Manav.id
Fraud · 5 min read

You can't un-send a wire. You can refuse to send one no human signed.

Americans lost $275M to real-estate wire fraud in 2025. Nearly 1 in 4 homebuyers received a suspicious communication during closing, and once the down payment leaves the country, recovery is close to zero. “Call the title company to verify” is advice, not a control.

The attack

It's a clean, devastating version of business email compromise. An attacker monitors a closing, then sends the buyer last-minute wire instructions — from a spoofed or compromised address that looks exactly like the title company — with the account number swapped to theirs. The buyer wires their life savings to a stranger. By the time anyone notices, the money is gone: the FBI logged $275.1M across 12,368 complaints in 2025, and recovery only happens (about 58% of the time) if funds are frozen before they leave the US banking system. After that, it's near zero.

It's widespread, not rare: more than 1 in 4 homebuyers got a suspicious closing message, and 60% of title professionals say fraud attempts are rising. Real-estate wire fraud is a slice of the $3.04B BEC problem, aimed at the least-experienced party in any large transfer: a person buying a home once a decade.

Why "verify by phone" isn't enough

The standard advice — call a known number to confirm the wire — helps, but phone numbers are spoofed too, and both parties are rushed and stressed at closing. It puts the entire control on a tired human catching a single swapped digit under time pressure. That's not a control; that's a hope.

Bind the disbursement to a signature

The wire instruction itself should carry a signature — from the title/escrow agent's enrolled device — bound to the payee and amount. The buyer's app verifies that signature against the title company's published key before any money moves. Instructions that don't carry a valid signature, or that were altered after signing, simply don't execute. A spoofed email with a swapped account can't produce the signature, so it can't be acted on.

For the buyer it's a green check instead of a leap of faith. For the title company it's a defensible, logged record that the instructions they issued are the instructions the buyer received — which matters when the lawsuits start.

Honest limits

This requires the title/escrow side to enroll and sign, and ideally the lender too — a coordination lift, though a one-time one. It stops the altered-instruction attack, which is the dominant one; it doesn't stop a title employee who is themselves compromised and signs a fraudulent instruction knowingly, which is what internal controls and multi-party approval address.

Frequently asked questions

Can't the buyer just call to confirm the wire? They should — but phone numbers are spoofed and people miss a single changed digit under closing pressure. A signature bound to the payee and amount is checked by software, not a stressed human.

Who has to adopt this for it to work? The title/escrow company signs the disbursement instructions; the buyer's side verifies. Adding the lender strengthens it further. It's a one-time enrollment, not a per-deal burden.

Does this replace title insurance or wire-verification services? No — it complements them. Those reduce or reimburse loss after the fact; this prevents the altered-instruction wire from executing in the first place.

A homebuyer wires once in a decade, against an attacker who does it daily. Don't make the green light a guess.