Skip to content

Real Estate Wire Fraud

Real estate wire fraud is the diversion of a property closing payment by an impostor using compromised email. The FBI classifies it as business email compromise rather than as real estate fraud, and the compromised mailbox can belong to any professional in the transaction rather than to the buyer.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The scheme substitutes fraudulent wiring instructions for the real ones, sent from or made to look like a compromised email account, which may belong to an agent, a lender, or the title or escrow company rather than to the buyer.
  • The FBI counts it as business email compromise. IC3's separate "Real Estate Fraud" category means investment, rental and timeshare losses, so figures published under that heading are not the cost of this.
  • The timing is the mechanism. Funds are due on the morning of closing, the amount is large and expected, and there is no slack in the schedule to verify anything.
  • The single countermeasure that works is verifying instructions on a phone number you already had, never one supplied in the same message as the instructions.
  • Recovery depends on hours rather than days. The FBI's stated guidance is to contact your financial institution immediately and request a recall, then file at ic3.gov.

Definition

Real estate wire fraud is the diversion of money owed at a property closing to an account controlled by an impostor, achieved by substituting fraudulent wiring instructions for the genuine ones. The buyer, or occasionally the seller, sends the funds themselves, believing the instructions came from the party they have been dealing with for weeks.

It is worth being precise about how the FBI classifies it, because the published numbers are easy to misread. The Internet Crime Complaint Center defines its "Real Estate Fraud" crime type as "loss of funds from a real estate investment or fraud involving rental or timeshare property", which is a different thing entirely. Closing wire fraud is counted as business email compromise, and the FBI's own tally of its recovery cases uses the label "BEC (BEC/Real Estate)" as a subtype of BEC. In the 2025 IC3 Annual Report, business email compromise was the second costliest crime type reported, at $3,046,598,558 across all its variants, behind only investment fraud. Any figure quoted from IC3's "Real Estate" line is measuring something else.

Advanced Explanation

The compromised mailbox need not be the buyer's, and that is what defeats the usual advice. A residential closing involves a real estate agent on each side, a lender, a settlement or escrow agent, a title company and often an attorney. Any one of those accounts is a viable entry point, and a professional's mailbox is more valuable than a consumer's because it contains many transactions with their dates and amounts. Once inside, the intruder reads until the closing date and the cash to close are known, then sends instructions that are correct in every detail except the account number. Advice built around the buyer's own password hygiene misses this entirely: the buyer's account can be perfectly secure while the scheme runs through somebody else's.

The timing structure is the mechanism, not an aggravating circumstance. Four features of a closing combine into an unusually exposed moment. The payment is large and its size is already known to everyone involved, so a six-figure transfer raises no suspicion. It is due on a specific morning, so the request is expected rather than a surprise. Wiring instructions legitimately do arrive by email late in the process, so a message containing them is normal. And the schedule has no slack: a buyer who pauses to verify risks the closing, the rate lock and, in some contracts, the deposit. A scheme that needs the target to act quickly without checking does not have to manufacture urgency here, because the transaction supplies it.

The one intervention that reliably works, and why it has to be phrased carefully. Confirm the instructions by telephone using a number obtained independently, from an earlier document, a signed agreement or the firm's published listing, and never a number contained in the same message as the instructions. A compromised account can reply to a "please confirm" email in the sender's own voice and can answer a number it supplied. The verification has to leave the channel that may already be compromised. That countermeasure is stated in the same terms on the wire transfer page, which is where the commercial-law reasons behind it belong.

Why the money is hard to get back, in one sentence with a pointer. A domestic wire is governed by state commercial law adopted from Article 4A of the Uniform Commercial Code, under which an order the customer authorized is the customer's order, and a cancellation is not effective once the beneficiary's bank has accepted it. A buyer who was deceived into sending the money has still sent it. The full machinery, including the refund rule that applies when a transfer is never completed, is on the wire transfer page.

What recovery actually looks like, described the way the FBI describes it. The Internet Crime Complaint Center runs a Recovery Asset Team, established in 2018, which operates a process it calls the Financial Fraud Kill Chain. The report's own description is that the team "streamlines communications with financial institutions and FBI field offices to assist in the freezing of funds for victims of fraudulent domestic and international transactions", that the domestic process can extend "beyond the initial recipient bank ... on 'second hop' transactions", and that the international process coordinates with the Financial Crimes Enforcement Network's rapid response team and with legal attachés abroad. In 2025 the team acted on 3,900 incidents involving $1,163,919,846 of attempted theft and froze $679,013,183, a success rate the report states as 58 percent.

The report also publishes a case that shows the shape. In March 2025 a Missouri victim, a senior citizen, "was attempting to close on a property and received a compromised email from the 'title company' containing wire instructions for over $1.3 million to a fraudulent bank account." The team froze the recipient account and found that wires from other victims had arrived in the same account. The following month an Oregon city government reported a separate loss of over $6 million to what turned out to be that same account, and because the earlier freeze was on record the receiving bank alerted the originating bank, which recalled the $6 million wire.

Two things follow that a reader can act on. First, the kill chain works often enough to be worth invoking, and it depends on the transaction details reaching the receiving bank while the funds are still there, which is a matter of hours. Second, the published figures carry no dollar threshold and no stated time window, so anyone quoting a minimum loss size or a fixed number of hours is adding something the FBI has not published. Report regardless of the amount and report immediately.

How to Remember

The email will be right about everything except the account number, and it will probably come from someone you have been corresponding with for weeks. Verify the numbers by voice, on a number you already had, before every closing wire.

Used in a Sentence

“The wiring instructions arrived from the escrow officer's real address the night before settlement, correct in every detail except the account number, which is what real estate wire fraud looks like.”

How It Works

An intruder gains access to the email account of someone in the transaction, typically through a credential-harvesting message, and monitors it. Near the closing date, using the correct names, the correct property and the correct amount, the intruder sends wiring instructions naming an account they control, either from the compromised account itself or from a lookalike address. The buyer wires the funds. The impostor moves the money onward, frequently through a second account, sometimes belonging to another victim who has been recruited unwittingly. The loss surfaces when the settlement agent asks where the money is.

A hypothetical example of why the timing leaves no room. Devrim's cash to close is $86,400: a $71,000 down payment plus $15,400 in settlement charges ($71,000 plus $15,400). Settlement is at 10 a.m. on a Friday and the funds must be received before then. At 7 p.m. on Thursday an email arrives from the address he has used throughout, referencing the property by address, stating the correct $86,400, and giving wiring instructions with a note that the firm has changed banks.

Every detail he can check from his own records is right, and the one detail that is wrong is the only one he has nothing to compare against. His bank opens at 9 a.m., which leaves an hour. Calling the number in the email reaches whoever sent it. Calling the number on the engagement letter he signed in the spring, which is the only step that leaves the compromised channel, takes two minutes and is the entire defense.

Had he sent it, the sequence is: tell his own bank immediately and ask, in those words, for a recall; tell the settlement agent and the lender; and file at ic3.gov with the full transaction details, including the amount, the date, the receiving bank and the account number, which is what the Recovery Asset Team needs in order to ask the receiving bank for a freeze.

Pros and Cons

This is a crime rather than a product, so what follows is what reduces exposure and what the protections do not reach.

What genuinely reduces exposure

  • Verifying wiring instructions by voice on a number obtained independently, before every transfer, including one that merely repeats instructions you already had.
  • Treating any late change of bank details as the single highest-risk event in the transaction, because a legitimate change is rare and a fraudulent one is common.
  • Agreeing the verification step with the settlement agent at the start of the transaction, so pausing on the morning of closing is expected rather than awkward.
  • Reporting within hours rather than days if it happens, since the freeze mechanism depends on the funds still being in the receiving account.
  • Filing at ic3.gov with the full transaction details regardless of the amount, since the published process states no minimum.

What the protections do not reach

  • A domestic wire the buyer authorized is the buyer's order under state commercial law, and deception about who was being paid does not change that.
  • Once the beneficiary's bank has accepted the order, a cancellation depends on that bank's agreement rather than on any right.
  • The compromise may sit in a professional's email account rather than the buyer's, in which case the buyer's own security practices cannot prevent it.
  • The Recovery Asset Team froze 58 percent of the attempted theft it acted on in 2025, which means a substantial share was not recovered even where the process ran.
  • Whether any insurance responds to a diverted closing payment is a question about the specific policy and the specific facts, and is not something to plan around.

People Also Asked

Answers to the most frequently asked questions.

Whose email account gets compromised?
It need not be the buyer's. Any account in the transaction is an entry point: a real estate agent, a lender, or the title or escrow company. A professional's mailbox is more useful to an intruder because it holds many transactions with their closing dates and amounts, which is what allows the fraudulent instruction to be correct in every detail except the account number. This is why advice focused on the buyer's own passwords misses the point, and why verification by voice is the step that matters.
Is real estate wire fraud the same as the FBI's "real estate fraud" category?
No, and conflating them produces the wrong numbers. IC3 defines its Real Estate Fraud crime type as loss of funds from a real estate investment or fraud involving rental or timeshare property. Closing wire fraud is classified as business email compromise, and the FBI's own recovery tallies label it "BEC (BEC/Real Estate)". In the 2025 IC3 Annual Report, business email compromise across all its variants was the second costliest reported crime type at just over $3 billion.
Can the money be recovered?
Sometimes, and speed decides it. The FBI's Internet Crime Complaint Center runs a Recovery Asset Team that asks receiving banks to freeze funds, and in 2025 it froze $679,013,183 of $1,163,919,846 in attempted theft across 3,900 incidents, a 58 percent success rate. The report's own guidance is that if you discover a fraudulent transfer, time is of the essence: contact your financial institution immediately and request a recall, then file at ic3.gov with the full transaction details. No minimum loss size and no fixed time window is published, so report whatever the amount and do it at once.
How do I verify wiring instructions safely?
Call a number you obtained independently: from the engagement letter or purchase agreement you signed, from the firm's published listing, or from a document that predates the current exchange of messages. Never use a number contained in the same message as the instructions, and do not rely on an email reply confirming them, because a compromised account can answer both. Read the account number back digit by digit. Doing this before every transfer, including one that only restates instructions you already have, is what closes the gap.
Is a late change of bank details ever legitimate?
It can be, which is exactly why the tactic works. The right response is not to assume the change is fraudulent but to verify it out of band, by voice, on an independently obtained number, before sending anything. Treat a late change as the highest-risk moment in the transaction and confirm it with the settlement agent directly rather than by replying to the message that announced it.

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor