Real estate is the perfect wire-fraud environment: large one-time transfers, deadline pressure, many parties on shared email threads, and buyers doing the biggest wire of their lives for the first time. Nobody in the chain has a routine to break, because for the buyer there is no routine at all.

How the attack works

A compromised mailbox — agent, title company, or buyer — lets the attacker watch the transaction approach closing. Days before closing, "updated wire instructions" arrive from a legitimate-looking address, often followed by a confirming phone call, increasingly with a spoofed number or cloned voice (see what is vishing). The buyer wires to the fraudster's account. Discovery comes at the closing table.

Who is liable

Liability is contested and fact-specific; courts have variously examined which party was compromised, whether warnings were given, and whether verification steps were reasonable. Buyers often bear the immediate loss; agents and title companies face negligence claims when their systems were the entry point. This is general information, not legal advice — liability turns on the specific facts and jurisdiction.

The protocol that prevents it

  • Wire instructions are exchanged once, early, through a verified channel.
  • Any change is treated as fraud until proven otherwise.
  • The buyer verifies instructions by calling the title company on a number from an independent source — their website or original documents, never from the email or the caller.
  • Title companies adopt enforced callback verification on their own outbound-instruction process; the callback protocol template is a starting point.
Protocol tipTell every buyer at engagement: "Our wire instructions will never change. If you receive new ones, it is fraud — call us on the number on our website." That one sentence, delivered early, defeats the entire attack.