How Criminals Are Using Deepfakes to Commit Wire Fraud in Real Estate
The moment money moves in a real estate closing is the moment fraud has to succeed by. Everything else in a criminal's playbook, the reconnaissance, the impersonation, the well-timed message, exists to redirect a single wire before anyone realizes the person on the other end wasn't who they claimed to be. That's always been the shape of wire fraud. What's changed is that "who they claimed to be" now includes a voice that sounds exactly like your seller, a video call face that looks exactly like your closer, and an email that reads exactly like the way your title officer writes. Deepfake technology has industrialized the impersonation, and payments are where the industry is feeling it.
The scale is not theoretical. Cyber-enabled fraud cost $13.7 billion in reported losses in 2024, according to the FBI's Internet Crime Complaint Center, and deepfake scams increased 40% year over year, per security firm Entrust's 2026 Identity Fraud Report. One reported case that captured how far the tactic has come: a finance employee at UK engineering firm Arup transferred approximately $25 million after a video conference in which every "colleague" on the call, including a supposed CFO, was a deepfake.
The Hong Kong police described the deception as multi-person, real-time, and convincing enough that the employee acted on it. That case wasn't real estate, but the mechanic behind it is exactly the one now being pointed at closings. This piece is about how deepfakes specifically enable wire fraud in a real estate transaction, and what a title company can rely on when the person authorizing a payment change may not be a person at all.
Why Wire Fraud Is the Point of Every Deepfake Attack on a Closing
Deepfake technology is dramatic, but the goal behind almost every deepfake attack on real estate is undramatic: move money to an account the fraudster controls. Closings are targeted because they concentrate three things in one moment. A large one-time transfer, a tight deadline, and a predictable sequence of communication that a criminal can study in advance. Every element of a deepfake attack, the cloned voice, the fake video call, the impersonated email, exists to survive one specific instant: the instant a wire is being sent.
The reason attention has shifted to deepfakes now is that the older wire fraud playbook, the misspelled email domain, the awkward phrasing, the unfamiliar phone number, no longer requires much sophistication to defeat. Modern AI has removed the signals that used to give away impersonation attempts, and it has done so precisely at the point in a transaction where money is about to move. Wire fraud didn't get more common because criminals got more determined. It got harder to spot because the impersonation got better.
Here is a video that can helps us understand the potential threat.
The Three Payment Moments a Deepfake Attack Targets
Money enters and leaves a closing at three distinct moments, and each is a different opportunity for a deepfake to land. Understanding which moment is being targeted is what makes the defense specific rather than general.
Earnest Money at the Start of the File
Earnest money is the first payment in a transaction and often the first opportunity for a fraudster to redirect funds. The buyer is early in their relationship with the title company and hasn't yet learned the office's rhythms. A voice message from what sounds like the closer, or an email that looks like it came from the title officer, with instructions on where to send the earnest money, doesn't need to survive much scrutiny. The relationship is too new for the buyer to notice anything wrong. It's why front-loading identity and communication expectations matters so much, and it's a recurring theme in why buyers get confused during closings.
Cash to Close, Under Deadline Pressure
The largest transfer of the transaction arrives at the end, on a deadline. This is the deepfake's ideal terrain. The buyer is stressed, the timeline is tight, and a well-timed call from what sounds like the title office, or a video message from what looks like the closer, with updated wire details, feels like exactly the kind of last-minute change a real closing sometimes requires. Except no legitimate closing requires it delivered this way. Every documented pattern of successful real estate wire fraud concentrates here, at the cash-to-close moment, because the pressure to act quickly is the fraudster's most reliable ally.
Seller Proceeds and Post-Closing Payments
Wire fraud attention overwhelmingly focuses on incoming buyer funds, but sellers receive money too, and seller impersonation, where a fraudster poses as the seller to redirect the payoff or net proceeds, has been the fastest-growing pattern in recent years. Deepfake voice has made it dramatically easier to execute. A cloned seller voice authorizing a change to where net proceeds should go is exactly the kind of instruction that used to be caught by ear and increasingly isn't.
How a Deepfake Actually Changes a Wire in a Closing
The technology itself isn't the entire story. The attack has to reach a specific person, at a specific moment, through a specific channel, and convince them to redirect a payment. Three mechanisms currently do most of the damage.
Voice Cloning the Party Who Authorizes the Wire
A very common deepfake tactic in real estate wire fraud today is voice cloning. Given a few seconds of audio, often lifted from a video the seller or agent posted online, a modern voice model produces a clone convincing enough to leave voicemails, sustain a phone conversation, or authorize a change under time pressure. The call is placed to the closer, to the buyer, or to the bank, depending on the workflow, at exactly the moment a change to wire details would feel plausible. The old defense, "did that sound like them?", now clears at a bar the technology has raised past most human ears.
Deepfake Video on Verification Calls
For a while, the industry's answer to voice-only fraud was to add a video step: "get on a call and confirm it's really the seller." Real-time video deepfakes have made that verification unreliable. A fraudster can now appear on a video call as the party in the transaction, in real time, with lip sync and facial expressions convincing enough to pass casual observation. The Arup case, whatever industry, made the point in the most public way possible: a multi-person video conference is not, by itself, a defense against impersonation anymore.
Here is a video of a title agent who caught a fake seller using a video on loop:
AI-Drafted Business Email Compromise That Changes Wire Details
Business email compromise, where a fraudster gains access to or spoofs an inbox in the transaction, has been the workhorse of real estate wire fraud for years. AI has upgraded it quietly. A compromised inbox can now produce messages in the exact writing style, tone, and signature format of the person being impersonated, because the AI can be trained on the emails already in the account. A closer reading a "please use the updated wire instructions attached" message from what looks like the lender no longer sees the typos or awkward phrasing that used to reveal the fake. It reads exactly like the person they've been corresponding with. Email is one of the reasons most anti-fraud tools don't fully protect title companies when the workflow itself still routes wire details through inboxes.
The Shrinking Window Between "Wire Sent" and "Wire Gone"
There's a technical reason deepfake wire fraud is uniquely damaging in real estate right now, beyond the impersonation itself: the window to recall a fraudulent wire has been shrinking. Modern payment rails move money faster, and once funds land in the fraudster's account, they're often broken into smaller amounts and moved onward within hours. The traditional recovery playbook, notify the sending bank, get law enforcement involved, freeze the receiving account, still works, but only if it happens fast enough.
The faster the rails, the smaller that window becomes.
For a closing, this changes the calculus of "we'll catch it after the fact." The realistic expectation now is that a wire redirected by a convincing deepfake is a wire that's gone, not a wire that's temporarily misplaced. Which means the defense has to move upstream, into the moment before the wire is authorized, not the hours after.
What Actually Defends a Real Estate Closing Against AI-Enabled Wire Fraud
Because deepfake wire fraud succeeds by defeating human judgment in the moment, the defenses that hold up are the ones that don't rely on human judgment in the moment. Four structural moves close off most of the openings these attacks depend on.
.png?width=600&height=400&name=2025%20Working%20Doc.%20Feature%20Images%20for%20Web%20(1).png)
Wire Details That Live Outside Email and Voice Channels Entirely
The strongest single defense is removing the channels a deepfake operates on from the wire-details conversation. When wire instructions are only ever released through an authenticated portal, and when the process for changing them isn't triggered by a call or an email, the deepfake has nowhere useful to land. A voice cloned perfectly cannot change a bank account it can't reach.
Identity Confirmed at Intake, Before the Pressure Point Arrives
Deepfakes are most effective at the moment of a mid-closing change, precisely because that moment relies on the person receiving the request to judge, on the spot, whether it's legitimate. If the identity of every party has been confirmed at the start of the file, before any change or release could be requested, the mid-closing "the seller wants to update the wire" doesn't land on the closer as an identity check. It lands on a workflow that already knows who the seller is and where their real instructions come from.
One Branded Communication Channel Every Party Learns
The reason a deepfake is convincing in the moment is that the moment feels ordinary. If every legitimate message in a closing comes from the title company's own web domain and phone number, and everyone in the transaction has learned that, then a technically flawless deepfake delivered through any other channel no longer fits the pattern. The impersonation can be perfect and still be caught, because it arrived somewhere it shouldn't be.
Callbacks That Actually Verify, Not Callbacks That Feel Like Verification
The old "confirm by phone at a known number" rule still works against deepfakes, but only if it's done with discipline. Under pressure, staff and clients alike tend to call the number in the new message, which is the fraudster's.
A no-exceptions rule that the verification number is the one captured when the file was opened, and never a number supplied in the message being verified, is what keeps this technique honest in an era when the voice answering may not be real.
The Old Payment Defenses vs. What Holds Up Now
|
The old model |
What deepfakes broke |
What still holds |
|---|---|---|
|
Recognize the party's voice or email style |
AI clears the "sounds like them" bar |
Identity confirmed before the moment of pressure |
|
Video call to prove it's really the seller |
Real-time deepfake video is now viable |
Wire details behind authenticated access only |
|
Trust wire instructions from a familiar email |
AI writes in the exact style of the sender |
Every closing message from one branded domain |
|
Call back to confirm the change |
Staff often call the number in the new message |
The number captured at intake, no exceptions |
|
Catch it after the wire is sent |
Faster rails, narrower recovery window |
Prevent the redirect before the wire is authorized |
How CloseSimple Helps Title Companies Defend Real Estate Payments
Deepfake wire fraud is a payments problem, and CloseSimple was built for title and escrow teams that want payments to happen inside a workflow the impersonation can't easily reach.
With CloseSimple, a title company can:
- Collect earnest money and cash to close inside one branded portal, so payments live in one predictable, authenticated place
- Deliver wire instructions only through authenticated portal access, never email or voice channels
- Confirm the identity of buyers and sellers at intake, before any payment detail or sensitive information is released
- Send every closing message from your own web domain and a phone number unique to your local area, so an outside sender stands out
- Give every client one branded destination for the entire closing, so a call or message from anywhere else contradicts the pattern they know
- Trigger secure steps directly from SoftPro 360, ResWare, or Settlor, so payment protection is built into the workflow
Schedule a demo today to see how CloseSimple can help your title company fight fraud in this ever-changing environment.
FAQ's
How are deepfakes being used to commit wire fraud in real estate?
Fraudsters use AI-cloned voice, real-time deepfake video, and AI-drafted email to impersonate a party in a closing, most commonly the seller, buyer, closer, or lender, and use that impersonation to request or authorize a change to wire instructions. The impersonation is convincing enough that older defenses based on recognizing a voice or writing style are no longer reliable.
Which point in a real estate closing is most vulnerable?
The cash-to-close moment, at the end of the transaction under deadline pressure, is the most common target because the timing, the size of the transfer, and the emotional intensity make a last-minute "please use these updated instructions" request feel plausible. Seller proceeds and post-closing payments are also increasingly targeted through deepfake seller impersonation.
How much has AI-enabled fraud grown?
Cyber-enabled fraud reached $13.7 billion in reported losses in 2024 according to the FBI's IC3, and deepfake scams alone rose 40% year over year according to security firm Entrust's 2026 Identity Fraud Report. Public cases include a reported $25 million loss at UK engineering firm Arup after a deepfake video conference impersonating multiple staff, an incident Hong Kong police described in detail in their 2024 briefing.
Can a fraudulent wire be recovered once it's been sent?
Sometimes, but the window is shrinking. Modern payment rails move money quickly, and funds are often broken up and moved onward within hours of landing in the fraudster's account. Recovery is possible only with immediate action from the sending bank and law enforcement, and even then the odds fall off rapidly with time. Prevention has become dramatically more important than recovery.
If fraud does occur, we strongly recommend using the CertifID Fraud Recovery Services.
Can a title company detect a deepfake voice or video by ear or eye?
Increasingly not, and this is the key shift. Some AI-generated content still has tells, but the reliability of "we'll catch it when it sounds wrong" is falling faster than staff training can compensate. Structural defenses that don't depend on catching the fake in the moment, identity confirmed at intake, wire details behind authenticated access only, one branded communication channel, are what continue to hold up as the technology improves.
What is the single most important defense against AI-enabled wire fraud?
Removing wire details from email and voice channels entirely. When wire instructions are only ever released through authenticated access, and when the process for changing them isn't triggered by a call or an email, the deepfake has nowhere useful to land, regardless of how convincing the impersonation is.
Written by Bill Svoboda
As the co-founder of CloseSimple, Bill Svoboda is dedicated to helping title companies modernize the closing experience through strategic innovation and growth. He is a frequent industry speaker on the intersection of AI, fraud prevention, and marketing/sales strategies, helping leaders scale their businesses with confidence.
bogid - 27787114388
Related posts
Identity Verification
4 Identity Verification Failures That Put Title Companies at Risk of Impersonation Fraud
Resources
Why Title Companies Should Route Every Real Estate Closing Payment Through One Portal
Fraud Prevention
7 Non-Negotiables for Preventing Wire Fraud at Your Title Company
Fraud Prevention
What Is Wire Fraud in Real Estate Closings? A Title Company's Guide to Stop It