CloseSimple | Resources

How Criminals Are Using Deepfakes to Commit Wire Fraud in Real Estate

Written by Bill Svoboda | July 08, 2026

The moment money moves in a real estate closing is the moment fraud has to succeed by. Everything else in a criminal's playbook, the reconnaissance, the impersonation, the well-timed message, exists to redirect a single wire before anyone realizes the person on the other end wasn't who they claimed to be. That's always been the shape of wire fraud. What's changed is that "who they claimed to be" now includes a voice that sounds exactly like your seller, a video call face that looks exactly like your closer, and an email that reads exactly like the way your title officer writes. Deepfake technology has industrialized the impersonation, and payments are where the industry is feeling it.

The scale is not theoretical. Cyber-enabled fraud cost $13.7 billion in reported losses in 2024, according to the FBI's Internet Crime Complaint Center, and deepfake scams increased 40% year over year, per security firm Entrust's 2026 Identity Fraud Report. One reported case that captured how far the tactic has come: a finance employee at UK engineering firm Arup transferred approximately $25 million after a video conference in which every "colleague" on the call, including a supposed CFO, was a deepfake.

The Hong Kong police described the deception as multi-person, real-time, and convincing enough that the employee acted on it. That case wasn't real estate, but the mechanic behind it is exactly the one now being pointed at closings. This piece is about how deepfakes specifically enable wire fraud in a real estate transaction, and what a title company can rely on when the person authorizing a payment change may not be a person at all.

Why Wire Fraud Is the Point of Every Deepfake Attack on a Closing

Deepfake technology is dramatic, but the goal behind almost every deepfake attack on real estate is undramatic: move money to an account the fraudster controls. Closings are targeted because they concentrate three things in one moment. A large one-time transfer, a tight deadline, and a predictable sequence of communication that a criminal can study in advance. Every element of a deepfake attack, the cloned voice, the fake video call, the impersonated email, exists to survive one specific instant: the instant a wire is being sent.

The reason attention has shifted to deepfakes now is that the older wire fraud playbook, the misspelled email domain, the awkward phrasing, the unfamiliar phone number, no longer requires much sophistication to defeat. Modern AI has removed the signals that used to give away impersonation attempts, and it has done so precisely at the point in a transaction where money is about to move. Wire fraud didn't get more common because criminals got more determined. It got harder to spot because the impersonation got better.

Here is a video that can helps us understand the potential threat.

The Three Payment Moments a Deepfake Attack Targets

Money enters and leaves a closing at three distinct moments, and each is a different opportunity for a deepfake to land. Understanding which moment is being targeted is what makes the defense specific rather than general.

Earnest Money at the Start of the File

Earnest money is the first payment in a transaction and often the first opportunity for a fraudster to redirect funds. The buyer is early in their relationship with the title company and hasn't yet learned the office's rhythms. A voice message from what sounds like the closer, or an email that looks like it came from the title officer, with instructions on where to send the earnest money, doesn't need to survive much scrutiny. The relationship is too new for the buyer to notice anything wrong. It's why front-loading identity and communication expectations matters so much, and it's a recurring theme in why buyers get confused during closings.

Cash to Close, Under Deadline Pressure

The largest transfer of the transaction arrives at the end, on a deadline. This is the deepfake's ideal terrain. The buyer is stressed, the timeline is tight, and a well-timed call from what sounds like the title office, or a video message from what looks like the closer, with updated wire details, feels like exactly the kind of last-minute change a real closing sometimes requires. Except no legitimate closing requires it delivered this way. Every documented pattern of successful real estate wire fraud concentrates here, at the cash-to-close moment, because the pressure to act quickly is the fraudster's most reliable ally.

Seller Proceeds and Post-Closing Payments

Wire fraud attention overwhelmingly focuses on incoming buyer funds, but sellers receive money too, and seller impersonation, where a fraudster poses as the seller to redirect the payoff or net proceeds, has been the fastest-growing pattern in recent years. Deepfake voice has made it dramatically easier to execute. A cloned seller voice authorizing a change to where net proceeds should go is exactly the kind of instruction that used to be caught by ear and increasingly isn't.

How a Deepfake Actually Changes a Wire in a Closing

The technology itself isn't the entire story. The attack has to reach a specific person, at a specific moment, through a specific channel, and convince them to redirect a payment. Three mechanisms currently do most of the damage.

Voice Cloning the Party Who Authorizes the Wire

A very common deepfake tactic in real estate wire fraud today is voice cloning. Given a few seconds of audio, often lifted from a video the seller or agent posted online, a modern voice model produces a clone convincing enough to leave voicemails, sustain a phone conversation, or authorize a change under time pressure. The call is placed to the closer, to the buyer, or to the bank, depending on the workflow, at exactly the moment a change to wire details would feel plausible. The old defense, "did that sound like them?", now clears at a bar the technology has raised past most human ears.

Deepfake Video on Verification Calls

For a while, the industry's answer to voice-only fraud was to add a video step: "get on a call and confirm it's really the seller." Real-time video deepfakes have made that verification unreliable. A fraudster can now appear on a video call as the party in the transaction, in real time, with lip sync and facial expressions convincing enough to pass casual observation. The Arup case, whatever industry, made the point in the most public way possible: a multi-person video conference is not, by itself, a defense against impersonation anymore.

Here is a video of a title agent who caught a fake seller using a video on loop:

AI-Drafted Business Email Compromise That Changes Wire Details

Business email compromise, where a fraudster gains access to or spoofs an inbox in the transaction, has been the workhorse of real estate wire fraud for years. AI has upgraded it quietly. A compromised inbox can now produce messages in the exact writing style, tone, and signature format of the person being impersonated, because the AI can be trained on the emails already in the account. A closer reading a "please use the updated wire instructions attached" message from what looks like the lender no longer sees the typos or awkward phrasing that used to reveal the fake. It reads exactly like the person they've been corresponding with. Email is one of the reasons most anti-fraud tools don't fully protect title companies when the workflow itself still routes wire details through inboxes.

The Shrinking Window Between "Wire Sent" and "Wire Gone"

There's a technical reason deepfake wire fraud is uniquely damaging in real estate right now, beyond the impersonation itself: the window to recall a fraudulent wire has been shrinking. Modern payment rails move money faster, and once funds land in the fraudster's account, they're often broken into smaller amounts and moved onward within hours. The traditional recovery playbook, notify the sending bank, get law enforcement involved, freeze the receiving account, still works, but only if it happens fast enough.

The faster the rails, the smaller that window becomes.

For a closing, this changes the calculus of "we'll catch it after the fact." The realistic expectation now is that a wire redirected by a convincing deepfake is a wire that's gone, not a wire that's temporarily misplaced. Which means the defense has to move upstream, into the moment before the wire is authorized, not the hours after.

What Actually Defends a Real Estate Closing Against AI-Enabled Wire Fraud

Because deepfake wire fraud succeeds by defeating human judgment in the moment, the defenses that hold up are the ones that don't rely on human judgment in the moment. Four structural moves close off most of the openings these attacks depend on.

Wire Details That Live Outside Email and Voice Channels Entirely

The strongest single defense is removing the channels a deepfake operates on from the wire-details conversation. When wire instructions are only ever released through an authenticated portal, and when the process for changing them isn't triggered by a call or an email, the deepfake has nowhere useful to land. A voice cloned perfectly cannot change a bank account it can't reach.

Identity Confirmed at Intake, Before the Pressure Point Arrives

Deepfakes are most effective at the moment of a mid-closing change, precisely because that moment relies on the person receiving the request to judge, on the spot, whether it's legitimate. If the identity of every party has been confirmed at the start of the file, before any change or release could be requested, the mid-closing "the seller wants to update the wire" doesn't land on the closer as an identity check. It lands on a workflow that already knows who the seller is and where their real instructions come from.

One Branded Communication Channel Every Party Learns

The reason a deepfake is convincing in the moment is that the moment feels ordinary. If every legitimate message in a closing comes from the title company's own web domain and phone number, and everyone in the transaction has learned that, then a technically flawless deepfake delivered through any other channel no longer fits the pattern. The impersonation can be perfect and still be caught, because it arrived somewhere it shouldn't be.

Callbacks That Actually Verify, Not Callbacks That Feel Like Verification

The old "confirm by phone at a known number" rule still works against deepfakes, but only if it's done with discipline. Under pressure, staff and clients alike tend to call the number in the new message, which is the fraudster's.

A no-exceptions rule that the verification number is the one captured when the file was opened, and never a number supplied in the message being verified, is what keeps this technique honest in an era when the voice answering may not be real.

The Old Payment Defenses vs. What Holds Up Now

The old model

What deepfakes broke

What still holds

Recognize the party's voice or email style

AI clears the "sounds like them" bar

Identity confirmed before the moment of pressure

Video call to prove it's really the seller

Real-time deepfake video is now viable

Wire details behind authenticated access only

Trust wire instructions from a familiar email

AI writes in the exact style of the sender

Every closing message from one branded domain

Call back to confirm the change

Staff often call the number in the new message

The number captured at intake, no exceptions

Catch it after the wire is sent

Faster rails, narrower recovery window

Prevent the redirect before the wire is authorized

How CloseSimple Helps Title Companies Defend Real Estate Payments

Deepfake wire fraud is a payments problem, and CloseSimple was built for title and escrow teams that want payments to happen inside a workflow the impersonation can't easily reach.

With CloseSimple, a title company can:

  • Collect earnest money and cash to close inside one branded portal, so payments live in one predictable, authenticated place
  • Deliver wire instructions only through authenticated portal access, never email or voice channels
  • Confirm the identity of buyers and sellers at intake, before any payment detail or sensitive information is released
  • Send every closing message from your own web domain and a phone number unique to your local area, so an outside sender stands out
  • Give every client one branded destination for the entire closing, so a call or message from anywhere else contradicts the pattern they know
  • Trigger secure steps directly from SoftPro 360, ResWare, or Settlor, so payment protection is built into the workflow

Schedule a demo today to see how CloseSimple can help your title company fight fraud in this ever-changing environment.