Every closing is a scheduled, publicly visible, six-figure wire
Nowhere else are the amount, the date and the parties all knowable in advance. The FBI logged 12,368 real estate complaints in 2025 and more than $275 million in reported losses. That is why the controls here have to be procedural as well as technical: the opening is a person under time pressure, not an unpatched server.
What you are carrying
- Closing dates and amounts are effectively public information
- Buyers act on wiring instructions under time pressure and without expertise
- Compromise of one mailbox in the chain is enough to redirect a closing
- Underwriters and lenders impose their own security requirements
- Files must remain retrievable for years after a transaction closes
What we do about it
- Email impersonation and lookalike-domain defence across the transaction chain
- A verification procedure for wiring instructions that nobody is allowed to skip
- Alerting on mailbox rules and unusual logins, where redirection begins
- Secure document exchange in place of emailed attachments
- Retention and retrieval that still works years after closing
- Support meeting underwriter and lender security requirements
The fraud that takes a closing does not look like hacking. It looks like an email from someone you have been dealing with for weeks, arriving on the day the money moves, with new instructions and a good reason. Technical controls narrow the opening. The verification step nobody is allowed to skip is what actually closes it.
How it usually works
What we find in real estate, title and escrow
One of these is a published federal figure. The rest is what a wire deadline does to the people handling it.
The FBI recorded 12,368 real estate complaints and $275,110,419 in reported losses in 2025.
FBI IC3 2025 Internet Crime Report (opens in a new tab)How it got that way
Real estate is one of the few categories IC3 reports separately, because the transaction has a public timeline, a known closing date and a wire at the end of it. That combination is unusually attackable.
What we do
Wire verification is a documented procedure, not a habit.
The wire figure above is often quoted as three billion dollars. That number is business email compromise across every sector, and the two are not the same category.
FBI IC3 2025 Internet Crime Report (opens in a new tab)How it got that way
The larger figure is more alarming and appears in the same report, so it gets borrowed. IC3 does not cross-tabulate them, which means nobody can honestly claim the larger one for this industry.
What we do
We publish the real one. A number you can check is worth more than a number that sounds worse.
Fraud in this industry usually reaches you through a real mailbox with a real relationship behind it, not through an obvious impostor.
How it got that way
A closing involves an agent, a lender, a title company and two parties, all emailing under time pressure. An attacker only has to compromise the least protected of them to be inside a conversation everyone already trusts.
What we do
We treat every party to a closing as part of the attack surface, not only your staff — and it reaches you as habits, not settings.
Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.
Compared honestly
What a generalist provider brings to real estate, title and escrow
This is the one vertical where the technical controls matter less than the procedure, and most providers only sell the technical controls.
A generalist
Deploys email security tuned for spam.
CY6
Tunes it for impersonation and lookalike domains across the whole transaction chain, which is where redirection begins.
A generalist
Secures your mailboxes.
CY6
Alerts on the mailbox rule changes and unusual logins that precede a redirected closing, because that is the observable part of the attack.
A generalist
Leaves wiring-instruction procedure to the firm.
CY6
Helps write a verification step nobody is allowed to skip, and treats it as part of the security work rather than as office policy.
Plenty of generalist providers are good at their job. The distinction here is context, not competence.
Rules in play
What you are likely to be measured against
We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.
- ALTA Best Practices (information security pillar)
- Underwriter and lender security requirements
- Gramm-Leach-Bliley Act safeguards, where applicable
- State breach-notification law
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967