Home Closing Wire Scam Sends Your Down Payment to Thieves

The house is chosen, the inspection is done, and the closing date is finally on the calendar. Then an email arrives with one last task: send the down payment to the updated account before the deadline.

A home closing wire scam is timed for the moment when a large transfer already feels normal. The message can match the property, the real estate agent, and even the language used in the genuine email thread.

Everything may look settled. One independent phone call can reveal that it is not.

Home closing wire scam shown in a fictional title company email

Overview

The criminal arrives at the most expensive moment

Buying a home creates a predictable burst of email. The buyer may be speaking with an agent, lender, lawyer, title company, escrow officer, inspector, and insurance provider at the same time. Documents change quickly, deadlines matter, and a wire transfer may be entirely legitimate.

The home closing wire scam hides inside that real workflow. A criminal compromises an email account or creates a lookalike address, watches the conversation, and waits until the buyer expects final instructions. The fraudulent account is presented as a routine update rather than a new request.

The FBI describes business email compromise as a sophisticated scheme that targets businesses and individuals making transfers. Real estate transactions are especially attractive because one convincing message can redirect a life-changing sum.

The email may contain information that is completely true

A generic phishing message is easy to dismiss. A closing-wire message is different. It can name the property, quote the expected amount, copy a real signature, and appear as a reply in an existing conversation.

Those details do not prove the payment destination is genuine. They may show that a mailbox, document portal, or earlier message was exposed. The attacker only needs to change the part that matters: the beneficiary name, routing number, account number, or link used to retrieve them.

The rest can remain accurate. That is why checking grammar or recognizing the agent’s name is not enough. The verification must happen through a separate channel that the email did not supply.

The wire can move faster than the truth

Wire transfers are designed to settle large payments quickly. That speed is useful in a real closing and useful to a fraud operation. Once money reaches a mule account, it may be divided, withdrawn, or sent abroad before the buyer realizes the title company never received it.

The FBI’s 2025 Internet Crime Report describes a buyer who received compromised title-company instructions and sent more than $1.3 million to a fraudulent account. Immediate reporting allowed authorities and banks to freeze funds in that case. Other victims were not as fortunate.

Warning signs include:

  • Wire instructions arrive for the first time only by email.
  • An existing account number changes close to the deadline.
  • The sender says a previous account is unavailable or under audit.
  • The beneficiary name does not exactly match the verified closing party.
  • The message discourages calling because the office is busy.
  • A new portal or document link appears late in the transaction.
  • The sender requests secrecy from another agent or family member.
  • The transfer must be completed before an unusually short cutoff.
  • A reply-to address differs from the address visible in the signature.
  • The recipient account is in a location unrelated to the property or company.

Fictional closing portal showing changed wire instructions and a new recipient

How the Home Closing Wire Scam Works

Step 1: The attacker finds an active property transaction

Criminals can learn that a sale is underway from compromised email, stolen credentials, public listings, social posts, data broker records, or a hacked account belonging to someone in the transaction. A mailbox offers the richest view because it reveals names, dates, attachments, and the normal writing style.

The buyer is not always the first account compromised. The entry point may be an agent, small law office, contractor, or vendor with weaker security. Once inside, the attacker searches for words such as closing, escrow, settlement, wire, deposit, and clear to close.

Step 2: The real conversation is quietly monitored

The criminal may spend days reading without sending anything. Inbox rules can hide security alerts or move replies into a private folder. The goal is to understand who gives instructions, when the money is expected, and which questions would sound normal.

This patience explains why the eventual email can feel so personal. The attacker is not guessing the transaction. They are borrowing its timing and vocabulary.

Step 3: A trusted identity is copied or hijacked

In one version, the message comes from a genuinely compromised mailbox. In another, the criminal registers a lookalike domain and changes one letter, punctuation mark, or word. A display name can remain identical even when the underlying address is different.

The signature block may be copied from an earlier email, complete with a real office address and telephone number. Those real details decorate the message, but they do not authenticate the account number inside it.

Step 4: The transfer destination changes at the last minute

The email says the escrow account was updated, the first bank is experiencing delays, or a secure portal now holds the final instructions. The change is framed as ordinary administrative cleanup.

Urgency keeps the buyer from comparing records. A deadline before the bank closes, fear of delaying the move, and the possibility of losing the property make a five-minute verification call feel inconvenient. That is the exact pressure the scam requires.

Step 5: A fake document or portal completes the illusion

The link may open a polished closing statement with the correct property and amount. It can use HTTPS, a professional layout, and familiar legal language. None of those features establish who controls the destination account.

Some links also steal Microsoft or Google credentials before displaying the document. That gives the attacker another mailbox, more contacts, and a way to continue the scheme after the first account is secured.

Step 6: The buyer authorizes a real wire to a criminal account

The bank follows an instruction genuinely submitted by its customer. The recipient account often belongs to a money mule who may have been recruited through a job, romance, or investment scam. Funds can move again within minutes.

The closing team may continue sending ordinary messages because it has no idea the buyer received different instructions. Both sides can assume the other is simply processing the transfer until someone asks why the funds have not arrived.

Step 7: The attacker buys time and prepares another attempt

If the buyer asks for confirmation, the criminal may answer from the compromised thread, claim that accounting is posting the transfer, or send a forged receipt. Every extra hour reduces the chance of recovery.

The same access can support a second request involving taxes, insurance, repairs, or a refund. It can also be used to target another client of the compromised professional. Changing one password may not end the intrusion if forwarding rules and active sessions remain.

Why the Message Can Look Completely Normal

This scam is dangerous because it does not require an absurd story. Real home buyers do receive wire instructions. Real title companies use portals. Real closing dates move. The fraudulent request succeeds by changing one legitimate detail inside a legitimate process.

A perfect signature proves only that the attacker could copy a signature. A correct amount proves that transaction data was visible somewhere. A message inside a real thread can result from a compromised account. None of those facts independently verifies the beneficiary bank account.

Do not rely on the sender’s telephone number if it appears only in the suspicious email. The attacker can replace that number along with the account details. Use a number from an earlier verified document, the company’s independently located website, or a contact saved before the transfer request arrived.

Verification should be specific. Read the beneficiary name and account number back to the known closing professional. Ask whether any instruction changed. A vague question such as “Is everything ready?” can produce a truthful yes while the wrong payment details remain untested.

When possible, two people should review a large transfer. One can compare the written instructions while the other makes the independent call. That simple pause is much cheaper than trying to recover a wire after it leaves the account.

Checks to Make Before Sending Closing Funds

Ask at the beginning of the transaction how wire instructions will be delivered and whether the title company ever changes them by email. Save the verified telephone number outside the email thread. That preparation turns a last-minute surprise into an obvious exception.

Compare the beneficiary name with the legal entity handling escrow. A mismatch deserves explanation from a known contact. Do not accept “our partner account” or “temporary processing bank” as an answer delivered only by the same email that introduced it.

Review the sender and reply-to addresses in full. On a phone, tap or expand the sender field. Look at the registered domain, not only the display name. One changed letter can be easy to miss when the message is otherwise familiar.

Call before every first wire and every changed wire. If the office confirms that it never changed the instructions, preserve the message and alert every professional in the transaction. Someone else’s mailbox may still be compromised.

After the transfer, confirm receipt through the same independent channel. Do not wait until the next day or the final walk-through. A rapid check gives the bank and authorities the best chance to interrupt the movement of funds.

Company, Address, and Payment Checks

The email address must match the established conversation

Expand the sender details and compare the complete domain with older verified messages. Watch for added words, doubled letters, substituted characters, and a different reply-to address. A familiar display name is not enough.

The telephone number must come from an independent record

Use the number from a signed contract, an earlier verified closing packet, or a website you reached independently. Do not call a number inserted into the update email or supplied by someone who answers its fake portal.

The office address does not authenticate the wire

Criminals copy genuine addresses, license numbers, names, and logos. Confirm that the company controls the email domain and that the employee works there, but verify the bank instructions separately. Public business data is easy to reproduce.

The beneficiary must match the verified closing party

Read the beneficiary and account details aloud during the independent call. Ask why any name or bank differs from earlier paperwork. Never send a test payment to an unverified account. A smaller loss still confirms that the route works.

What to Do if You Have Fallen Victim to This Scam

  1. Call your bank’s fraud and wire department immediately. Use the number on the bank’s official site or your statement. Ask for an urgent recall, hold, fraud marker, and contact with the receiving institution.
  2. Report the incident to the FBI IC3 now. Submit the wire details at IC3.gov. Large recent transfers may qualify for rapid Financial Fraud Kill Chain action, so do not wait for a complete internal investigation.
  3. Tell the real closing team through known contacts. The title company, lawyer, lender, and agent need to preserve records, warn other clients, and determine which account or system was exposed.
  4. Confirm the real property payment status. Fraud does not automatically satisfy the closing obligation. Ask the professionals what deadlines remain and obtain legal advice about protecting the transaction.
  5. Preserve the complete evidence. Save the original email with headers, attachments, portal URL, wire receipt, beneficiary data, call logs, and every follow-up message. Do not forward the message in a way that destroys header information.
  6. Secure the email account from a clean device. Change the password, sign out other sessions, enable strong multifactor authentication, and inspect forwarding rules, filters, delegates, app passwords, and connected applications.
  7. Notify the email administrator. If a work account was involved, the administrator should review sign-in logs and search for similar messages across the organization. The visible email may be only one part of the intrusion.
  8. Scan affected devices. If you opened a file, installed an application, or entered credentials after following the link, run a full Malwarebytes scan and remove unfamiliar browser extensions.
  9. Add blocking after containment. AdGuard can stop many known phishing pages and malicious ads, but it cannot reverse a wire or prove a closing portal is genuine. Use it as another layer after accounts are secured.
  10. Report identity exposure. If tax forms, identification, or Social Security data was shared, use IdentityTheft.gov and consider credit freezes with the major bureaus.
  11. Watch for recovery scammers. Anyone promising guaranteed wire recovery for an upfront fee, cryptocurrency, or remote access may be using the original loss to start a second fraud.

Frequently Asked Questions

Can a closing-wire email come from a real account?

Yes. A professional’s mailbox may be compromised, allowing the attacker to send from the genuine address or reply inside a real conversation. Verify the account details by telephone through a previously trusted number.

Are last-minute changes to wire instructions always fraudulent?

Not always, but they are high risk and must be independently confirmed. Never use contact information contained only in the message announcing the change.

Does calling the number in the email count as verification?

No. A criminal can replace both the bank details and telephone number. Call a number from an older signed document, independently reached website, or trusted contact record.

Can a bank reverse a fraudulent wire?

Sometimes, especially when the report is immediate and funds remain in the receiving account. Recovery is not guaranteed. Contact the sending bank and IC3 as soon as the mistake is discovered.

Why did the email include my exact property and closing amount?

The attacker may have read a compromised mailbox or stolen transaction records. Accurate context shows access to information, not authority to change the payment destination.

Should I send a small test wire first?

No. A test confirms nothing if the account belongs to the criminal. Verify the full beneficiary information with the closing professional through an independent channel before any transfer.

The Bottom Line

A home closing wire scam turns a real transaction into cover for one false account number. The message may know the property, amount, deadline, and people involved because the criminal has been watching.

Treat every new or changed wire instruction as unverified until a known professional confirms the exact beneficiary and account by a separately sourced telephone number. The call takes minutes. Skipping it can send an entire down payment beyond reach.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

RFQ Confirmation Email Scam Exposed: Fake Procurement Attachment Reviewed

Next

Fake Model Collaboration Scam Charges a Shipping Fee