through how BEC attacks unfold, why real estate keeps getting targeted, and the specific steps that stop a diversion before it happens.
CertifID was built in 2017 after our founder lost $180,000 to a business email compromise attack. In 2025 alone, CertifID verified over 1.46 million transfers, prevented $283 million in direct financial loss, and blocked 1,018 fraudulent transactions. Our State of Wire Fraud report is cited by HousingWire, NAR, and ALTA.

Business email compromise is a sophisticated cyber scam where criminals take over or spoof a legitimate business email account to redirect funds. The goal is simple: move money into an account they control. BEC attacks target both businesses and consumers.
In real estate, BEC almost always targets closing funds: buyer cash-to-close, seller net proceeds, or mortgage payoffs. The FBI IC3 has ranked BEC among the costliest categories of cybercrime it has tracked for years running.
Unlike generic phishing, BEC rarely needs malware or a suspicious link. Often, the attacker just needs a login. From there, they read your mail, learn your habits, and wait for the right moment to strike.
With that risk in mind, here's how a closing creates the opening.
Real estate closings are built for this kind of attack. A typical residential purchase runs 42 to 45 days from contract to close. That creates a long window for cybercriminals to sit inside an inbox undetected.
Most attacks start with a phishing email or a reused password.
A closer clicks a fake link or logs in with a password already exposed in another breach. Either way, the attacker now has valid credentials.
Attackers rarely act right away. Instead, they set up forwarding rules that copy every incoming email to an account they control.
A former U.S. Secret Service e-crimes investigator, now leading fraud investigations at Yahoo, says these rules can be built in under a minute. Attackers often pair them with auto-delete filters, so the account holder sees nothing unusual.
They also tend to swap out recovery phone numbers and email addresses for their own. That locks the real owner out of a fast recovery once the compromise is found.
While inside the account, attackers study the closing details. They get intel about the homebuyer, seller, lender, and title company. They learn the closing date, the dollar amount, and even the tone each party uses in email.
In one case cited by Secret Service investigators, attackers tracked a victim's in-person board meeting schedule closely enough to convince her bank to release an $800,000 wire transfer a full week before she was expected there in person. They knew her calendar better than her own colleagues did.
Near closing, the attacker sends new wiring instructions from a spoofed or hijacked account, almost always with an urgent tone. They use expressions such as:
That pressure is deliberate. It gives the recipient less time to question what they're looking at.
In short, BEC involves social engineering and/or computer intrusion to enable the illegitimate transfer of diverted funds.
A few conditions make title agencies, law firms, and lenders especially attractive to BEC criminals:
These conditions enable fraudsters to build convincing, well-timed scams with minimal effort. Closings also depend on several parties coordinating quickly by email, so incoming messages tend to get taken at face value.
Every additional party in a closing is another entry point. Buyers, sellers, agents, lenders, attorneys, and title staff all exchange sensitive info over email. Each one is an account a fraudster can spoof to earn credibility with the rest of the group.
These attacks aren't hypothetical. Federal investigators have documented cases that show exactly how much damage BEC can do.
A homebuyer in Illinois lost $350,000 after fraudsters took over a real estate account and set up a fake title company email. The fraudulent account pointed to a different bank than the one the seller used. Investigators later traced the scheme to more than 50 linked accounts, clustered mostly in Illinois and Florida.
An attorney in New Jersey sent legitimate wiring instructions to a client. Three hours later, the client's bank received a follow-up from an address nearly identical to the attorney's. The latest communication asked them to disregard the first message and follow the new instructions instead. That single email redirected $277,000. Investigators later linked the account to a ring operating out of South Africa, connected to roughly 190 other targeted accounts.
Both cases follow the same approach. A compromised or spoofed account, a well-timed follow-up, and a request just urgent enough to skip a second call.
You can see more of these cases play out in our To Catch A Fraudster series, and read how the same pattern shows up in seller impersonation fraud.

No single control stops BEC attacks by itself. Effective prevention combines people, processes, and technology, so that one mistake doesn't turn into a six-figure loss.
Written policies only work if your team follows them under pressure. Fraudsters rely on urgency to short-circuit good judgment. Make it normal for closers to pause and verify. No one should feel rushed into skipping a check.
Watch for last-minute changes to wiring instructions, unusual urgency, or a slightly altered email address. Your company's BEC attacks staff awareness training needs to be ongoing because the tactics change constantly.
Manual phone callbacks have long been the industry standard, and they're easy to defeat. Fraudsters spoof the caller ID or leave a fake number in the same fraudulent email. Callbacks help. They shouldn't be your only defense. Our wire fraud prevention guide covers 22 additional funds-diversion protection practices to build into your closing workflow.
Have your team periodically review mail settings for forwarding rules they didn't create, unfamiliar filters, or recovery contacts they don't recognize. Catching one of these early can stop an attack before funds move.
A Secret Service-trained investigator estimates that enabling multi-factor authentication (MFA) across email accounts stops roughly 90% of account takeovers. It takes minutes to set up and is one of the highest-impact defenses available. See our guide on why a password alone is a security risk.
Reused passwords remain one of the most common entry points for BEC. A password manager makes unique, complex passwords practical across every account. We compare a few solid options in our password manager guide for real estate professionals.
Manual processes don't scale, and they weren't built to catch plausible-looking AI-assisted deepfake fraud. A purpose-built verification platform closes the weaknesses left by callbacks, encrypted PDFs, and internal checklists.
As BEC attacks become more sophisticated each day, investing in email security and payoff fraud prevention platforms is now a must for businesses.

Stopping BEC takes more than one tool. While CertifID doesn't stop a fraudster from trying to phish for your information via a business email compromise attack, it can stop the fraudster from moving through the deal if they get into your email and try to use fraudulent instructions to redirect funds.
CertifID combines verification, insurance, and recovery into one connected platform built for real estate closings. Every party and step of the closing is protected.
CertifID confirms both identity and bank account details before a dollar moves, replacing the manual callback that a spoofed number can easily defeat. Verification is built into the workflow, including SoftPro, ResWare, and RamQuest, so closers don't lose time switching tools. No separate portal. No extra login. No second place to verify.
Payoff fraud accounts for the largest share of losses reported to our recovery team. PayoffProtect automates verification of payoff statements and lender bank accounts before disbursement. No other platform offers an equivalent, insured payoff verification product. Our guide on how to detect mortgage payoff fraud walks through the specific red flags.
Every verified wire and payoff carries up to $5M in direct insurance, underwritten by an A-rated carrier. That's an actual policy, not a marketing guarantee with caps and exclusions. Competing guarantees often leave firms exposed exactly when protection matters most.
If fraud happens, CertifID's Fraud Recovery Services team works directly with federal law enforcement. That partnership has helped recover more than $130M for victims to date. Most firms hit by fraud don't know who to call in the first 24 hours. CertifID does.
CertifID’s one connected platform helps you build secure, BEC-resilient systems to keep your precious funds safe.
Speed changes outcomes. If you suspect a fraudulent wire or payoff instruction, act immediately:
Victims who catch the fraud quickly recover funds far more often than those who wait even a day. Our full wire transfer fraud recovery guide breaks down the first-hour steps in more detail. If you already work with CertifID, contact Fraud Recovery Services right away.
BEC thrives on trust, patience, and long closing timelines. Fraudsters study the closing before ever sending a fake wire.
The best defense combines trained staff, strong account hygiene, and verification technology that doesn't rely on a phone call. CertifID builds tight payoff fraud protection systems into the closing experience. Plus, it’s backed by a real $5M insurance cover and a recovery team that knows exactly what to do next if funds are stolen.
Ready to protect your next closing? Talk to the CertifID team today.
BEC is a scheme in which criminals take over or spoof a trusted party's email during a closing to redirect wire transfers. It can target buyer funds, seller proceeds, or mortgage payoffs. Real estate is exposed because closings involve large sums and parties who communicate almost entirely by email.
Very common. Business email compromise (BEC) in real estate is a fraud scheme in which an attacker gains access to an email account tied to a closing and uses it to redirect funds. The attacker monitors the thread, learns the closing date, then sends new wire instructions right before funds move, from an address the homebuyer, agent, or closing team already trusts. The FBI attributed $446.1 million in losses to real estate BEC in 2022, across 2,284 reported incidents.
Most often through phishing emails or reused passwords. A single compromised password can unlock an account with no additional security in place. Once inside, attackers can set up forwarding rules within minutes, letting them read incoming messages without the account owner noticing anything unusual.
Watch for urgent, last-minute changes to wiring instructions. If a message pushes you to act faster than usual, slow down and verify. Email addresses that look slightly altered, unfamiliar forwarding rules, and requests to skip a callback are also red flags.
Most standard cyber and E&O policies exclude or sub-limit social engineering losses, including BEC. That leaves many firms and consumers unprotected when a wire is misdirected. CertifID covers that risk with direct, underwritten insurance up to $5M per verified wire and per verified payoff.
Director of Fraud & Risk Products
Arpitha is a seasoned product leader with nearly a decade of experience in fraud prevention and digital identity verification. She has a proven track record of scaling products from 0 to 1 across startups and Fortune 500 companies alike. Driven by a deep commitment to access and equity, Arpitha is passionate about building inclusive digital identity experiences that empower individuals to engage confidently with the products they love, while stopping fraudsters in their tracks.
Business email compromise (BEC) in real estate cost victims $446 million in 2022, the last year the FBI's Internet Crime Complaint Center published a real estate breakout. Total BEC losses across all sectors hit $3 billion in 2025. Hold real estate's share constant and that's roughly $500 million today. Attackers sit inside a compromised inbox, study the closing timeline, then send new wire instructions right before funds move. The key takeaway: awareness training and callback verification catch some attempts, but both depend on one person making the right call under deadline pressure. Identity and account verification built into the closing workflow removes that dependency.
BEC has become the leading way criminals steal closing funds. Today's attackers skip the obvious phishing scams and the malware. Instead, they watch a live closing, learn how the parties communicate, and wait. When money is about to move, they strike with instructions that look exactly right.
That patience is what makes BEC so hard to catch. Careful staff is not enough on its own. Instead, stopping it requires stronger, purpose-built identity verification at the point funds are released.
This guide walks through how BEC attacks unfold, why real estate keeps getting targeted, and the specific steps that stop a diversion before it happens.
CertifID was built in 2017 after our founder lost $180,000 to a business email compromise attack. In 2025 alone, CertifID verified over 1.46 million transfers, prevented $283 million in direct financial loss, and blocked 1,018 fraudulent transactions. Our State of Wire Fraud report is cited by HousingWire, NAR, and ALTA.

Business email compromise is a sophisticated cyber scam where criminals take over or spoof a legitimate business email account to redirect funds. The goal is simple: move money into an account they control. BEC attacks target both businesses and consumers.
In real estate, BEC almost always targets closing funds: buyer cash-to-close, seller net proceeds, or mortgage payoffs. The FBI IC3 has ranked BEC among the costliest categories of cybercrime it has tracked for years running.
Unlike generic phishing, BEC rarely needs malware or a suspicious link. Often, the attacker just needs a login. From there, they read your mail, learn your habits, and wait for the right moment to strike.
With that risk in mind, here's how a closing creates the opening.
Real estate closings are built for this kind of attack. A typical residential purchase runs 42 to 45 days from contract to close. That creates a long window for cybercriminals to sit inside an inbox undetected.
Most attacks start with a phishing email or a reused password.
A closer clicks a fake link or logs in with a password already exposed in another breach. Either way, the attacker now has valid credentials.
Attackers rarely act right away. Instead, they set up forwarding rules that copy every incoming email to an account they control.
A former U.S. Secret Service e-crimes investigator, now leading fraud investigations at Yahoo, says these rules can be built in under a minute. Attackers often pair them with auto-delete filters, so the account holder sees nothing unusual.
They also tend to swap out recovery phone numbers and email addresses for their own. That locks the real owner out of a fast recovery once the compromise is found.
While inside the account, attackers study the closing details. They get intel about the homebuyer, seller, lender, and title company. They learn the closing date, the dollar amount, and even the tone each party uses in email.
In one case cited by Secret Service investigators, attackers tracked a victim's in-person board meeting schedule closely enough to convince her bank to release an $800,000 wire transfer a full week before she was expected there in person. They knew her calendar better than her own colleagues did.
Near closing, the attacker sends new wiring instructions from a spoofed or hijacked account, almost always with an urgent tone. They use expressions such as:
That pressure is deliberate. It gives the recipient less time to question what they're looking at.
In short, BEC involves social engineering and/or computer intrusion to enable the illegitimate transfer of diverted funds.
A few conditions make title agencies, law firms, and lenders especially attractive to BEC criminals:
These conditions enable fraudsters to build convincing, well-timed scams with minimal effort. Closings also depend on several parties coordinating quickly by email, so incoming messages tend to get taken at face value.
Every additional party in a closing is another entry point. Buyers, sellers, agents, lenders, attorneys, and title staff all exchange sensitive info over email. Each one is an account a fraudster can spoof to earn credibility with the rest of the group.
These attacks aren't hypothetical. Federal investigators have documented cases that show exactly how much damage BEC can do.
A homebuyer in Illinois lost $350,000 after fraudsters took over a real estate account and set up a fake title company email. The fraudulent account pointed to a different bank than the one the seller used. Investigators later traced the scheme to more than 50 linked accounts, clustered mostly in Illinois and Florida.
An attorney in New Jersey sent legitimate wiring instructions to a client. Three hours later, the client's bank received a follow-up from an address nearly identical to the attorney's. The latest communication asked them to disregard the first message and follow the new instructions instead. That single email redirected $277,000. Investigators later linked the account to a ring operating out of South Africa, connected to roughly 190 other targeted accounts.
Both cases follow the same approach. A compromised or spoofed account, a well-timed follow-up, and a request just urgent enough to skip a second call.
You can see more of these cases play out in our To Catch A Fraudster series, and read how the same pattern shows up in seller impersonation fraud.

No single control stops BEC attacks by itself. Effective prevention combines people, processes, and technology, so that one mistake doesn't turn into a six-figure loss.
Written policies only work if your team follows them under pressure. Fraudsters rely on urgency to short-circuit good judgment. Make it normal for closers to pause and verify. No one should feel rushed into skipping a check.
Watch for last-minute changes to wiring instructions, unusual urgency, or a slightly altered email address. Your company's BEC attacks staff awareness training needs to be ongoing because the tactics change constantly.
Manual phone callbacks have long been the industry standard, and they're easy to defeat. Fraudsters spoof the caller ID or leave a fake number in the same fraudulent email. Callbacks help. They shouldn't be your only defense. Our wire fraud prevention guide covers 22 additional funds-diversion protection practices to build into your closing workflow.
Have your team periodically review mail settings for forwarding rules they didn't create, unfamiliar filters, or recovery contacts they don't recognize. Catching one of these early can stop an attack before funds move.
A Secret Service-trained investigator estimates that enabling multi-factor authentication (MFA) across email accounts stops roughly 90% of account takeovers. It takes minutes to set up and is one of the highest-impact defenses available. See our guide on why a password alone is a security risk.
Reused passwords remain one of the most common entry points for BEC. A password manager makes unique, complex passwords practical across every account. We compare a few solid options in our password manager guide for real estate professionals.
Manual processes don't scale, and they weren't built to catch plausible-looking AI-assisted deepfake fraud. A purpose-built verification platform closes the weaknesses left by callbacks, encrypted PDFs, and internal checklists.
As BEC attacks become more sophisticated each day, investing in email security and payoff fraud prevention platforms is now a must for businesses.

Stopping BEC takes more than one tool. While CertifID doesn't stop a fraudster from trying to phish for your information via a business email compromise attack, it can stop the fraudster from moving through the deal if they get into your email and try to use fraudulent instructions to redirect funds.
CertifID combines verification, insurance, and recovery into one connected platform built for real estate closings. Every party and step of the closing is protected.
CertifID confirms both identity and bank account details before a dollar moves, replacing the manual callback that a spoofed number can easily defeat. Verification is built into the workflow, including SoftPro, ResWare, and RamQuest, so closers don't lose time switching tools. No separate portal. No extra login. No second place to verify.
Payoff fraud accounts for the largest share of losses reported to our recovery team. PayoffProtect automates verification of payoff statements and lender bank accounts before disbursement. No other platform offers an equivalent, insured payoff verification product. Our guide on how to detect mortgage payoff fraud walks through the specific red flags.
Every verified wire and payoff carries up to $5M in direct insurance, underwritten by an A-rated carrier. That's an actual policy, not a marketing guarantee with caps and exclusions. Competing guarantees often leave firms exposed exactly when protection matters most.
If fraud happens, CertifID's Fraud Recovery Services team works directly with federal law enforcement. That partnership has helped recover more than $130M for victims to date. Most firms hit by fraud don't know who to call in the first 24 hours. CertifID does.
CertifID’s one connected platform helps you build secure, BEC-resilient systems to keep your precious funds safe.
Speed changes outcomes. If you suspect a fraudulent wire or payoff instruction, act immediately:
Victims who catch the fraud quickly recover funds far more often than those who wait even a day. Our full wire transfer fraud recovery guide breaks down the first-hour steps in more detail. If you already work with CertifID, contact Fraud Recovery Services right away.
BEC thrives on trust, patience, and long closing timelines. Fraudsters study the closing before ever sending a fake wire.
The best defense combines trained staff, strong account hygiene, and verification technology that doesn't rely on a phone call. CertifID builds tight payoff fraud protection systems into the closing experience. Plus, it’s backed by a real $5M insurance cover and a recovery team that knows exactly what to do next if funds are stolen.
Ready to protect your next closing? Talk to the CertifID team today.
Director of Fraud & Risk Products
Arpitha is a seasoned product leader with nearly a decade of experience in fraud prevention and digital identity verification. She has a proven track record of scaling products from 0 to 1 across startups and Fortune 500 companies alike. Driven by a deep commitment to access and equity, Arpitha is passionate about building inclusive digital identity experiences that empower individuals to engage confidently with the products they love, while stopping fraudsters in their tracks.