Manav.id
Vertical · 5 min read

Why closing wires remain the easiest large theft in America

Why closing wires remain the easiest large theft in America

The attacker does not need to break anything. They read a mailbox for three weeks, learn the closing date, and send wiring instructions that look exactly like the ones the buyer was expecting — because they are a copy of them, with one field changed.

Why are closing wires so easy to divert?

Five properties combine: one large irreversible transfer, a date everyone knows, parties who have never met, no baseline for what is normal, and email as the coordination medium. The attacker does not break anything — they copy the real instructions and change one field.

Key takeaways
  • The transaction's structure creates the exposure: a large irreversible transfer, a known date, unfamiliar counterparties, and email as the coordination medium.
  • Portals and callbacks help and are routed around, because the attacker can contact the buyer directly and redirect them.
  • The missing artefact is proof of what the buyer was shown when they initiated the wire — which neither party currently has.

Why this transaction and not others

A mailbox in the transaction is compromisedagent, buyer or a small firmWeeks of quiet readingnames, tone, timeline, amountLookalike instructions sentone field changedBuyer calls the number in the emailreaches the attackerWire leavesdiscovered at closing
After the mailbox is compromised, every remaining step is the normal process working.

Five properties combine, and each one alone would be manageable.

PropertyConsequence
Large single transferOne successful attack is worth six figures
Irreversible railRecovery depends on speed and the receiving bank's cooperation
Known dateThe attacker knows exactly when to send the instructions
Unfamiliar partiesThe buyer has no baseline for what is normal from a title agent
Email coordinationUnauthenticated, spoofable, and the attacker may be reading it

The fourth row is underrated. A buyer completes one or two closings in a lifetime and has no basis for recognising an unusual request. Everything is unfamiliar, so nothing seems unusual.

The attack, in its usual form

  1. Access is obtained to a mailbox in the transaction — often the agent's or the buyer's, sometimes a smaller firm's with weaker controls.
  2. The attacker reads quietly for weeks, learning names, tone, timeline and amounts.
  3. Near the closing date, instructions are sent that copy the genuine ones with the account details changed.
  4. If the buyer calls to verify, they call the number in the fraudulent email.
  5. The wire leaves. By the time the discrepancy surfaces at closing, the funds have moved on.

There is no technical exploit in this sequence after step one. The remaining steps are the normal process working as designed.

Why the current defences are routed around

DefenceHow it is defeated
Encrypted portal for instructionsAttacker phones the buyer and directs them elsewhere
Callback verificationBuyer calls the number in the fraudulent message
Email warning bannerPresent on every message, including the genuine ones; ignored
Payee bank account verificationVerifies the account the title agency used, not what the buyer saw
Two-person review at the agencyReviews the agency's outgoing instructions, not the buyer's incoming ones

The pattern: every control operates on the agency's side of the transaction. The buyer, who initiates the wire, is outside all of them.

The artefact nobody has

After a diversion, the question is what the buyer was shown. The agency says they published correct instructions; the buyer says they received different ones. Both are telling the truth.

There is no record of what the buyer actually saw at the moment they instructed their bank. That record is what would resolve the dispute, and it is also what would prevent it.

# What the buyer signs, on their own device, before wiring

  Wire instructions — closing 2026-09-18

  Property:     1420 Fillmore Street
  File:         ESC-2026-4471
  Send to:      First National Trust
  Routing:      021000021
  Account:      ****8823
  Beneficiary:  Cascade Title & Escrow LLC
  Amount:       $389,142.00

  Issued by Cascade Title & Escrow, countersigned 2026-09-16.

  [Touch ID] I have read these instructions and am sending
             this amount to this account.

→ receipt held by buyer, agency and lender; verifiable offline

The buyer's bank can be shown this before releasing the wire. A buyer presenting instructions with no valid receipt is, at minimum, a reason to pause.

What changes for each party

The honest limits

A buyer determined to follow instructions from a convincing caller can ignore the signed statement entirely and wire anyway. Nothing prevents someone from acting outside the process.

What changes is that the process has a canonical artefact. "Do not send funds without a valid receipt from the closing file" is a rule a buyer can follow, unlike "be alert for fraudulent instructions", which asks them to do something they are not equipped to do.

It also changes the position after a loss. An agency that issued a verifiable statement, and can show what the buyer signed, is in a very different posture from one holding a copy of an email with a red banner on it.

Why every existing control is on the wrong side

Each control protects the agency's channel
ControlHow it is routed around
Encrypted portalAttacker phones the buyer and directs them elsewhere
Callback verificationBuyer calls the number in the fraudulent message
Email warning bannerOn every message, including the copies; ignored
Payee account verificationVerifies what the agency used, not what the buyer saw
Two-person review at the agencyReviews outgoing instructions, not incoming ones

The buyer initiates the wire and sits outside all of them. That is the structural gap, and it is why the missing artefact is a record of what the buyer was shown at the moment they instructed their bank.

Objections and honest limits

“A determined buyer can still be talked into wiring anyway.” True. What changes is that the process has a canonical artefact. ‘No valid receipt, no wire’ is a rule a first-time buyer can follow; ‘be alert for fraudulent instructions’ is not.

“This is the buyer's responsibility.” Courts increasingly examine what the professional did, not what the consumer failed to spot. An agency that offered an un-spoofable channel is in a materially different position from one holding an email footer.

Closing the buyer-side gap

  1. Issue instructions as a countersigned statement. Not as an email attachment.
  2. Have the buyer sign on their own device before wiring. Rendered from the signature, not the message.
  3. Give the buyer one rule. No valid receipt, no wire — whatever anyone says on the phone.
  4. Put the receipt on the file. For the lender, the underwriter and any later claim.

Terms used here

Payoff diversion
Redirecting closing or payoff funds by substituting wiring instructions.
Business email compromise
Fraud conducted from a genuine compromised mailbox rather than a spoofed one.
Recall
A request to return a wire, whose success depends almost entirely on speed.

Frequently asked questions

Don't secure portals already solve this? They secure the agency's channel. The attacker contacts the buyer directly by phone or email and redirects them away from the portal.

What does callback verification miss? The buyer calls the number in the fraudulent message. Verification is only as good as the channel used to obtain the number.

Can a buyer still be tricked? Yes, if they act outside the process entirely. What changes is that a clear rule exists — no valid receipt, no wire — which is something a buyer can actually follow.

Does this help after a loss? Substantially. The agency can demonstrate what it issued and what the buyer signed, which is a stronger position than a disclaimer in an email footer.

Don't secure portals solve this? They secure the agency's channel. The attacker contacts the buyer directly and redirects them away from it.

Where this fits in Manav

Manav renders the wire or payoff details from a statement the issuer countersigned, has the payer sign on their own device, and puts a verifiable receipt on the file for the agency, the lender and the insurer.

See wire confirmation →

Sources and further reading