Why closing wires remain the easiest large theft in America
The attacker does not need to break anything. They read a mailbox for three weeks, learn the closing date, and send wiring instructions that look exactly like the ones the buyer was expecting — because they are a copy of them, with one field changed.
Why are closing wires so easy to divert?
Five properties combine: one large irreversible transfer, a date everyone knows, parties who have never met, no baseline for what is normal, and email as the coordination medium. The attacker does not break anything — they copy the real instructions and change one field.
- The transaction's structure creates the exposure: a large irreversible transfer, a known date, unfamiliar counterparties, and email as the coordination medium.
- Portals and callbacks help and are routed around, because the attacker can contact the buyer directly and redirect them.
- The missing artefact is proof of what the buyer was shown when they initiated the wire — which neither party currently has.
Part of Title, escrow and closing wires
Why this transaction and not others
Five properties combine, and each one alone would be manageable.
| Property | Consequence |
|---|---|
| Large single transfer | One successful attack is worth six figures |
| Irreversible rail | Recovery depends on speed and the receiving bank's cooperation |
| Known date | The attacker knows exactly when to send the instructions |
| Unfamiliar parties | The buyer has no baseline for what is normal from a title agent |
| Email coordination | Unauthenticated, spoofable, and the attacker may be reading it |
The fourth row is underrated. A buyer completes one or two closings in a lifetime and has no basis for recognising an unusual request. Everything is unfamiliar, so nothing seems unusual.
The attack, in its usual form
- Access is obtained to a mailbox in the transaction — often the agent's or the buyer's, sometimes a smaller firm's with weaker controls.
- The attacker reads quietly for weeks, learning names, tone, timeline and amounts.
- Near the closing date, instructions are sent that copy the genuine ones with the account details changed.
- If the buyer calls to verify, they call the number in the fraudulent email.
- The wire leaves. By the time the discrepancy surfaces at closing, the funds have moved on.
There is no technical exploit in this sequence after step one. The remaining steps are the normal process working as designed.
Why the current defences are routed around
| Defence | How it is defeated |
|---|---|
| Encrypted portal for instructions | Attacker phones the buyer and directs them elsewhere |
| Callback verification | Buyer calls the number in the fraudulent message |
| Email warning banner | Present on every message, including the genuine ones; ignored |
| Payee bank account verification | Verifies the account the title agency used, not what the buyer saw |
| Two-person review at the agency | Reviews the agency's outgoing instructions, not the buyer's incoming ones |
The pattern: every control operates on the agency's side of the transaction. The buyer, who initiates the wire, is outside all of them.
The artefact nobody has
After a diversion, the question is what the buyer was shown. The agency says they published correct instructions; the buyer says they received different ones. Both are telling the truth.
There is no record of what the buyer actually saw at the moment they instructed their bank. That record is what would resolve the dispute, and it is also what would prevent it.
# What the buyer signs, on their own device, before wiring
Wire instructions — closing 2026-09-18
Property: 1420 Fillmore Street
File: ESC-2026-4471
Send to: First National Trust
Routing: 021000021
Account: ****8823
Beneficiary: Cascade Title & Escrow LLC
Amount: $389,142.00
Issued by Cascade Title & Escrow, countersigned 2026-09-16.
[Touch ID] I have read these instructions and am sending
this amount to this account.
→ receipt held by buyer, agency and lender; verifiable offline
The buyer's bank can be shown this before releasing the wire. A buyer presenting instructions with no valid receipt is, at minimum, a reason to pause.
What changes for each party
- The buyer has one place to look and one action to take, instead of judging which of several emails is genuine.
- The title agency can prove what it issued, which matters both for prevention and for the negligence claim afterwards.
- The lender and the receiving bank get a checkable artefact rather than a verbal assurance.
- The insurer has a control to price, which is currently absent from this transaction class.
The honest limits
A buyer determined to follow instructions from a convincing caller can ignore the signed statement entirely and wire anyway. Nothing prevents someone from acting outside the process.
What changes is that the process has a canonical artefact. "Do not send funds without a valid receipt from the closing file" is a rule a buyer can follow, unlike "be alert for fraudulent instructions", which asks them to do something they are not equipped to do.
It also changes the position after a loss. An agency that issued a verifiable statement, and can show what the buyer signed, is in a very different posture from one holding a copy of an email with a red banner on it.
Why every existing control is on the wrong side
| Control | How it is routed around |
|---|---|
| Encrypted portal | Attacker phones the buyer and directs them elsewhere |
| Callback verification | Buyer calls the number in the fraudulent message |
| Email warning banner | On every message, including the copies; ignored |
| Payee account verification | Verifies what the agency used, not what the buyer saw |
| Two-person review at the agency | Reviews outgoing instructions, not incoming ones |
The buyer initiates the wire and sits outside all of them. That is the structural gap, and it is why the missing artefact is a record of what the buyer was shown at the moment they instructed their bank.
Objections and honest limits
“A determined buyer can still be talked into wiring anyway.” True. What changes is that the process has a canonical artefact. ‘No valid receipt, no wire’ is a rule a first-time buyer can follow; ‘be alert for fraudulent instructions’ is not.
“This is the buyer's responsibility.” Courts increasingly examine what the professional did, not what the consumer failed to spot. An agency that offered an un-spoofable channel is in a materially different position from one holding an email footer.
Closing the buyer-side gap
- Issue instructions as a countersigned statement. Not as an email attachment.
- Have the buyer sign on their own device before wiring. Rendered from the signature, not the message.
- Give the buyer one rule. No valid receipt, no wire — whatever anyone says on the phone.
- Put the receipt on the file. For the lender, the underwriter and any later claim.
Terms used here
- Payoff diversion
- Redirecting closing or payoff funds by substituting wiring instructions.
- Business email compromise
- Fraud conducted from a genuine compromised mailbox rather than a spoofed one.
- Recall
- A request to return a wire, whose success depends almost entirely on speed.
Frequently asked questions
Don't secure portals already solve this? They secure the agency's channel. The attacker contacts the buyer directly by phone or email and redirects them away from the portal.
What does callback verification miss? The buyer calls the number in the fraudulent message. Verification is only as good as the channel used to obtain the number.
Can a buyer still be tricked? Yes, if they act outside the process entirely. What changes is that a clear rule exists — no valid receipt, no wire — which is something a buyer can actually follow.
Does this help after a loss? Substantially. The agency can demonstrate what it issued and what the buyer signed, which is a stronger position than a disclaimer in an email footer.
Don't secure portals solve this? They secure the agency's channel. The attacker contacts the buyer directly and redirects them away from it.
Where this fits in Manav
Manav renders the wire or payoff details from a statement the issuer countersigned, has the payer sign on their own device, and puts a verifiable receipt on the file for the agency, the lender and the insurer.