A buyer wires funds on Tuesday. On Wednesday, the other side asks where the money is.
In a residential closing, that call may come from the title company.
In a commercial transaction or high-value lease, it may come from the landlord, lender, escrow agent, broker, or counsel.
At first, everyone focuses on the thief. Soon, the focus shifts to a different question: whose inbox was compromised?
That answer often determines who will be responsible for the loss. And it can’t be found by reading emails alone.
It requires a complex forensic investigation, often completed by experts with former law enforcement experience. One wrong wire can place an entire organization under internal investigation, with litigation holds and insurance notices to follow.
A single fraudulent wire can trigger an internal investigation, a forensic review of how the compromise occurred, insurance notifications; and, in some cases, regulatory scrutiny.
Transactions are different in the age of AI. The FBI reports that “Chan generators can quickly create official-sounding emails” that direct victims to wire funds to fraudulent accounts. (FBI IC3, 2025 Internet Crime Report, p. 39.)
The Scope of Threat
The risk is not theoretical.
The FBI’s Internet Crime Complaint Center registered 12K+ real estate fraud complaints in 2025. The amount of reported real estate losses exceeded $275M. (FBI IC3, 2025 Internet Crime Report, pp. 7–8).

Business email compromise (BEC) had more $3,046,598,558 in reported losses in 2025. That was the the second-largest loss category after investment fraud (FBI IC3, 2025 Internet Crime Report, p. 9).
FinCEN found that real estate represented 16 percent of reported BEC cases (FinCEN, Updated BEC Advisory, 2019, p. 5).
The same advisory noted that criminals target individuals “particularly and increasingly those with high net worth” (FinCEN, Updated BEC Advisory, 2019, p. 3).
The IC3 received more than 22,000 AI-related complaints in 2025, with adjusted losses above $893 million (FBI IC3, 2025 Internet Crime Report, p. 39).
Common Wire Fraud Attack Vectors
The FBI describes “[real estate wire fraud]… as a sub-category of BEC, in which criminal actors target individuals or companies executing large wires related to real estate transactions” (FBI, BEC and Real Estate Wire Fraud, FY2022 Report, p. 3).
Victims include title companies, law firms, real estate agents, buyers, and sellers (FBI, FY2022 Report, p. 3).
For example, in 2025, a Missouri buyer received a “compromised email from the ‘title company'” with instructions to wire more than $1.3 million (FBI IC3, 2025 Internet Crime Report, p. 23).
In another closing, buyers received “an email impersonating their legitimate attorneys” and wired more than $449,000 (FBI IC3, 2025 Internet Crime Report, p. 23).
Fortunately, the investigation determined that title company’s email system had been compromised. That finding likely saved the buyer significant time and resources that otherwise would have been required to prove the source of the breach.
In one federal case, a company wired $51,040.99 in rent after an email from an impersonator posing as its landlord (DOJ, N.D. Ga., June 1, 2021).

The FTC has received more than 65K+ rental scam reports with about $65 million in losses since 2020 (FTC Data Spotlight, Dec. 22, 2025).
The FBI warns of “title pirates” who use forged deeds to convey title and of scammers who impersonate owners to list property (FBI Boston, Apr. 1, 2025).
New York now treats deed theft as larceny under Penal Law § 155.05(2)(g) (N.Y. Penal Law § 155.05).
A Texas title company employee created “a fraudulent email address resembling that of a legitimate lienholder” and requested the title company to wire more than $350,000 (DOJ, S.D. Tex., Apr. 28, 2025). Not every compromise comes from outside.
The first question: whose email was compromised?
In our experience, most real estate wire fraud losses start with either a compromised email account or a convincing email impersonation scheme.
The critical question is not whether fraud occurred, but whose account was compromised.
The breach could originate with the buyer, seller, attorney, broker, title company, landlord, lender, or escrow agent.
The answer often defines liability analysis and could determine who ultimately bears the loss.
A party whose email system was compromised may face claims that inadequate cybersecurity controls enabled the fraud.
A party that wired funds based on unverified instructions could face allegations that it failed to follow basic verification procedures.
The forensic evidence usually paints the story. FinCEN lists the indicators that matter: email auto-forwarding, inbox sweep or sorting rules set up in the victim’s account, and the authentication protocol that was compromised (FinCEN, Updated BEC Advisory, 2019, p. 10). None of them is visible in the fraudulent email itself.

Why forensics Often Determines Liability
NIST defines digital forensics as “The application of science to the identification, collection, examination, and analysis, of data while preserving the integrity of the information and maintaining a strict chain of custody for the data” (NIST SP 800-86, via CSRC Glossary).
In practice, the compromised devices have to be analyzed.
Computers, phones, and mailboxes must be imaged and analyzed, and the audits are expensive.
Dilendorf Law Firm uses retired cybercrime law enforcement agents to conduct these audits. Their reports establish which account was breached, when, and through what path.
Showing that your organization was not compromised requires mailbox audit logs, sign-in records, rule-change histories, and endpoint images.
FinCEN’s recovery program asks for sender email addresses with associated IP addresses and timestamps, and for login information with location and timestamps (FinCEN, RRP Fact Sheet, Feb. 11, 2022).
Proving a negative is harder than proving a breach. One wrong wire can place an entire organization under internal investigation, with litigation holds and insurance notices to follow.
Proving a negative is harder than proving a breach. One wrong wire can place an entire organization under forensic scrutiny.
What begins as a missing payment could quickly evolve into audits, insurance claims, regulatory inquiries. And if a system compromise is confirmed, company could be subject to extensive reporting obligations under federal/ state law.
Critical Evidence Does Not Last Forever
Claims must be investigated on time.
In our experience, consumer providers such as Gmail and Apple may retain the account activity records needed to prove a compromise for only about six months after the incident.
In our experience, consumer email providers such as Gmail and Apple may retain account activity records for only a limited time, sometimes as little as six months after an incident.
Private organizations vary widely. A landlord, title company or broker m may retain years of logs, while others may retain little or no historical data. Some may not have formal retention policies at all.
That matters. Missing logs can make it difficult to determine how the fraud occurred and whether a system was compromised.
The bank will not resolve it
Under UCC § 4A-207(b)(1), “if the beneficiary’s bank does not know that the name and number refer to different persons, it may rely on the number as the proper identification of the beneficiary of the order. The beneficiary’s bank need not determine whether the name and number refer to the same person.” (UCC § 4A-207).
The FBI observed: “When BEC acts occur, the bank does not have to verify the transfer beyond the number. In order to address this shortcoming, it’s ” (FBI, FY2022 Report, p. 11).
FinCEN adds that such transfers “are often irrevocable” (FinCEN, Updated BEC Advisory, 2019, p. 8). The loss therefore usually remains between the transacting parties.
When splitting the loss makes sense
A full forensic audit of two organizations can cost tens of thousands of dollars. Where the loss is modest relative to that cost, a negotiated allocation before the forensic phase may be the rational outcome, depending on the facts.
Where the loss is large, forensics are unavoidable, and the findings drive the claim. Either way, preservation comes first, because talks fail and logs expire.
What to do in the first 72 hours
- Contact the originating bank and request a recall. Send your bank a “Hold Harmless Letter or Letter of Indemnity” (IC3, Business Email Compromise).
- File a complaint at ic3.gov immediately. “FinCEN is most likely to be able to interdict or recover funds when fraudulently induced wire transfers are reported to law enforcement within 72 hours of the transaction.” (FinCEN, RRP Fact Sheet, Apr. 15, 2026, p. 2).
- Suspend mailbox deletion, export audit and sign-in logs. Retain forensic expert witness to image affected devices before anyone “cleans” the account.
- Notify every counterparty in writing and request that each preserve evidence.
- Review cyber/crime policies and give notice within policy deadlines.
- Retain counsel and independent forensic investigators before assigning blame.
The recovery window is measured in hours and so is the evidence. If you’re a victim of wire fraud, call our New York office at +1 212 457 9797.
How Dilendorf Law Firm helps
Dilendorf Law Firm has practiced digital asset law since 2017 and has arbitrated more than 100 cybercrime matters. We work with retired FBI and cybersecurity law enforcement agents who investigate real estate wire fraud and conduct internal network compromise audits.
Their findings are critical in developing claims against a counterparty, or in defending against one. When the other side is a large landlord or title company, our team takes apart its compliance and cybersecurity record to prove who was at fault.
We represent high-net-worth individuals, family offices, and title companies in recovery and litigation. Buyers and sellers also retain the firm for complex New York real estate transactions and closings, where safeguarding cybersecurity throughout the closing process is paramount.
We advise on wire fraud prevention, secure fund transfers, and risk mitigation (and cross-border structuring and real estate asset protection, drawing on more than 15 years of NYC and Manhattan real estate experience).
Clients turn to Max Dilendorf for real estate asset protection, including trust and LLC structures designed to protect New York property from creditors and fraud.
We also advise clients on the growing cyber risks affecting real estate transactions, including business email compromise (BEC) schemes, fraudulent wire instructions, and seller or title company impersonation scams.
Contact Us
If you’re a victim of wire fraud, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Wire fraud recovery is time-sensitive and uncertain. Contacting Dilendorf Law Firm does not guarantee that any funds will be recovered or that any claim will succeed.
Frequently asked questions
Who is liable when closing funds are wired to a fraudster?
There is no single rule. Liability may depend on whose email system was compromised, who transmitted the instructions, and what the contracts require. A party whose account was breached may face claims that its security failures caused the loss. A party that wired without verifying may face the argument that it ignored reasonable procedures. The FBI reports victims at every level of the transaction, including title companies, law firms, agents, buyers, and sellers (FBI, FY2022 Report, p. 3). The answer usually requires forensic evidence, not assumptions.
How do we determine whose email was compromised?
Through digital forensics. Investigators review mailbox audit logs, sign-in records, and IP addresses with timestamps. They look for auto-forwarding rules, inbox sorting rules, and the authentication method that failed (FinCEN, Updated BEC Advisory, 2019, p. 10). Device images may reveal malware. Network logs may show the intrusion path. Both parties’ systems often need review, because a spoofed email may involve no compromise at all on one side. NIST defines the discipline as work that preserves data integrity and maintains a strict chain of custody (NIST SP 800-86, via CSRC Glossary).
Can the bank reverse the wire?
Not on its own in most cases. FinCEN notes that such transfers “are often irrevocable” (FinCEN, Updated BEC Advisory, 2019, p. 8). The originating bank can request a recall, and the IC3 recommends requesting a Hold Harmless Letter or Letter of Indemnity (IC3, Business Email Compromise). Recovery depends on whether funds remain in the recipient account. In 2025 the FBI’s Recovery Asset Team froze $679,013,183 of $1,163,919,846 in attempted theft, a 58 percent success rate (FBI IC3, 2025 Internet Crime Report, p. 17). Speed matters more than any other factor.
Does the bank have to match the beneficiary name to the account number?
Generally no under the UCC. Section 4A-207(b)(1) allows the beneficiary’s bank to “rely on the number as the proper identification of the beneficiary of the order” when it does not know of a mismatch (UCC § 4A-207). The FBI has recommended that the section be redrafted to require banks to confirm that name and number match (FBI, FY2022 Report, p. 11). State enactments may vary. A name mismatch alone therefore rarely shifts the loss to the bank, depending on the facts.
What must be preserved after a fraudulent wire?
Everything connected to the transaction. The IC3 instructs victims to “Collect and save all documents and electronic transmissions directly related to your loss” (IC3, Victim Resources). In practice this means the genuine and fraudulent emails with full headers, mailbox audit logs, sign-in logs, rule histories, device images, and phone records. Retention settings should be suspended so logs do not roll off. In our experience, consumer providers such as Gmail and Apple may keep account activity records for only about six months. Counterparties should receive written preservation demands. The affected account should not be reset or cleaned before it is imaged.
What is the FinCEN Rapid Response Program?
A Treasury program that helps recover fraudulently induced wires sent abroad. Victims activate it by filing with the IC3 or the U.S. Secret Service, not by contacting FinCEN directly (FinCEN, RRP Fact Sheet, Apr. 15, 2026, p. 1). FinCEN is most likely to interdict or recover funds when the wire is reported within 72 hours (FinCEN, RRP Fact Sheet, Apr. 15, 2026, p. 2). Since 2015 the program has facilitated the interdiction of $1.8 billion and the recovery of over $1 billion for 5,790 U.S. victims (FinCEN, RRP Fact Sheet, Apr. 15, 2026, p. 1).
Is it smarter to split the loss than to pay for forensics?
Sometimes. A full forensic audit of two organizations can cost tens of thousands of dollars. Where the loss is modest relative to that cost, a negotiated allocation may be sensible, depending on the facts. Where the loss is large, or where one party plainly ignored verification steps, forensics may be the only path to recovery. Preservation should occur in either scenario. Any settlement should address confidentiality, mutual releases, and insurance rights.
Are lease and rental payments targeted too?
Yes. In one federal case, a company wired $51,040.99 in rent after receiving an email from an impersonator posing as its landlord (DOJ, N.D. Ga., June 1, 2021). The FTC has received nearly 65,000 rental scam reports with about $65 million in losses since 2020 (FTC Data Spotlight, Dec. 22, 2025). Tenants and property managers should verify any change in payment instructions with the requester by telephone (FBI, Business Email Compromise).
Is deed theft a crime in New York?
Yes. Deed theft is now a form of larceny under Penal Law § 155.05(2)(g), which covers forged conveyance instruments and misrepresentation of ownership (N.Y. Penal Law § 155.05). The Attorney General has stated that deed theft itself was not a crime under prior New York law (N.Y. Attorney General, July 19, 2024). Prosecution must begin within five years of the theft or two years after the owner discovers it, whichever is later (N.Y. Attorney General, July 19, 2024). Owners may register for title alerts with the county clerk (FBI Boston, Apr. 1, 2025).
Are real estate transactions different in the age of AI?
Yes. The FBI reports that AI chat generators can “quickly create official-sounding emails” mimicking a company’s executives, with phishing links or directions to wire funds (FBI IC3, 2025 Internet Crime Report, p. 39). Voice cloning can also be used to request a wire payment (FBI IC3, 2025 Internet Crime Report, p. 39). In 2025, businesses reported losses of more than $30 million to BEC scams involving AI (FBI IC3, 2025 Internet Crime Report, p. 39). A wire instruction that reads and sounds authentic is therefore no longer proof of authenticity. Every change in payment instructions should be confirmed by telephone at a number known before the transaction began.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report (2026). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI, Business Email Compromise and Real Estate Wire Fraud, FY2022 Report to Congress (Nov. 14, 2022). https://www.fbi.gov/file-repository/reports-and-publications/fy-2022-fbi-congressional-report-business-email-compromise-and-real-estate-wire-fraud-111422.pdf
[3] FinCEN, Updated Advisory on Email Compromise Fraud Schemes, FIN-2019-A005 (July 16, 2019). https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[4] FinCEN, Rapid Response Program Fact Sheet (Apr. 15, 2026). https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[5] FinCEN, Rapid Response Program Fact Sheet, FIN-2022-FCT1 (Feb. 11, 2022). https://www.fincen.gov/system/files/shared/RRP%20Fact%20Sheet%20Notice%20FINAL%20508.pdf
[6] IC3, Business Email Compromise (crime information page). https://www.ic3.gov/CrimeInfo/BEC
[7] IC3, Victim Resources. https://www.ic3.gov/Outreach/Resources
[8] FBI, Business Email Compromise (scams and safety page). https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise
[9] FBI Boston, “FBI Boston Warns Quit Claim Deed Fraud Is on the Rise” (Apr. 1, 2025). https://www.fbi.gov/contact-us/field-offices/boston/news/fbi-boston-warns-quit-claim-deed-fraud-is-on-the-rise-
[10] U.S. Department of Justice, N.D. Ga., “Atlanta man sentenced for laundering over $247,000 from business email compromise schemes” (June 1, 2021). https://www.justice.gov/usao-ndga/pr/atlanta-man-sentenced-laundering-over-247000-business-email-compromise-schemes
[11] U.S. Department of Justice, S.D. Tex., “Texas title company employee sent to prison for orchestrating $350,000 real estate wire fraud scheme” (Apr. 28, 2025). https://www.justice.gov/usao-sdtx/pr/texas-title-company-employee-sent-prison-orchestrating-350000-real-estate-wire-fraud
[12] Federal Trade Commission, Data Spotlight, “Rental scams hit home: $65 million in reported losses” (Dec. 22, 2025). https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/12/rental-scams-hit-home-65-million-reported-losses
[13] NIST Computer Security Resource Center, Glossary, “digital forensics” (quoting NIST SP 800-86). https://csrc.nist.gov/glossary/term/digital_forensics
[14] Uniform Commercial Code § 4A-207, Misdescription of Beneficiary (Cornell Legal Information Institute). https://www.law.cornell.edu/ucc/4A/4A-207
[15] New York Penal Law § 155.05, Larceny; defined (New York State Senate). https://www.nysenate.gov/legislation/laws/PEN/155.05
[16] New York Attorney General, “Attorney General James Announces New Protections Against Deed Theft” (July 19, 2024). https://ag.ny.gov/press-release/2024/attorney-general-james-announces-new-protections-against-deed-theft

