Case Study 27.1 — Wire Fraud at the Closing Table, and the Warnings Nobody Reads Twice
A real, public, and continuing industry problem — assembled from federal agency alerts and industry association guidance. No borrower in this case study is a real person; the pattern is documented public record.
Background: a crime that found a perfect target
Residential real estate closings have four characteristics that, combined, make them close to an ideal target for financial crime, and every one of them is a feature of how the business works rather than a defect anyone could remove.
- Large, single, non-recurring transfers. A homebuyer sends more money at once than they will ever send again. On the Linden Street file that number is \$25,376.34, against total verified assets of \$38,000.00.
- A hard, publicly known date. Closings are scheduled weeks in advance and discussed openly by agents, title companies, lenders, and buyers. The moment of maximum exposure is on a calendar.
- Many parties, many mailboxes, no shared security perimeter. A single transaction routinely involves a buyer, a seller, two real estate agents and their brokerages, a lender, a title or escrow company, a closing attorney in some states, an insurance agent, and assorted assistants. Each has an email account. The transaction is only as secure as the weakest one, and no party has authority over the others' systems.
- Instructions that legitimately arrive late. Final figures move. Amounts change. Everyone in the transaction is conditioned to expect a message near the end that says "here is what to send and where."
Put those together and the crime writes itself. It has a name — business email compromise — and federal agencies have been warning about its use against real estate closings for years.
The issue: how the scheme actually runs
The pattern described in agency alerts and industry guidance is consistent enough that it is worth learning as a sequence, because knowing the sequence is what lets you interrupt it.
Step one: access. A criminal obtains access to one mailbox in the transaction — most often through credential harvesting, a fake login page that captures a password. Which mailbox varies, and this is the part people get wrong: it is not always the title company. It is frequently a real estate agent, an assistant, or the homebuyer's own personal email account. The compromise is silent. Nothing is stolen. Nothing appears to happen.
Step two: reconnaissance. The criminal reads. For weeks, sometimes longer, they learn the property address, the price, the parties, the closing date, the amount of the buyer's funds, the writing style of the person they intend to imitate, and — most valuable of all — who normally tells whom about money. In some documented variants, mail rules are set up to divert or hide specific messages so the legitimate party never sees the exchange happening in their name.
Step three: the message. Days before closing, a message arrives at the buyer. It contains the correct property address, the correct closing date, the correct approximate amount, a plausible signature block, and one new fact: the wiring instructions have changed. The stated reason is always mundane — a bank change, an account update, a fraud-prevention measure, an accounting department request. Often the message comes from a lookalike domain, a near-copy of a real one differing by a character, which survives a glance and fails a careful reading nobody performs at 9:40 p.m. three days before they get keys.
Step four: the transfer. The buyer wires. The funds land in an account controlled by the criminal or a money mule, and are typically withdrawn, converted, or moved onward very quickly — often within hours, frequently across borders.
Step five: discovery. Discovery happens at the worst possible moment, when the settlement agent says the funds have not arrived. By then, the recoverable window has usually been open for a day or more without anyone using it.
The interagency response — and what is odd about it
What makes this case instructive is not that the government warned about it. It is how many different parts of the government warned about it, separately, to different audiences, with no single regulator owning the problem.
- The FBI, through its Internet Crime Complaint Center (IC3), has issued repeated public service announcements on business email compromise and email account compromise, including guidance specific to the real estate sector. IC3 also operates a Recovery Asset Team, which works with financial institutions to attempt to freeze fraudulently transferred domestic funds — a process that depends heavily on speed of reporting.
- The Financial Crimes Enforcement Network (FinCEN) issued an advisory to financial institutions on email compromise fraud schemes in 2016 and an updated advisory on email compromise fraud schemes targeting vulnerable business processes in 2019, specifically identifying the real estate sector among the targeted processes. Verify current advisory numbers and text at FinCEN's website; advisories are periodically updated and superseded.
- The Consumer Financial Protection Bureau and the Federal Trade Commission issued a joint consumer alert in 2016 warning homebuyers about mortgage closing scams, aimed directly at consumers rather than institutions.
- The American Land Title Association has run sustained wire-fraud awareness efforts for its members and publishes incident-response guidance for title and settlement companies.
- The National Association of REALTORS® has published wire fraud guidance and warnings to its membership.
Notice the structure. The FBI warns law enforcement and the public. FinCEN warns financial institutions. The CFPB and FTC warn consumers. The title industry warns settlement agents. The realtor association warns agents. Nobody regulates the homebuyer's personal email account, and the homebuyer is where the money actually leaves.
That is the whole institutional problem in one sentence, and it is why the effective control is not a rule. It is a person — usually the loan officer or the settlement agent — who says the right sentence to a buyer at the right time.
What it shows
First, that sophistication is not the risk factor. These are not technically remarkable attacks. They are patient ones. The criminal's advantage is entirely contextual: they know things about the transaction that only an insider should know, which is exactly what makes the message persuasive.
Second, that the loss lands on the household. When a business email compromise hits a corporate accounts-payable department, the loss falls on a company with insurance, counsel, and a balance sheet. When it hits a homebuyer, the loss falls on a family that has just liquidated everything it owns. The recovery mechanisms that exist — bank recall requests, IC3's recovery function, civil actions — all work sometimes and none of them work reliably. Agencies consistently describe recovery as far from assured, and describe reporting speed as the single most important variable. Do not quote a recovery rate; there is no stable number and any figure you have heard is probably from a different year and a different measurement.
Third, that the industry's own response tells you where the control belongs. Look at what actually changed in practice: title companies added wire-fraud warnings to every email footer; settlement agents adopted mandatory voice callback verification on any change to disbursement instructions; some lenders now deliver a written wire-fraud warning at application as a standard disclosure; and a growing number of settlement offices refuse to transmit instructions by email at all, using secure portals instead. Those are all process controls at the point of transfer, adopted voluntarily, because no regulation could have reached the weakest mailbox in the chain.
Fourth, that the warning has a shelf life. This is the finding practitioners underrate. A warning delivered at application, six weeks before closing, competes with a Loan Estimate, an initial disclosure package, a home inspection, and a move. It fades. The attack is timed for exactly the moment it has faded. A single warning is a compliance artifact. Two warnings, one of them in the week before closing, is a control.
Outcome
There is no clean resolution to report, and that is itself the finding. The scheme has not been solved. It has been managed, unevenly, by an industry that adopted callback verification and warning language faster than any regulator could have required it — and by individual loan officers and settlement agents who make one phone call that a criminal cannot intercept.
Enforcement happens. Prosecutions for wire fraud, money laundering, and conspiracy in connection with real estate business email compromise are a routine part of the federal docket, and money mule networks are periodically disrupted. But enforcement is downstream of a loss that has usually already become permanent. The intervention that works is the one that happens before the wire.
The lesson
Five sentences, and the last one is the chapter's whole thesis in a different costume.
- The message will look right, because the criminal has been reading your transaction.
- The buyer's own email may be the compromised account, so confirming by email confirms nothing.
- Verification must happen by voice, on a phone number obtained from a source the sender did not choose — the executed contract, a directory you looked up, a number already in your phone.
- Warn at application, in writing, and warn again in the week before closing, because a single warning is not a control.
- Fraud's entire project is to control which channel you use. Refuse, and this crime does not work.
Discussion questions
-
Five different federal and industry bodies warned about this scheme to five different audiences, and the crime continued. What does that tell you about the difference between a warning and a control? Name one control in your own workflow that does not depend on anyone remembering anything.
-
The chapter argues the borrower's own email account is frequently the compromised one. Trace what that does to each of the following "safe" practices: (a) replying to the email to confirm, (b) asking the borrower to forward the instructions to you, (c) confirming by text to the number in the signature block.
-
On the Linden Street file, cash to close is \$25,376.34 against \$38,000.00 in total verified assets. Compute what fraction is lost in a successful attack, then describe what the household's position is the next morning — not emotionally, but concretely: what do they own, what do they owe, and what happens to the \$5,000 earnest money and the \$650 appraisal fee?
-
Settlement agents adopted mandatory callback verification voluntarily, before any rule required it. Why do you think process controls emerged faster from the industry than from regulators here? What does that suggest about where to look for the next fraud control?
-
Write the exact language of your wire-fraud warning for the week before closing — the second one, not the first. It has to survive a tired, distracted, excited borrower. What makes the second warning different in tone and content from the first?
-
A borrower calls you having already sent the wire. You have perhaps two hours of real recovery window. Write your first four instructions, in order, in the words you would actually use — and then say what you deliberately will not spend those two hours discussing.