Case Study 23.2 — The Wire That Went Somewhere Else
Business email compromise at the closing table, and the prevention script that works
This case study is written entirely from the prevention side. It describes what a victim sees and what a professional does about it. It does not describe how a scheme is executed, and Chapter 27 takes mortgage fraud, its criminal exposure, and its detection in full.
Tier 1 where it names agencies and their published programs. No dollar figure or statistic from any agency report is quoted here on purpose — those figures are published annually and change, and a textbook that prints one is wrong within a year. Check the FBI Internet Crime Complaint Center's current annual report and FinCEN's current advisories for figures.
Background: why closings
Real estate closings have four characteristics that, taken together, make them an unusually attractive target for a particular kind of fraud.
- A large, one-time, irreversible payment. On the Linden Street file, \$25,376.34 moves in a single wire. Wires are fast and, once accepted by the receiving bank and moved onward, extremely difficult to recover.
- A known date, known in advance. Everyone in the transaction knows the closing date weeks ahead. So does anyone reading the email traffic.
- A crowd of parties who barely know each other. A buyer, a seller, two agents, a lender, a settlement agent, sometimes an attorney, sometimes a mortgage broker. Most of them have never met. Instructions routinely arrive from people the buyer has never spoken to.
- A first-time buyer who does not know what normal looks like. They have never done this. They have been told all week to expect documents and instructions from unfamiliar companies. They have been told to move quickly. They do not know that "we've updated our wire instructions" is not a normal sentence.
The federal government has tracked the resulting crime category for years. The FBI's Internet Crime Complaint Center (IC3) treats business email compromise (BEC) — sometimes paired with "email account compromise" — as one of the costliest categories of reported cybercrime, and reports on the real estate sector as a persistent target. The Financial Crimes Enforcement Network (FinCEN) has issued advisories on email-compromise fraud schemes, including guidance addressed to the real estate setting, describing the pattern and the red flags financial institutions should watch for. Industry bodies including the American Land Title Association publish wire-fraud prevention resources and incident-response plans for settlement agents, and the Consumer Financial Protection Bureau has published consumer-facing warnings about mortgage closing scams.
Every one of those sources says essentially the same thing, which is the good news in this case study: the pattern is well documented and the prevention is not complicated.
The issue: what a victim actually sees
Stripped to what the buyer experiences, the scheme has one move. Somewhere in the chain of people emailing about this closing, an email account is being read by someone who should not have access to it, or an email address is being imitated closely enough that a hurried reader will not notice. Shortly before closing, the buyer receives a message that appears to come from a party they have been corresponding with — the settlement agent, the escrow officer, their agent, sometimes the loan officer — providing wire instructions.
The message is usually:
- timed to the closing, arriving one to three days before, when instructions are expected
- contextually correct — the right property address, the right closing date, the right amount, sometimes quoting earlier correspondence
- urgent, with a reason to act now and a reason not to call: a bank change, a system migration, an officer traveling, a deadline
- and, in the version that catches professionals, a change to instructions that were previously given correctly
The buyer wires. The money is accepted, then moved. Days later, at the closing table or on the phone, someone asks where the funds are.
The same pattern runs in other directions, and settlement agents and lenders are targets as often as buyers:
- Seller proceeds diversion — instructions purporting to come from the seller, redirecting the seller's net proceeds after closing.
- Payoff diversion — a fraudulent payoff statement sent to the settlement agent, redirecting the payoff of the seller's existing mortgage. This one is dangerous because the seller's old lien does not get released and the problem may not surface for weeks.
- Commission and vendor diversion — smaller amounts, same mechanism.
- Post-closing redirection — the servicing-transfer letter described in §23.10, which targets the borrower's monthly payment rather than the closing wire.
A composite
[COMPOSITE — constructed from documented patterns in public agency advisories and reported industry cases. This is not a specific case, and no real transaction, company, or person is depicted.]
A first-time buyer couple is closing on a Friday. Two days earlier — Wednesday afternoon — they receive an email that appears to come from the settlement company's escrow officer, whose name they recognize from a prior message. It references the property address correctly, states the correct amount, \$25,376.34, and explains that the company has changed banks and that the previously provided wiring instructions should be disregarded. It closes by noting that the escrow officer will be out of the office Thursday and asks the buyers to confirm by email once sent.
They wire Thursday morning.
Friday at 1:40 p.m., the settlement agent calls the loan officer to say the buyers' funds have not arrived. The buyers produce their bank's confirmation. The account number on the confirmation does not match the settlement company's account.
What happens next is a race measured in hours, not days:
| Time | Action |
|---|---|
| Immediately | The buyers call their own bank — the originating bank — report the fraud, and request a wire recall |
| Immediately | The settlement agent and the loan officer notify the receiving bank if it can be identified |
| Same day | A complaint is filed with the FBI's Internet Crime Complaint Center at ic3.gov, and the local FBI field office is contacted |
| Same day | Law enforcement's recovery process — the IC3 Recovery Asset Team, working with receiving institutions — may be able to freeze funds that have not yet moved onward |
| Same day | Every party's email is treated as potentially compromised; passwords changed, multi-factor authentication enforced, forwarding rules examined by IT |
| That week | The closing does not happen. The contract's deadlines do not care why. |
Recovery is possible and it is not the way to bet. The variable that matters most is elapsed time, and the difference between reporting in three hours and reporting in three days is enormous. Who ultimately bears the loss is litigated case by case, turns on facts and on state law, and produces inconsistent outcomes. The only sound planning assumption is that the money is gone.
Notice what the composite does not include: no negligence by any professional in the transaction is required for it to happen. The instructions looked real because they were built from real correspondence. That is the entire design.
What it shows
The vulnerability is a process, not a person. Every party in the transaction had a correct email address, a real relationship, and a legitimate reason to send instructions. The failure is that the process permitted instructions about money to be accepted over an unauthenticated channel. Email is an unauthenticated channel. It always was.
"They changed the instructions" is the signature. Legitimate settlement agents change bank accounts rarely and criminals need to change them every time. Any communication that alters payment instructions — new account, new bank, new address, new payee — is the single highest-value red flag in the transaction, and it is the one a hurried buyer is least equipped to notice.
The borrower's protection has to be installed before the attack. A warning delivered after the suspicious email arrives is too late, because by then the borrower is comparing your warning against a message that looks exactly like everything else they have received all week. The warning has to be installed at application and repeated before closing, so that it is already in their head when the email lands.
And it connects forward. §23.10's servicing-transfer scam is the same crime with a smaller check and a longer runway. Chapter 27 places both inside the broader landscape of mortgage fraud and the criminal exposure attached to it, and Chapter 26 covers the information-security obligations — including under the Gramm-Leach-Bliley Act — that sit on your side of the desk.
Prevention: what a loan officer actually does
The script, delivered twice. Once at application, once two days before closing:
"Nobody in this transaction will ever email you new wire instructions. If you get an email that changes where money goes — from me, from the title company, from your agent, from anyone — it is fraud until you prove otherwise, and you prove otherwise by hanging up and calling a number you already had. Not the number in the email. A number from a statement, a business card, or a website you looked up yourself. Call me too. I would rather take fifty unnecessary calls than one of these."
The verified callback. Before wiring, the borrower calls the settlement agent at a number obtained independently and reads the instructions back — account number and routing number, digit by digit — and confirms the amount. This step is the whole defense and it takes four minutes.
Confirm receipt. After sending, the borrower calls again to confirm the funds arrived. This is what compresses discovery time from days to hours, and elapsed time is the variable that determines whether recovery is possible.
On your own side of the desk. Multi-factor authentication on every email account. Never send account numbers by email; use your company's secure portal. Never accept a change of instructions by email from anyone, including a colleague. Watch for lookalike domains in reply-to addresses. And follow your employer's incident-response process, which exists — find it before you need it.
One habit worth adopting. Put the warning in writing, in the same email in which you first discuss closing costs, and put it above the numbers rather than below them. Borrowers read the top of an email.
Discussion questions
-
The composite required no negligence by any professional in the transaction. Does that change how you think about who should bear the loss? Argue both sides, then say what a loan officer should do given that the answer is unsettled.
-
This chapter's §23.10 asks you to warn borrowers at closing that a servicing transfer letter is likely. Case Study 23.1 shows that servicing transfers are legitimate, routine, and heavily regulated. Explain how to give a warning that prepares a borrower for the real letter without priming them to accept a fraudulent one. What exact sentence does the work?
-
Rank these four controls by how much risk each removes per minute of effort: (a) a verified callback before wiring, (b) multi-factor authentication on the loan officer's email, (c) a written warning at application, (d) confirming receipt after the wire is sent. Defend your ranking.
-
A borrower tells you they would rather bring a cashier's check than wire. What are the trade-offs, and what do you need to confirm before agreeing?
-
Your borrower forwards you a suspicious email at 4:55 p.m. the day before closing and asks whether it is real. Write what you do in the next ten minutes, in order.
-
The chapter argues that this crime works because a first-time buyer "does not know what normal looks like." Identify two other places in the origination process where the same vulnerability exists, and say what a loan officer can install in advance to close each one.