This scenario is a composite drawn from publicly reported patterns, not a specific real case.
Week 1: reconnaissance
The groundwork starts long before closing day. Property listings, public records, and social media posts about an upcoming move all signal that a transaction is in progress. An attacker doesn't need to hack anything to learn who's involved; a buyer's agent's listing history, a title company's staff directory, or even an out-of-office reply can name exactly who's handling the file.
Days before closing: the setup
With names and a closing date established, the attacker sets up the infrastructure: a domain that looks nearly identical to the title company's, or access to a genuinely compromised inbox obtained through a reused or leaked password. Everything is ready before a single suspicious message is sent.
Closing day: the email arrives
The message lands at a moment that makes urgency feel normal, often close to the wire deadline. It references the real address, the real closing date, sometimes the real names of everyone else on the file. The change requested is usually small: a routing number update, a note that the original account "bounced." Nothing about it looks dramatic.
The follow-up call
If the buyer hesitates, a phone call often follows, sometimes from a spoofed number, increasingly from an AI-generated voice matching someone the buyer has already spoken with. The call exists to remove the last bit of doubt before the wire is sent.
After the wire
Once funds are sent, they typically don't stay in the receiving account for long. They're moved, split, or converted within hours, specifically to outrun a recall request. Discovery often doesn't happen until days later, when the actual seller or lender confirms funds never arrived.
Where the sequence could have broken
Every stage above depends on one thing going unverified: the identity of whoever is asking for money to move, and the account it's moving to. Confirming both, independently, and recording that confirmation to a tamper-evident blockchain record rather than an editable database, is the single step that breaks the entire sequence.
- How far in advance do attackers typically start planning?
- Reconnaissance often begins weeks before a closing, using publicly available listing, staff, and social media information rather than any system breach.
- Is a phone call enough to confirm instructions are legitimate?
- Only if it's made to a number you already had, not one provided in the suspicious message, and paired with independent verification of identity and account details.
