In March 2025, a senior citizen in Missouri was closing on a property when a fraudulent email arrived. They thought it was real. A fraudster had infiltrated a title company’s email and was posing as a professional from that company. They sent the email to convince the buyer there were new wire instructions in the hopes of getting the buyer to send them the money instead of to the seller. The homebuyer ultimately sent more than $1.3 million to an account the criminal controlled.

Often, that life savings would disappear forever. This time, the story ended well. The Federal Bureau of Investigation (FBI) worked fast with bank partners to freeze the fraudster’s account. The funds were safe. 

Many victims aren’t so lucky when encountering this type of scam: Business Email Compromise (BEC)—one of the biggest fraud threats title & escrow faces. Our industry must be well prepared to combat it. We handle clients’ life savings during what’s often the biggest financial moment of their lives. Protecting those wires, and the trust behind them, is essential. Here’s what BEC looks like and how to defend against it. 

What is Business Email Compromise?

Business Email Compromise happens when a scammer hijacks an email account, or poses as someone through email, to trick a business or individual into wiring money to an account the criminal controls. Attackers favor companies that move large sums by wire, which makes title & escrow agencies a frequent target. Fraudsters can get in multiple ways: hacking an account directly, reusing a password stolen from another website, or tricking an employee into handing over access. The goal is the same: convince someone to send money.

Is Business Email Compromise a major threat to real estate closings?

Yes. The Qualia 2026 Wire Fraud Report found that 86% of title & escrow professionals identify phishing/business email as a starting point for wire fraud attempts. It’s by far the most commonly cited origination point for wire fraud attacks.

The BEC threat extends throughout real estate and beyond. In 2025, the FBI’s Internet Crime Complaint Center (IC3) logged 24,768 Business Email Compromise complaints, totaling more than $3 billion in losses. That made Business Email Compromise the second-costliest cybercrime type overall, behind only investment fraud. 

How can title & escrow companies protect against Business Email Compromise?

Three elements make BEC work: stolen credentials, quiet mailbox access, and manufactured urgency. Defend on three fronts: people and process, technology, and, if an attack happens, a swift, strategic response.

PEOPLE & PROCESS:

  • Treat urgency and secrecy as red flags. Phrases like “we must fund today,” “keep this between us,” and “the CEO needs it now” signal an attack in progress. A real transaction can survive a ten-minute verification call. A fraudulent one cannot.
  • Train your team to spot and report phishing. Pair regular training and simulations with a one-click way to report suspicious messages, and treat every report as a win, including the false alarms. BEC is a social engineering attack. One fast report lets leadership or your dedicated security team pull the message from every inbox and warn the firm before anyone acts.
  • Require a second approver for sensitive actions. Wire disbursements, changes to payoff instructions, and updates to vendor banking details should all get a second set of eyes. A second reviewer breaks the urgency the fraudster is counting on.
  • Verify every payment instruction change. If wiring details arrive or change by email, confirm them by phone using a number already on file, never one supplied in the message itself. The most dangerous BEC emails come from a real, compromised account. A two-minute callback defeats an otherwise perfect attack.

TECHNOLOGY:

  • Require multi-factor authentication everywhere. Turn on multi-factor authentication (MFA) for email, escrow accounting, banking portals, and remote access. Use phishing-resistant methods, like security keys, for your highest-value accounts. Stolen credentials are the front door for most BEC attacks. With MFA in place, a phished password alone will not get an attacker in.
  • Use a password manager and unique passwords. Attackers use passwords stolen from unrelated breaches. A unique password for every site contains the damage from any single leak. A password manager adds a quiet second defense too, since autofill will not offer saved credentials on a lookalike phishing site.
  • Audit mailbox rules and forwarding settings. Review rules regularly, set alerts for newly created rules, and disable automatic forwarding to outside addresses where possible. Attackers who get into a mailbox almost always add forwarding or hiding rules so they can monitor transactions quietly and time a fraudulent wire request. Those rules survive a password reset, so an attacker can persist long after you think they’re gone.
  • Lock down your email domain and watch for imposters. Use Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting & Conformance. These are authentication standards that can block fraudsters from spoofing your domain. Free tools like MXToolbox can check your domain’s status.
  • Use technology solutions built to protect home closings. A secure communication portal made for title & escrow can help keep sensitive documents and instructions in one verified place. A wire fraud solution that automatically runs wire verifications on every wire can help catch fraudulent changes in wire instructions.

IF AN ATTACK HAPPENS:

  • Report every attack, attempted or successful. Flag suspicious messages to your security team right away, especially if you clicked a link or opened an attachment. This can help limit damage or stop a current or future attack. File a report with IC3 here, even if no money was lost. Reports of attempts help the FBI track and shut down active campaigns.
  • If a fraudulent wire goes out, act immediately. Alert your bank at once; that must be the first call. File a complaint with IC3 and notify transaction parties. The bank and FBI can sometimes freeze the funds, but the odds drop with each passing hour. Also consider involving a professional fraud recovery service that knows title & escrow. The Qualia 2026 Wire Fraud Report found that about 30% of victimized firms used a professional service in efforts to recover stolen wire funds in 2025. 

How should title & escrow companies talk to clients about Business Email Compromise?

Define what normal looks like before a fraudster defines it for you. Most buyers and sellers close on a handful of homes in their lifetime. They might have no idea what a normal request looks like. If you do not set that expectation early, a fraudster will. Tell clients three things from day one:

  • How sensitive information will arrive, and how it will not. For example: “Wire instructions come only through our secure portal, never as an email attachment, and they will not change during your transaction. Any message telling you otherwise is fraud.”
  • A phone number as a second channel. Give clients a verified number in writing at the start, so they always have a trusted contact that no later email can override.
  • An instruction to call that number before sending funds. Tell clients to confirm wiring details by phone, using the number you gave them or one they look up independently, never one from an email. Make clear that calling to double check is never an imposition.

Repeat this message through every stage of interaction: email footers, welcome packets, pre-closing calls. Extend the same guidance to the real estate agents and lenders in your transactions. Their compromised mailboxes are a common launch point for wire fraud against your shared clients. Informed partners protect everyone at the closing table.

How does Qualia help protect against Business Email Compromise?

Qualia helps close the gaps BEC aims to exploit:

  • Qualia Connect is a secure, multi-channel communications platform. It reduces the BEC risk by moving sensitive requests and document sharing into a platform that centralizes all order activity, so clients and agents can be confident in who they’re talking to. Connect’s Magic Links also provide legitimate parties with secure access to specific one-time tasks, which reduces phishing exposure.
  • Qualia Shield checks wire instructions automatically, on every wire, without anyone needing to remember a manual step. That helps prevent a criminal’s attempt to slip in fake wire instructions via BEC. Shield also verifies bank account ownership straight from the bank’s own records and cross-checks identity details like name, address, and Social Security number against public records, so a fraudster’s fake instructions or fake identity can be caught. 
  • Qualia Fraud Recovery Service (Qualia FRS) orchestrates a wire recovery effort on behalf of a title & escrow company at no additional cost to any Qualia Core Customer. Qualia FRS coordinates fund recovery for victimized firms across banks and law enforcement, managing the multi-agency recovery process swiftly when speed and strategic response matter most. Some individual recoveries have topped $1 million, and Qualia FRS has reclaimed stolen funds within a week—far faster than the 30 to 90 days (or longer) it typically takes. 

Business Email Compromise preys on gaps in process, verification, and what clients expect. Every gap you close makes your firm harder to defraud. Doing that makes every home sale or refinance safer. 

Learn more about how Qualia can help protect your business from fraud, and help you recover funds if you’re ever victimized. Contact us today.

Speak With An Expert

ABOUT THE AUTHOR: Alex Hamlin leads the Information Security and IT departments at Qualia. He discovered his passion for security while taking an elective course on computer, network, and election security at the University of Michigan. After graduating from Ann Arbor with a Computer Science degree, he spent the next decade-plus breaking into and/or securing applications, networks, cloud infrastructure, and the occasional physical office space—all as an ethical security expert whose work helped companies strengthen their defenses.