Intentionally desktop-first — best experienced on a workstation
Portfolio
Threat Analysis · BEC · Real Estate Wire Fraud

The Closing Table —
Real Estate Wire Fraud and the BEC Attack That Targets the Most Trusted Email in a Transaction

Author
Yana Ivanov
Published
July 2026
Classification
Public — Educational
Attack Type
BEC · Wire Fraud · Impersonation
Sector
Real Estate · Title · Legal · Financial
Severity
Critical — $275M in 2025 Losses
$275.1M in real estate wire fraud losses in 2025  ·  12,368 FBI IC3 complaints  ·  58% recovery rate — 42% gone permanently
Section 01

Executive Summary

Real estate wire fraud is one of the most financially damaging and emotionally devastating cybercrimes in the United States — not because it is technically sophisticated, but because it exploits the single most trusted moment in a real estate transaction: the closing wire. The FBI's 2025 IC3 Annual Report documented 12,368 complaints and $275.1 million in losses from real estate wire fraud — a 59% increase from $173 million in 2024 and a 90% increase from $145 million in 2023. Even with the FBI's Recovery Asset Team successfully freezing funds in some cases, the recovery rate is approximately 58%. The remaining 42% is gone permanently.

The attack is a variant of Business Email Compromise (BEC) in which the attacker impersonates a trusted party to the transaction — a title company, a closing attorney, a real estate agent, or a lender — and sends fraudulent wire instructions at the exact moment the buyer is expecting them. The email arrives at the right time, references the correct transaction details, and creates urgency around a deadline the buyer already knows is real. Nothing about it feels wrong. Because the money moves via wire transfer, which is designed to be final and irreversible, recovery is the exception rather than the rule.

Current email security detection for this specific attack vector is a gap. Existing BEC rules target generic patterns — new sender domains, invoice language, executive impersonation — but none specifically address the real estate closing wire scenario, where the timing of the email, the impersonated parties, and the specific language around "closing," "escrow," and "wire instructions" are the detection signals.

$275M
2025 Losses
FBI IC3 2025 Annual Report. Up from $173M in 2024 and $145M in 2023.
12,368
FBI Complaints
Reported real estate wire fraud incidents in 2025. Actual losses estimated significantly higher.
42%
Unrecovered
Of attempted wire fraud intercepts, 42% of funds are permanently lost even with FBI intervention.
90%
3-Year Increase
Cumulative rise in real estate wire fraud losses from 2023 to 2025. Category growing faster than BEC overall.
Section 02

Why Real Estate Transactions Are the Perfect BEC Target

A real estate closing involves a predictable sequence of high-value wire transfers between parties who have often never interacted before, operating under strict deadlines, using email as the primary communication channel. The buyer expects to receive wire instructions from their title company, closing attorney, or escrow agent in the days before closing. The wire amount is large — often the single largest financial transaction of a person's life. The timeline is fixed and non-negotiable. The urgency is built into the legitimate transaction.

Attackers exploit every one of these structural conditions. They monitor compromised email accounts belonging to title companies, real estate attorneys, mortgage brokers, or buyers' agents — waiting for the right moment. When a transaction approaches closing, they send fraudulent wire instructions that appear to come from the expected party, at the expected time, referencing the correct transaction details. The buyer wires the funds. By the time the fraud is discovered — often at the closing table when the real parties ask where the money is — the funds have already moved through multiple accounts and are effectively gone.

IC3 documented case, August 2025: A couple closing on a home received an email impersonating their legitimate attorneys with modified wire instructions. They wired over $449,000 to the fraudulent account. The FBI's Recovery Asset Team initiated the Financial Fraud Kill Chain immediately upon receiving the IC3 complaint — but recovery was not guaranteed. This is not an edge case. The FBI's RAT handles hundreds of these incidents annually.

The FBI has specifically designated Real Estate Wire Fraud (REWF) as a sub-category of BEC due to its prevalence and financial impact. Victims include buyers, sellers, title companies, law firms, real estate agents, and lenders — every party to a transaction is a potential target. The attack does not require technical sophistication. It requires access to one party's email, knowledge of the transaction timeline, and a wire instruction email sent at the right moment.

check_circle Legitimate Closing Wire Email

Sender: titleco@firstamericantitle.com — known domain, established relationship, DMARC passing

Timing: Sent 3-5 days before closing date as expected

Content: Wire instructions to the title company's escrow account, correct bank name, routing and account numbers the buyer has verified previously

Tone: Professional, references specific property address and closing date, no unusual urgency

warning Fraudulent Closing Wire Email

Sender: titleco@firstamericantitle-closings.com — lookalike domain registered days earlier, DMARC not established

Timing: Sent just before closing — urgency framing around same-day or next-day wire deadline

Content: "Updated" wire instructions with different bank, routing, and account numbers. References same property address and closing date. Asks buyer to disregard previous instructions.

Tone: Adds urgency — "funds must be received by 2pm to proceed with closing" — mirroring real transaction pressure

Attack model based on FBI IC3 2025 Annual Report documented cases and FBI Congressional Report on BEC and Real Estate Wire Fraud.

Section 03

The Attack Chain — How Real Estate Wire Fraud Executes

Figure 1 — Real Estate Wire Fraud Attack Chain
01
Reconnaissance — Finding the Target Transaction
The attacker monitors compromised email accounts at title companies, real estate law firms, mortgage lenders, or buyers' agents — looking for active transactions approaching closing. Public records, MLS listings, and social media provide additional intelligence about upcoming closings. AI tools now enable attackers to monitor and reconnoitre many small organizations simultaneously and cheaply, making the attack viable against targets of any size — not just large commercial transactions. A couple buying their first home is as viable a target as a corporate real estate acquisition.
02
Domain Registration — The Lookalike Infrastructure
The attacker registers a lookalike domain — firstamericantitle-closings.com, stewart-title-closing.net, escrow-closingteam.com — typically days or weeks before the attack. The domain is configured with basic email infrastructure. DMARC may or may not be set up; many attackers skip it to save time, relying on the visual similarity of the display name and domain to fool recipients who are not scrutinizing the exact sender address. The time pressure of a closing — "funds must be received today" — reduces the likelihood the buyer will pause to verify the address character by character.
03
Delivery — The Wire Instruction Email
The attacker sends a professional, well-formatted email from the lookalike domain — or from a compromised legitimate account — with "updated" wire instructions. The email references the correct property address, closing date, and buyer and seller names (all available from the compromised inbox or public records). The wire instructions themselves look normal — bank name, routing number, account number — but the account belongs to a money mule controlled by the attacker. The email arrives when the buyer expects closing communications and contains exactly what they are looking for.
04
Execution — The Wire Transfer
The buyer or their bank initiates the wire transfer to the fraudulent account. Wire transfers are designed to be fast and final — the funds move within hours. The fraudulent account is typically a "funnel account" controlled by a domestic money mule, which immediately re-wires the funds through additional accounts — sometimes internationally — making recovery exponentially harder with every transfer. By the time the fraud is discovered at the closing table when the title company confirms they have not received funds, the money has often already left the first fraudulent account.
05
Laundering — The Recovery Window Closes
The FBI's Recovery Asset Team operates a Financial Fraud Kill Chain (FFKC) that can freeze fraudulent accounts if notified quickly enough. In the August 2025 case documented in the IC3 Annual Report, the RAT was able to initiate a freeze — but the same fraudulent account was later used in a $6 million fraud against an Oregon city government, demonstrating that even partially disrupted fraud infrastructure continues operating. The 42% of funds that are not recovered represent cases where the laundering chain moved faster than the recovery process.
Attack model based on FBI IC3 2025 Annual Report, FBI Congressional Report on BEC and Real Estate Wire Fraud, and documented case studies from Stewart Title and other industry sources. MITRE ATT&CK: T1566.002 (Spearphishing Link), T1586.002 (Compromise Email Accounts), T1036 (Masquerading), T1657 (Financial Theft).
Section 04

Key Findings

1
No Dedicated Detection Rule Exists for Real Estate Closing Wire Fraud
A review of major open-source email security rulesets reveals no rule specifically targeting the real estate closing wire fraud pattern — the combination of closing-related language, wire instruction content, impersonation of title companies or closing attorneys, and urgency framing around a closing date. Existing BEC rules target generic patterns: new sender domains, invoice language, executive impersonation. None address the specific lexicon and timing signals of a real estate closing wire. A lookalike domain impersonating a title company, sending updated wire instructions referencing a closing date and property address, passes every existing detection rule that does not specifically look for these signals.
CRITICAL
2
The Attack Is Accelerating Faster Than BEC Overall
Real estate wire fraud losses grew 90% from 2023 to 2025 — compared to approximately 24% growth in overall BEC losses over the same period. The category is outpacing the broader BEC trend by a factor of nearly four. AI is a likely contributor: the democratization of BEC described by Cisco Talos in April 2026 applies directly to real estate fraud, where AI tools now enable attackers to identify approaching closings, craft personalized wire instruction emails matching the specific transaction details, and target any size transaction — not just large commercial deals. A couple's home purchase is as viable a target as a $50 million commercial acquisition.
CRITICAL
3
The Detection Window Is the Email — Before the Wire
Once the wire transfer is initiated, recovery depends on the speed of FBI FFKC notification and the willingness of recipient banks to freeze accounts — a process that succeeds only about 58% of the time even with rapid response. The only reliable intervention point is before the wire is sent — which means detecting the fraudulent email before the buyer acts on it. Email security platforms operating at the delivery layer have a clean shot at the signals that distinguish a fraudulent closing wire email from a legitimate one: lookalike domain, recently registered sender, wire instruction language, closing urgency framing, and title company or attorney impersonation cues.
HIGH
4
The Reply-To Mismatch Is a Consistent Signal
In many real estate wire fraud cases, the attacker sets the Reply-To header to a different address than the From header — allowing them to conduct the fraudulent conversation from a separate account while the display name shows a legitimate entity. This is a detectable signal: a message appearing to come from a title company or closing attorney, where replies would go to a different domain, is anomalous. Combined with wire instruction language and closing-related urgency, this mismatch is a high-confidence fraud indicator that is underutilized in existing detection logic.
HIGH
5
The Victim Pool Is Expanding Downmarket
Real estate wire fraud historically concentrated on commercial transactions where large wire amounts justified the attacker's time investment. AI-assisted BEC has changed this economics — smaller residential transactions are now equally viable targets. A $300,000 home purchase wire is worth the same to an attacker as a $300,000 commercial closing if the effort to target both is identical. This expansion means the victim population now includes first-time homebuyers, retirees downsizing, and any individual involved in a residential real estate transaction — not just corporate treasury departments and commercial real estate professionals.
MEDIUM
Section 05

Recommendations

Defense against real estate wire fraud operates at two levels: individual transaction hygiene and email-layer detection. Both are necessary. Neither is sufficient alone.

1
No email instruction to wire funds should be acted on without a phone verification call to a number obtained independently — not from the email itself. This is the single most effective defense against real estate wire fraud and the one that failed in nearly every documented case. Call your title company or closing attorney using the number from their official website or a business card obtained in person. If they say they sent the email, the wire instructions are legitimate. If they did not, you have just prevented the fraud. This verification step should be standard practice for every real estate transaction regardless of how legitimate the email appears.
2
Email clients display the sender's name prominently and often hide the full email address behind it. "First American Title" as a display name tells you nothing about where the email actually came from. Click on the sender name to reveal the full email address, and examine the domain character by character. A hyphen, a different TLD, or an extra word in the domain — firstamericantitle-closings.com vs firstam.com — is a fraud signal. On mobile where the full address is often hidden, be especially cautious about wire instructions and always verify by phone before acting.
3
Legitimate title companies rarely change wire instructions mid-transaction. An email asking you to disregard previously provided wire details and use new account information is one of the highest-risk signals in a real estate transaction. Even if the email appears to come from the correct sender, even if it references the correct property and closing date, any change to wire instructions should trigger an immediate phone verification call. The FBI specifically notes that attackers time these emails to create urgency — "funds must be received by 3pm today" — to prevent the buyer from pausing to verify.
4
Email security platforms operating at the delivery layer can detect the pattern before the buyer ever sees the email. The combination of signals — wire instruction language, closing-related urgency, title company or attorney impersonation, recently registered sender domain, and reply-to mismatch — is detectable and specific enough to produce high-confidence alerts with low false positive rates against legitimate closing communications. A companion detection rule targeting this pattern is in development and will be submitted to Sublime Security's open-source rule feed.
5
Time is the critical factor in wire fraud recovery. File a complaint at ic3.gov immediately upon discovering the fraud. Contact your bank's wire transfer department simultaneously and request a recall. The FBI's Recovery Asset Team can initiate the Financial Fraud Kill Chain to freeze fraudulent accounts — but every hour reduces the probability of recovery as funds move through additional accounts. In the documented August 2025 case, rapid FFKC initiation successfully froze $1.3 million. Speed of reporting is the primary determinant of whether the 58% recovery rate applies to your case.

Detection Signals Summary

SignalIndicatorConfidenceNotes
Sender domain agenetwork.whois().days_old < 30HighNew domains impersonating established title companies
Reply-to mismatchreply_to domain ≠ sender domainHighAttacker routes replies to separate fraudulent account
Wire instruction languagerouting number + account number patternMedium-HighRegex pattern for bank routing/account number strings
Closing urgency language"closing," "wire by," "funds due"MediumCombined with other signals — alone too broad
Title company impersonationDisplay name ≠ sender domainHighKnown title company names in display name from unknown domain
Updated instructions framing"updated wire," "new account," "disregard previous"HighExtremely specific to fraud — rarely in legitimate closing email
BEC NLU intentml.nlu_classifier intent == "bec"MediumSupports other signals — not sufficient alone
Section 06

The Gap Between What Exists and What Is Needed

Real estate wire fraud is not a new attack. It has been documented by the FBI since at least 2015, and the FBI has run a dedicated congressional reporting category for it since 2022. The losses have grown every year. The attack pattern is well understood. And yet a dedicated email security detection rule for the specific signals of a closing wire fraud email does not exist in any major open-source ruleset.

This is not because the problem is technically hard to detect. The signals are specific and identifiable: a recently registered domain impersonating a title company, wire instruction language with routing and account numbers, urgency framing around a closing date, and a reply-to mismatch routing the conversation to a separate fraudulent account. These signals are not present in normal business email. They are present in real estate wire fraud emails. The combination is detectable at the email layer before any wire transfer occurs.

The 90% growth in losses over three years suggests the attack is scaling faster than awareness and detection are keeping up. AI has made the targeting cheaper and the personalization more convincing — the Cisco Talos "democratisation" observation applies directly here. An attacker no longer needs to spend hours researching a target. They need access to one email account, enough public information to reference the correct transaction, and a lookalike domain registered the week before.

The email is still the only reliable intervention point. Once the wire is sent, the recovery window is measured in hours and closes quickly. The detection rule that catches this before delivery is straightforward to write. The analysis that explains why it matters is this one.

This analysis is based on publicly available information including the FBI IC3 2025 Annual Report, the FBI Congressional Report on Business Email Compromise and Real Estate Wire Fraud, Cisco Talos Threat Source newsletter (April 2026), and industry documentation from Stewart Title and First American. A companion Sublime Security detection rule targeting real estate closing wire fraud email patterns is in development and will be submitted to the open-source rule feed when complete. This analysis represents independent research produced as a contribution to the security community.

YI
Yana Ivanov
Security Analyst  ·  Threat Intelligence  ·  Detection Engineering

I'm a security researcher in Connecticut. Analysis is the part I love: tracing threat actor behavior, pulling apart supply chain attacks, and following evidence even when it lands on "unknown." When a question needs a tool that doesn't exist, I build it; most of the tools on this site started that way. Before security I spent 15 years designing enterprise software, which is why my tools assume a human will actually have to use them. I contribute detection rules to Sublime Security's open-source production ruleset. Security+ in progress. Everything here is independent work, shared as a contribution to the security community.

Portfolio