Real estate closings combine a large sum of money, a firm deadline, several email threads and parties who rarely know one another. Criminals understand this, which is why wire fraud against title and closing practices remains a focus of FBI warnings about business email compromise. The typical scheme is simple: an attacker inserts a message with new wiring instructions at the moment a buyer or seller is ready to send funds.
This playbook is written for closing attorneys and the staff who support them. It covers prevention, the call-back procedure and what to do within minutes if something goes wrong.
How the scam typically works
Most attacks follow a pattern.
- A criminal gains access to an email account belonging to someone in the transaction, such as an agent, lender, title contact or the firm itself, or creates a lookalike domain.
- They monitor conversations until a payment is near.
- They send a message, often in the existing thread, with a polished explanation for changed instructions.
- The money moves to an account the criminal controls and is withdrawn or transferred quickly.
The email may look perfectly normal because it can come from a genuine, compromised account. That is why the defense cannot be "look carefully at the email."
Controls that matter
Verify by phone, every time
Any instruction to send money, or any change to instructions, is confirmed by a phone call to a number obtained independently, such as one in your own file from the start of the matter, not one in the email itself. Speak to a person who knows the transaction. Document who you spoke with, the number, the date and the time.
Give clients the same guidance in writing
At intake, tell buyers and sellers that your firm will never change wire instructions by email, and that they should call you before sending funds. Include the warning in engagement letters and closing instructions, and repeat it in closing emails. Provide a trusted number.
Use secure channels for sensitive details
Prefer a client portal or encrypted message for sharing account information, not plain email. Reduce the number of places where wiring details live.
Separate duties
Require two people for outgoing wires: one who prepares and one who approves, with the approver independently confirming the details. Set dollar thresholds that trigger an extra check, and never allow a single person to alter saved beneficiary information alone.
Lock down email
- Enforce MFA on every account.
- Monitor for forwarding rules and unusual sign-ins.
- Filter for lookalike domains and external sender warnings.
- Publish SPF, DKIM and DMARC records for your domain so criminals cannot easily spoof it.
Train for the pressure moments
Fraud works by exploiting urgency. Teach staff that urgent requests for changes are a reason to slow down, and that nobody will be disciplined for taking time to verify. Run short drills with fake change requests so people practice the call-back.
If you suspect a fraudulent wire
Time is critical. The FBI's IC3 guidance recommends contacting your financial institution immediately and asking it to initiate a recall, and filing a report with IC3. Prepare a one-page plan in advance.
- Call your bank's fraud or wire department at once, and request a recall or hold.
- Provide transaction details: amount, date, beneficiary account and the receiving bank.
- Contact the FBI through the IC3 website, and your local FBI field office where appropriate.
- Notify your cyber insurance carrier and your attorney, and review the policy's reporting requirements.
- Secure the compromised accounts and preserve evidence.
- Communicate with affected clients promptly and honestly. Rule 1.4 addresses keeping clients reasonably informed, and ABA Formal Opinion 483 discusses obligations after a data breach. Check state requirements.
Speed improves the chance of recovery, but there is no guarantee.
Trust accounting considerations
Many state bars have rules about client trust accounts, so ask your bar or ethics counsel how a loss from a fraudulent disbursement should be handled. Do not assume that a bank will cover it.
A short checklist
- Phone verification documented for every wire.
- Client warning in writing at intake and closing.
- Dual approval and thresholds.
- MFA and monitoring on every mailbox.
- Written recall plan with phone numbers.
How we can help
Counsel Cyber works with law firms on email security, DMARC, monitoring and staff training that supports a call-back culture. If you want your closing process reviewed before the next big closing, contact us.