Succession Holding LLC

Independent real estate education for small-portfolio investors

Succession Weekly Brief

The Wire Fraud Epidemic Is Getting Worse: A 10-Point Protocol for Independent Operators Before Every Closing

The number that should stop every independent real estate operator in their tracks is this: $275.1 million. That is what the FBI Internet Crime Complaint Center recorded in real estate fraud losses in 2025, up from $173 million in 2024 and $145 million in 2023. The trend line is not flattening. The crime is getting more sophisticated, more targeted, and more profitable for the people running it.

The 2026 CertifID State of Wire Fraud Report — drawing on 1.4 million real estate transactions, recovery case data, and national consumer and title professional surveys — adds texture to the FBI number. One in five homeowners received a fraud-related message connected to their transaction before closing. One in four recent buyers reported receiving a suspicious message during the transaction itself. Business Email Compromise attempts across real estate are up 1,760 percent year-over-year, a spike CertifID attributes directly to AI tooling that lets criminals craft convincing emails, texts, and even voice messages at scale and at low cost.

Independent operators are not exempt from this. The assumption that wire fraud only hits luxury transactions or buyers working with large national title companies is precisely the assumption that makes independent operators vulnerable. The criminals know that smaller transactions often involve less sophisticated parties, smaller title agencies with fewer security protocols, and operators who are handling their own closings for the first time in a while. The protocol for preventing wire fraud is not complicated. It is specific, and it has to be applied consistently. Here is the 10-point framework.

Why the Attack Surface Is Wider Than Most Operators Realize

The standard attack is well-known: a criminal intercepts email communication between buyer, seller, agent, and title company, then sends revised wire instructions from an address that looks almost identical to the title company's real address. The wire goes out. By the time the buyer realizes the instructions were fake, the money is gone and the recovery odds — CertifID's data puts recovery at roughly 69 percent when the theft is reported within 24 hours — still leave a substantial share of stolen funds unrecovered.

What is less well understood is how comprehensive the reconnaissance has become. The criminals know the names of the parties, the property address, the transaction amount, the closing date, and the name of the title company. They acquired this information not by hacking a title company database but by monitoring public records, scraping listing data, and occasionally by compromising an agent's email account. The attack does not start at closing. It starts when the property goes under contract.

The AI escalation is the newest layer. CertifID's 2026 report documents how criminals are using large language models to generate convincing correspondence, mimic writing styles from compromised email threads, and craft spear-phishing messages that do not have the grammar artifacts that used to flag a fake. A spoofed email from your title company — sent from an address like "title-company-support@domain.com" instead of the real "closing@titlecompany.com" — now reads like something the title company would actually write.

The 10-Point Wire Fraud Prevention Protocol

1. Verify all communication channels before the transaction begins. Before wiring any funds, establish a verified callback protocol with your title company using a phone number you looked up independently — not one provided in an email. Call the title company directly at the beginning of the transaction to confirm the contact person, the closing schedule, and the wire instructions process. Do not use any phone number provided in an email.

2. Treat every email with new wire instructions as presumptively fraudulent. If you receive revised wire instructions by email — even if they appear to come from your title company, attorney, or agent — do not act on them. Pick up the phone and call the sender at a verified number. Use a different communication channel than the one that delivered the instructions. If the email says "call me at this number," do not call that number. Call the number you have on file from your own independent verification.

3. Implement a dual-verification rule for any wire over $10,000. Any wire transfer above $10,000 requires two independent confirmations: one via a phone call to a verified number at the title company, and one via a secondary confirmation from your bank that the receiving account name matches the title company's name on record. Most banks now have a fraud warning process for large wire transfers — use it, even if it feels like a hassle at the closing table.

4. Establish a wire instruction baseline at the start of the transaction. Get the wire instructions in writing on the first day of the transaction. Photograph or save the written instructions. Any subsequent communication that proposes different instructions — a different routing number, a different account name, a different bank — is a fraud indicator. The only legitimate reason for revised wire instructions is if the closing is postponed and the title company legitimately moves the closing account. Even then, the verification protocol applies.

5. Monitor your email account security. A significant share of wire fraud originates from compromised agent or buyer email accounts rather than title company systems. Enable two-factor authentication on every email account involved in a real estate transaction. If you are working with an agent whose email has been compromised — and you may not know this happened — the fraudster has your transaction data. Do not use email as the sole communication channel for anything related to wire transfers.

6. Run the callback confirmation at the 24-hour and 4-hour marks before closing. The fraud attempt typically comes 24 to 48 hours before closing, when the buyer is most focused and least likely to scrutinize a last-minute change. Establish a standing callback rule: you will call the title company at both the 24-hour and 4-hour marks before closing to verify the wire instructions have not changed. Put this in your calendar as a standing task.

7. Confirm with your bank the wire will reach a known institution, not a stranger account. When you initiate the wire at your bank, ask the banker to read back the full account name and routing number. The receiving bank name should be recognizable as the title company's bank. If the wire is going to an account at a bank you have never heard of, stop the transfer and investigate. Criminals sometimes use routing numbers that pass surface-level checks but route to accounts at small or online-only banks.

8. Get written confirmation from the title company after funds are wired. The day you wire funds, send a confirmation email and make a phone call to the title company to confirm receipt. CertifID's recovery data shows that funds recovery within 24 hours of a fraudulent wire substantially improves recovery odds. The title company should confirm receipt within the same business day. If you cannot get confirmation, escalate immediately.

9. Do not access closing documents from links in emails. Access the closing documents through the title company's established document portal, not through a link in an email. If you receive an email with a link to "your closing package," do not click the link. Navigate directly to the title company's website and access their portal from there. Compromised email accounts often send document links that route to convincing but fake login pages.

10. Document everything and tell every party in the transaction about the protocol. The protocol only works if everyone in the transaction knows it exists. Tell your agent, your attorney, and the title company at the beginning of the transaction that you follow a strict wire verification protocol and that you will be calling to confirm all wire instructions. The criminals's job is harder when the buyer has already established a verification habit with the title company.

Buyer Concern Is the Warning Sign

CertifID's survey found that a majority of buyers say they are worried about wire fraud. The share who delayed sending funds due to fraud concerns is actually a healthy sign — it means the awareness campaign is working and buyers are taking the risk seriously. The 1,760 percent spike in BEC attempts is the counterweight: criminals are responding to greater awareness with more sophisticated attacks, not fewer of them.

The independent operator who treats wire fraud as something that happens to other people — larger transactions, more sophisticated buyers, bigger markets — is precisely the operator the criminals are looking for. The protocol above is not expensive. It does not require specialized software or a security consultant. It requires a phone call and a calendar reminder.

Wire the funds. Then call the title company to confirm receipt. It is that simple and that important.

SOURCES: CertifID 2026 State of Wire Fraud Report (certifid.com/whitepaper/2026-state-of-wire-fraud-report); FBI Internet Crime Complaint Center (IC3) 2025 real estate fraud data; FBI IC3 2024 annual report ($173M); Alliance Title blog (alliancetitle.com, March 2026); Home Fraud Defense / CertifID consumer survey data ($275.1M, 1-in-5 homeowners, 1-in-4 buyers).

All Weekly Briefs · How we work