How Wire Fraud Reaches a Real Estate Closing

Real estate wire fraud in Ontario starts weeks before closing, inside a compromised mailbox, not with a stranger. How GTA brokerages stop it in time.

A real estate deal is one of the few transactions where an ordinary household or a small business moves six figures in a single wire, on a fixed date everyone involved already knows. That combination, a large sum and a public deadline, is exactly what business email compromise is built to exploit. The FBI's Internet Crime Complaint Center has flagged real estate transactions among the costliest categories of this fraud for several years running, and the reason is simple. A hijacked invoice thread nets an attacker a few thousand dollars. A hijacked closing nets a down payment.

The pattern rarely starts with a phone call from a stranger or a suspicious-looking email out of nowhere. It starts inside a mailbox that already belongs to someone in the deal, an agent, a lawyer, a mortgage broker, or a coordinator at the brokerage, and the fraud rides in on a conversation that was already happening.

Why a closing is such an easy target

Most business email compromise depends on the attacker guessing at a relationship. Real estate removes the guesswork. The buyer, the seller, both agents, the lawyers on each side, and the lender are all named, in writing, inside the same thread, often for weeks before the money moves. The closing date is set in advance and known to everyone. MLS listings, land registry filings, and lawyer trust letters make it easy to confirm who is involved in a specific deal without ever breaking into anything.

That transparency is normal and necessary for a transaction to close. It is also a gift to an attacker, because it means a fraudulent email does not have to invent a relationship. It only has to slot into one that already exists, at the one point in the deal where a large sum is expected to move on short notice. A revised wire instruction that arrives two days before closing, referencing the actual property address and the actual lawyer's name, reads as routine because everything around it is real.

Where the compromise actually happens

The account that ends up sending the fraudulent instructions is almost never the agent's alone. Brokerages run on shared inboxes, assistants with delegated access, and lawyers' conveyancing teams juggling a dozen files at once, and any one of those accounts is a way in. A phishing page that looks like a DocuSign notification or a lender portal collects a password. A malicious add-in or a third-party app asking for calendar and mail permissions gets approved by someone in a hurry between showings, the same consent-based route we walked through in the app that walks past your MFA. Either way, the attacker is now reading a real deal thread from the inside.

From there the move is patient rather than loud. A forwarding or filing rule quietly routes anything mentioning wire, trust, or deposit out of sight, the same technique behind the invoice fraud pattern we covered in how invoice fraud starts in your inbox. The attacker studies how the real lawyer or agent writes, waits for the week of closing, then sends new banking details from the hijacked account or from a domain one letter off the real one. Buyers assume a lawyer's office would never ask for money by email without good reason, so the request lands with exactly the authority it needs.

The verification step that actually holds

Every technical control in this piece matters, but the one habit that stops a fraudulent wire cold costs nothing and takes a minute. Before any trust funds move, the buyer or the lawyer's office calls the other side using a phone number they already had on file, never a number pulled from the email that contains the new instructions, and confirms the account details out loud. An attacker who controls the email thread does not control that phone line. Brokerages that write this step into their closing checklist, rather than leaving it to whoever happens to notice something felt off, are the ones who catch the swap before the money leaves.

Ontario adds a regulatory layer on top of the financial one. Deposits usually sit in a brokerage or law firm trust account governed by the Trust in Real Estate Services Act, and misdirected trust funds create a problem for the brokerage's license, not just a loss for the buyer. That is worth keeping in mind alongside the privacy obligations we outlined in PIPEDA and SOC 2 for growing firms, since a brokerage handling deposits and identification documents is squarely inside both.

Hardening the mailbox itself

Underneath the phone-call rule sits the tenant configuration that decides whether a hijack is even possible. Phishing-resistant sign-in, meaning number-matching prompts at minimum and passkeys where you can get there, closes the gap that plain approve-or-deny MFA leaves open, a gap we detailed in the MFA prompt you approved too fast. Blocking legacy mail protocols removes a door that ignores MFA entirely. Reviewing which third-party apps have been granted mail and calendar access, on a schedule rather than never, catches the consent-based route before it turns into a live compromise.

The other half of the problem is outbound, not inbound. Nothing stops a criminal from registering a domain that looks like your brokerage's and emailing a buyer directly, appearing to come from your own name. Proper SPF, DKIM, and DMARC records are what let a receiving mail server tell a real message from your domain apart from a forged one, the mechanics of which we covered in the email your clients think came from you. A brokerage that has locked down sign-in but never configured DMARC has only closed half the door.

What this means for renewal season too

Cyber insurers underwriting a brokerage now ask about most of this directly, because the loss profile is well understood in the industry. Expect questions about MFA on every account handling deal correspondence, whether legacy authentication is disabled, and whether staff have a documented wire verification process. Firms that can answer yes to all three, with evidence rather than a guess, tend to fare noticeably better at renewal, a shift we walked through in cyber insurance renewals just got harder.

None of this requires a large security team. A brokerage on Microsoft 365 or Google Workspace already has most of these controls available in the admin console. The work is turning them on, writing the phone-verification step into the closing process, and checking periodically that nothing has drifted. Our real estate industry page walks through what that setup looks like end to end, and our managed security and compliance work covers the ongoing monitoring that catches a compromised mailbox before closing day rather than after. If you want a second set of eyes on how a specific deal thread would look to someone trying to hijack it, reach out any time.