The FBI's Internet Crime Complaint Center reported $688 million in losses from real estate wire fraud in 2025 — up from $446 million the year prior. The number climbs every year. The scam works because it exploits a moment every real estate transaction has: the wire transfer of closing funds. The attacker doesn't need to be sophisticated. They need one compromised email account and a buyer who doesn't pick up the phone before sending $400,000 to an account that isn't the title company's.
This guide explains exactly how wire fraud happens, which warning signs indicate an active attack, and what businesses and buyers can do today to prevent it.
How Real Estate Wire Fraud Actually Works
Real estate wire fraud is a specific variant of business email compromise (BEC). The attack follows a predictable sequence:
- Compromise: The attacker gains access to an email account involved in the transaction — the buyer's agent, the seller's agent, the title company, or the closing attorney. This usually happens through phishing, credential stuffing, or purchasing credentials on the dark web. The attacker doesn't announce themselves. They watch.
- Monitor: The attacker reads email threads for weeks or months, learning the transaction timeline, the parties involved, and the expected closing date. They identify when wire instructions will be sent.
- Intercept: Just before closing, the attacker sends an email that appears to come from the title company. The email contains updated wiring instructions with the attacker's bank account substituted for the real one. The email may reference the actual address, loan amount, or other transaction-specific details gleaned from the monitored inbox — making it highly convincing.
- Collection: The buyer, believing the email is legitimate, wires closing funds to the attacker's account. Money is moved to foreign accounts within hours. By the time anyone realizes what happened, recovery is nearly impossible.
The scam works because wiring instructions do legitimately change. Last-minute changes happen in real transactions — escrow accounts, bank mergers, office banking changes. Buyers have no reliable way to distinguish legitimate updates from fraudulent ones based on email alone.
Why It's Getting Worse
Several factors make wire fraud easier to execute today than five years ago:
- AI-generated phishing: Attackers now use LLMs to write phishing emails indistinguishable in tone and grammar from legitimate correspondence. The "spelling mistake" tell that once flagged fraud emails is gone.
- Email is inherently insecure: Email authentication (DMARC, DKIM, SPF) protects against spoofing a domain — but not against a legitimately compromised account. An attacker operating from inside a breached inbox bypasses all email authentication checks.
- Transaction volume: High-volume periods (spring and fall real estate seasons) create pressure to move fast. Buyers rushing to close are more likely to act on wiring instructions without calling to verify.
- Remote transactions: As more closings happen remotely — buyers in different cities, agents working from home — the "call the title company directly" verification step is less natural than it would be in an in-person setting.
The 8 Warning Signs of an Active Wire Fraud Attack
These patterns indicate a transaction may be under active attack. Any single one warrants an immediate phone call to verify:
- Wiring instructions arrive via email rather than a secure document portal
- Instructions reference a different bank than previous correspondence
- The email requests urgency: "Wire must be received by 3pm today or closing will be delayed"
- The sender's email address is slightly different from previous messages (title-company.com vs titlecompany.co)
- Instructions arrive on a Friday afternoon or the day before a holiday
- The email contains small but unusual formatting differences from previous correspondence
- No phone call accompanies the wiring instruction email
- The instruction email comes from a personal Gmail or Outlook address, not a company domain
The Prevention Protocol Every Closing Should Follow
Wire fraud is almost entirely preventable with consistent process. The protocol is simple:
1. Establish Wire Instructions Early — Before Closing Week
Set wire instructions at the start of the transaction, not in the final days. Get the title company's bank account information during the initial escrow setup. Tell all parties that wiring instructions will not change. If they do change, a phone call to a known, pre-established number is required for verification.
2. Never Act on Email-Only Wire Instruction Changes
This is the single most effective fraud prevention step. Every change to wiring instructions, no matter how legitimate-seeming the email, must be verified by phone. Call the number you have on file — not the number in the email. If the email claims the previous number is out of service, treat that as a fraud signal.
3. Transmit Wiring Instructions Through Secure Channels Only
Wire instructions should never travel through unencrypted email. Use a secure document portal that requires recipient authentication before delivering instructions. When the buyer receives wiring instructions through a secure, authenticated link — rather than an email attachment — the attack surface for interception shrinks dramatically.
4. Monitor Transactions for Anomalies
Automated monitoring can catch changes that manual review misses. Systems that compare current wiring instructions against a verified baseline and alert on discrepancies give transaction coordinators a second line of defense against in-flight attacks.
5. Educate Buyers at the First Meeting
Most buyers have never heard of wire fraud. Real estate professionals who explain the risk upfront — "Before you wire any money, call us directly at this number to confirm the instructions" — dramatically increase the chance that buyers will pause and verify before acting.
How Zignature's Wire Fraud Shield Works
Zignature's Wire Fraud Shield is an AI-powered monitoring layer built into the real estate transaction workflow. It continuously scans transaction documents and communications for patterns associated with wiring instruction substitution — bank account changes, routing number discrepancies, and communication patterns consistent with BEC attacks. When the system detects a potential substitution, it sends an immediate alert to the transaction coordinator, the buyer's agent, and the title company before funds move.
Wire instructions distributed through Zignature are delivered via authenticated document links — not email attachments. Recipients must authenticate before accessing the document, creating a verification layer that email cannot provide. Every access is logged with timestamp, IP address, and device fingerprint — giving transaction coordinators a clear record of who accessed wiring instructions and when.
For real estate professionals handling multiple closings per month, the Wire Fraud Shield runs continuously in the background. No manual review is required.
Learn how Wire Fraud Shield works or explore Transaction Rooms — the full real estate workflow built around wire fraud prevention.