Real estate is the perfect wire-fraud environment: large one-time transfers, deadline pressure, many parties on shared email threads, and buyers doing the biggest wire of their lives for the first time. Nobody in the chain has a routine to break, because for the buyer there is no routine at all.
How the attack works
A compromised mailbox — agent, title company, or buyer — lets the attacker watch the transaction approach closing. Days before closing, "updated wire instructions" arrive from a legitimate-looking address, often followed by a confirming phone call, increasingly with a spoofed number or cloned voice (see what is vishing). The buyer wires to the fraudster's account. Discovery comes at the closing table.
Who is liable
Liability is contested and fact-specific; courts have variously examined which party was compromised, whether warnings were given, and whether verification steps were reasonable. Buyers often bear the immediate loss; agents and title companies face negligence claims when their systems were the entry point. This is general information, not legal advice — liability turns on the specific facts and jurisdiction.
The protocol that prevents it
- Wire instructions are exchanged once, early, through a verified channel.
- Any change is treated as fraud until proven otherwise.
- The buyer verifies instructions by calling the title company on a number from an independent source — their website or original documents, never from the email or the caller.
- Title companies adopt enforced callback verification on their own outbound-instruction process; the callback protocol template is a starting point.