AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Threats

Threats

Wire Fraud at a Miami Closing Table: How the Payoff Email Changes Banks

Wire fraud in a Miami real estate closing: how the payoff email changes banks, the three signals that catch it, and the callback rule that ends the argument.

Sam KhanSam Khan The Cyber ExpertFounder and CEOOctober 12, 2026 · 6 min read

The payoff letter that arrived on a Friday afternoon

The closing coordinator at a Coral Gables title agency has a 2:00 signing and a seller's payoff to fund before the wire cutoff. At 12:51 the payoff letter lands. It is a reply inside the existing thread with the seller's lender, correct loan number, correct per diem, correct payoff figure to the cent, and one new line in bold: our bank has migrated, please use the updated wiring instructions below.

She has been doing this for eleven years. The email is not the crude kind. The signature block matches, the disclaimer footer matches, the sender's display name matches, and the reply sits under three of her own messages from the past week.

She wires 412,000 dollars at 1:38.

At 4:20 the lender's payoff department calls to ask why the wire has not arrived. The routing number belonged to a small bank in another state. The receiving account was opened nine days earlier in the name of a limited liability company incorporated in Florida a month before that. By Monday the balance is 900 dollars.

The only thing that was fake was the address the reply came from. One character in the domain, in a font where that character is nearly invisible, in a thread she had every reason to trust.

What the heck happened in that inbox

This is business email compromise, and in a closing it has a specific shape. The attacker does not break into the money. The attacker breaks into the conversation about the money.

Thread hijacking: the attacker reads a real mailbox, usually a lender's or an agent's, then replies inside an existing thread from a domain that resembles the real one. Every detail is right because the details were copied from the thread.

Lookalike domain: a registration that differs by one character, a swapped letter, an added hyphen, or a character from another alphabet that renders almost identically.

Mailbox rules: after a login is stolen, the attacker sets a rule that moves the real lender's replies to a folder nobody reads, so the coordinator never sees the message that would have blown the whole thing open.

Payoff letter: the document nobody questions, because it comes from the party owed the money and it always arrives late.

The pattern to hold onto is this. A change in banking instructions is the event, and the channel it arrives on can never be the channel you use to verify it.

The numbers that matter

Real estate and rental fraud cost 275 million US dollars across 12,368 victims in the FBI's IC3 2025 Internet Crime Report. That is the specific column this closing sits in, and it is a column made almost entirely of one-off losses at small agencies and individual buyers.

Business email compromise accounted for 3.05 billion US dollars across 24,768 complaints in that same IC3 2025 report, and 86 percent of the money moved by wire or ACH. Not gift cards. Not crypto. The plumbing your closing already runs on.

Business email compromise and funds transfer fraud together made up 58 percent of reported claims in the Coalition 2026 Cyber Claims Report. For a title agency that is the whole risk picture in one figure: the thing most likely to produce a claim is an email that asks you to change where money goes. Credential abuse, the way most of these mailboxes get opened, accounted for 13 percent of breaches in the Verizon 2026 Data Breach Investigations Report.

What to do this week

  1. Write the callback rule and put it in the file, not in someone's head. Any change to wiring instructions, from anyone, at any stage, is verified by phone to a number taken from the original engagement documents, never from the email. The person who verifies is never the person who sends. (CIS 17 Incident Response Management)
  2. Turn on external-sender banners, domain authentication (SPF, DKIM and DMARC with a reject policy) and lookalike-domain detection in your mail platform. The banner alone would have made that reply look wrong at a glance. (CIS 9 Email and Web Browser Protections)
  3. Put multi-factor authentication on every mailbox and every remote login, then alert on new mailbox forwarding and inbox rules. A rule that hides a lender's replies is the loudest signal in this attack and almost nobody watches for it. (CIS 6 Access Control Management)
  4. Send wiring instructions to buyers and sellers on paper or through a secure portal at the start of the transaction, with one sentence in bold: these instructions will never change by email. Then honour it. (CIS 9 Email and Web Browser Protections)
  5. Run one fake payoff letter a quarter at your own team, and reward the person who calls the lender instead of wiring. Score it, do not punish it. (CIS 14 Security Awareness and Skills Training)
  6. Write the recovery card now: bank fraud line, wire recall request, IC3 filing, insurer notice, counsel, in that order with the phone numbers filled in. The window is measured in hours and Friday afternoons are when this happens. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment looks at a closing the way the attacker does: which mailboxes hold transaction threads, who can change wiring instructions, what alerts exist on inbox rules, and whether the callback rule survives a busy Friday. Our team implements the controls at a reasonable rate, from mail authentication to data loss prevention to protecting the assets that hold your files. We work with title agencies and brokerages across Miami and South Florida, and the real estate program is built around this one attack. Start with the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer.

Questions people ask

Who is liable when closing funds go to a fraudulent account? It depends on the state, the engagement letter and who was compromised, and it is usually decided long after the money is gone. Insurers and courts look hard at whether the party sending funds followed a documented verification procedure. That is the practical answer for a title agency: the callback rule is not only how you prevent the loss, it is the evidence that decides who carries it.

Can we recover a wire that has already gone out? Sometimes, and only if you move within hours. Call your bank immediately and ask for a recall, then file with the FBI's IC3 with the exact amount, the receiving bank and the account number. Recovery odds fall sharply once the funds are broken up and moved onward, which often happens the same business day.

Does encrypted email solve this? No, because the usual failure is not interception. The attacker is inside a real mailbox, or is sending from a domain that reads correctly at a glance, so the message is authentic in every way except the instruction it carries. Encryption protects the contents in transit. Only a callback to a number you already had protects the money.

Nobody at that closing table was careless. They were busy, on a Friday, with a real thread and a real loan number. That is the entire business model, and a phone call breaks it.

Controls this post maps to

CIS 9 Email and Web Browser ProtectionsCIS 6 Access Control ManagementCIS 17 Incident Response Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.