Introduction

Real estate wire fraud is a scam where criminals impersonate trusted parties to redirect money during a property transaction.

These transactions often involve large wire transfers, and time-sensitive communication between buyers, sellers, lawyers, real estate agents, title companies, notaries, and financial institutions.

Together, these factors make real estate transactions a prime target for fraud.

For high-net-worth individuals, and executives, the risks can be especially significant.

Property purchases and sales may involve large sums of money, multiple advisors, and sensitive personal or financial information. A single fraudulent email or payment can lead to substantial financial loss.

The most important rule is simple: before sending money, always verify wire instructions by phone using a trusted number you already have, not one provided in an email.

Why it matters

Real estate transactions remain a major target for fraud. In 2025, the FBI’s Internet Crime Complaint Center reported more than 12,000 real estate fraud complaints and over $275 million in reported losses. This was higher than 2024, when losses were about $173 million.

These losses show how common and damaging real estate fraud can be. In many cases, the victim believes they are sending funds to a legitimate party, only to discover that the money was redirected to a fraudulent account.

How the attack works

Attackers often begin by gaining access to an email account involved in the transaction or by impersonating one of the parties. They may silently monitor the conversation and wait for the right moment to intervene.

Once attackers understand the details of the deal, they send a convincing email with fraudulent bank details that redirect the money to the attacker. Attackers may impersonate any party involved in the transaction, such as a real estate agent, lawyer, title company representative, or even the buyer or seller themselves.

Because the attacker may know specifics like dollar amounts, property addresses, and names of people involved, the message can look legitimate, making the email extremely convincing.

How to protect yourself

The most effective protection is independent verification. Before sending any wire transfer, call the intended recipient using a trusted phone number that was provided in person, saved previously, or found through an independently verified source.

Do not rely on contact information included in an email containing wire instructions. If an attacker controls the email conversation, they may also provide a fake phone number to “confirm” the fraudulent details.

This is especially important as AI voice cloning becomes more convincing. A phone call is only useful if the number is trusted. When in doubt, use a number you already know or independently verify the number through an official website or previously established contact.

The same approach should be used for any high-value payment, account change, or request involving sensitive financial information.

Red flags to watch for

Be cautious of:

- Last-minute changes to wire instructions

- Pressure to wire immediately

- Email addresses that look slightly off, such as ‘titlecompany.co’ instead of ‘titlecompany.com’

- Request to confirm payment details only via email

- Unusual urgency, secrecy, or changes in communication style

- New bank account details that were not previously discussed

However, a well-crafted attack may not include any obvious warning signs. Rather than trying to decide whether an email “looks suspicious”, treat all wire instructions as unverified until they are confirmed by phone using a trusted number.

Before sending a wire transfer

Before sending funds, take these steps:

1. Confirm the wire instructions by phone using a known, trusted number.

2. Verify the recipient's name, bank name, account number, routing number, and payment amount.

3. Do not use phone numbers or links provided in the same email as the wire instructions.

4. Be especially cautious about last-minute changes.

5. If anything feels unusual, pause the transaction and contact your advisor, bank, or security team.

How Richter Guardian can help you

Richter Guardian can help reduce the risk of wire fraud through proactive monitoring, personal cybersecurity guidance, and expert support to secure accounts, devices, credentials, and identity-related information.

If you are unsure about a transaction, receive suspicious payment instructions, or want added protection before a high-value transfer, contact us.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Digital protection tips
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Executive sitting in chair, legs crossed

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification

Business email compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. The message may come from a lookalike email address or a real account that has been compromised. Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets.

Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.

The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.

Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.

How it works

An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.

If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.

The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.

Why BEC is a major threat

According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.

BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.

Warning signs of business email compromise

Watch for:

  • Urgency combined with secrecy
  • New or changed payment or banking details
  • A reply-to address that differs from the sender’s address
  • A request that skips the normal approval process
  • Pressure to move the conversation to text or WhatsApp
  • An unusual request for sensitive information

A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.

How to protect yourself

Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.

Never use a number provided in the same email as the request.

During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.

Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.

Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.

If you have been targeted

If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.

If you believe your email account was compromised:

  1. Change the password from a trusted device.
  2. Sign out of other active sessions.
  3. Review the account’s security and recovery settings.
  4. Remove unfamiliar rules or connected applications.
  5. Notify anyone who may have received a fraudulent message from your account.

How Richter Guardian can help you

Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.

We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.

If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: What is Authorized push payment fraud?

What is authorized push payment fraud?

Authorized push payment (APP) fraud happens when victims are tricked into sending money to scammers. We explain how it works—impersonation, BEC, invoice fraud—and how to verify payments and reduce risk.

Introduction​

Authorized push payments involve an account holder granting permission to their bank or payment service to transfer funds directly from their account to another account. The payer usually triggers this transaction using services like online banking, phone banking, or peer-to-peer payment platforms.​

Authorized push payment (APP) fraud, also known as bank transfer scams or authorised bank transfer fraud, occurs when a victim is tricked into authorizing a payment to an account controlled by a scammer. ​

Unlike unauthorized transactions where a fraudster gains access to someone’s account without permission, in APP fraud, the victim is deceived into willingly making the payment, often believing they are paying a legitimate entity or individual.​​

How does app fraud happen?

Authorized push payment fraud can happen in various ways. ​

  1. Advance Fee Scams: The victims are asked to pay a fee to access a service or a prize, which are never delivered. For example, a scammer may impersonate a lottery organization, and will withhold the prize until an administrative fee is paid. When the payment is made, the victim never receives the reward. ​
  2. Impersonation: The scammer poses as a trusted entity, such as a bank, government agency, utility company, or even a friend or family member, and requests payment for a fake invoice, overdue bill, or urgent situation.​
  3. Fake Services or Goods: The victim pays for goods or services that are never delivered or are significantly different from what was advertised. The scammer may set up a fake online store, auction, or classified ad to lure victims.​
  4. Social Engineering: The scammer manipulates the victim through psychological tactics, exploiting emotions like fear, urgency, or greed to coerce them into making the payment.​
  5. Business Email Compromise (BEC): Scammers compromise email accounts of businesses or individuals, or create lookalike accounts, and use them to request payments from employees, clients, or partners, often by impersonating company executives or vendors.​
  6. Invoice Fraud: The scammer pretends to be a vendor and sends fake invoices to the business. The invoice may request payment for goods or services that were never delivered. ​

Prevention​

We recommend the following measures to mitigate the risks of authorized push payment fraud.​

  1. Verify the authenticity of requests for payments – ensure that the request for payment is legitimate by confirming the identity of the individual, organization or service you are initiating a payment for. If the payment is sent to an organization, check the organization’s website and contact their phone number to confirm the request. ​
  2. Establish payment protocols – establish clear protocols within your organization that outline how to properly authorize payments. Ensure relevant employees are aware of these protocols and procedures.​
  3. Monitor transactions – check your accounts to identify any unusual activity that could indicate fraud.

To combat APP fraud, it’s essential for individuals and businesses to remain vigilant and verify the authenticity of requests for payments. We understand that It can be difficult to approach this alone. ​

Transunion identity protection is included on our platform. Transunion identity protection will alert you of any unusual activity on your credit monitoring report that could indicate fraud.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Sailing on vacation with father and son

A $4.5-Million Account Raid: What Every Investor Should Learn About Protecting Their Wealth While on Vacation

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

What happened

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.

According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.

When it collapsed, he lost roughly $4.5 million in retirement savings.

TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

Why this keeps happening

This isn't an isolated incident.

TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.

Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's  oversight and controls.

Why travel makes you a target

It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.

Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.

At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.

Travel disrupts every one of those habits at once:

- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.

Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.

Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.

A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.

None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.

Steps you can take right now

Basic habits, especially before and during travel, meaningfully reduce your own risk:

- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.

Where personal habits aren't enough

Even careful people get targeted, especially the moment they step away from their routine.

This is a gap Richter Guardian is built to close.

Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.

Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.

Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.

The bottom line

Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.