The ITRE Review / Wire fraud
Wire Fraud in BC Real Estate Conveyancing: A Practical Defence
How payment-redirection fraud works in BC closings and the technical and procedural controls that stop it.
Few events are as costly to a real estate transaction as a deposit or a closing payment sent to the wrong account. The fraud rarely involves sophisticated hacking. It involves patience: a criminal gains access to one mailbox, reads the correspondence for days and then sends a short, plausible message at precisely the right moment. This article describes how the pattern works in British Columbia closings and what a brokerage, law office or developer can do about it.
How the fraud actually unfolds
The typical sequence begins with a stolen password, usually obtained through a convincing sign-in page sent to an agent, a conveyancer or a client. Once inside the mailbox, the attacker creates a hidden rule that forwards or hides messages and then watches the transaction develop. They learn the names, the dates, the amounts and the way the participants write to each other.
At the decisive moment, a message arrives from what looks like the lawyer, the brokerage or the client, advising that payment instructions have changed. Sometimes the sender address is a one-letter variation of the real domain. Sometimes it is the genuine mailbox, taken over. Either way, the instruction is sent when everyone is busy and the deadline is real.
Why real estate is a favoured target
Real estate combines three features that criminals value: large amounts, firm deadlines and a chain of parties who have rarely met. A buyer, a seller, two agents, two lawyers, a lender and sometimes a developer all communicate by email, and each one is a possible point of entry. The urgency of a closing discourages the pause that would otherwise expose the trick.
The consequences are also lopsided. A funds transfer that leaves the trust account is frequently difficult to recover, while the cost of the attack to the criminal is almost nothing. That is why prevention is far more effective than reaction, and why the controls that matter are the ones that operate before money moves.
The technical controls that matter
Start with the mailbox. Multi-factor authentication on every account, with legacy sign-in methods switched off, removes the most common route in. Add alerting on new inbox rules and on forwarding to external addresses, because those are the attacker's first moves. Configure SPF, DKIM and DMARC for your own domain so that criminals cannot easily send messages that appear to come from you.
Next, watch the edges. Monitoring for newly registered look-alike domains, and warning banners on external mail that resemble internal names, give staff a visible cue when something is off. None of these controls is exotic, and all are available within Microsoft 365 or Google Workspace at ordinary licence levels when they are configured deliberately.
The procedural control that beats the clever attacker
Technology reduces the odds, but the decisive control is a rule: no change to payment instructions is accepted on the strength of an email alone. Any change must be confirmed by calling a number already on file, not a number in the message, and by a person other than the one who received the request. The rule should be written on a single page and followed without exception, including when the request comes from a senior person.
Rehearse it. A ninety-minute session using a realistic closing-day scenario will reveal whether the call-back step is practical, who answers and what happens if the usual contact is unavailable. Write down the first-hour incident steps too: whom to call at the bank, how to preserve the mailbox and who informs the parties.
What to do if it happens
Speed matters more than anything. Contact the sending and receiving banks immediately, ask them to attempt a recall, and report the incident to police and to the Canadian Anti-Fraud Centre. Preserve the compromised mailbox rather than deleting it, because the logs show how the attacker entered and what they read.
Then notify the relevant parties and your professional regulator or insurer as your obligations require. Your lawyer should guide that step. Afterwards, hold a short review: which control failed, which worked, and what will change. A firm that treats an attempted fraud as a lesson, not an embarrassment, becomes much harder to deceive the second time.
Common mistakes we see
The first mistake is to rely on a single control. A firm that deploys multi-factor authentication but has no call-back rule will still be defrauded when a client's mailbox, not the firm's, is the compromised one. The second is to treat the call-back as a courtesy rather than a requirement, so that it is skipped whenever a senior person is in a hurry.
A third is to forget the client. Buyers and sellers are targeted directly, and they are least likely to recognise a forged instruction. A written notice at the start of every file, explaining how payment details will and will not be communicated, costs almost nothing. Finally, many firms never test their incident steps, and discover during a real event that the bank's fraud line number was in the compromised mailbox.
Checklist to take to your next meeting
- Multi-factor authentication on every mailbox, legacy sign-in disabled
- Alerts for new inbox rules and external forwarding
- SPF, DKIM and DMARC configured and monitored
- One-page call-back procedure for any payment change
- Quarterly rehearsal using a closing-day scenario
- Written first-hour incident steps with bank and police contacts
Where this fits in your technology plan
Guidance works best as part of a coordinated programme rather than a one-off fix. These ITRE services address the subject directly.
- 01AI for Real Estate Operations
AI for Real Estate Operations helps firms adopt generative AI tools safely. We select approved tools, define what information may be entered, and implement automations that save administrative time without exposing client data.
- 02VoIP for Real Estate Teams
VoIP for Real Estate Teams replaces the aging office phone system with a cloud service that works on desk phones, laptops and agent mobiles, and integrates with your CRM so that every conversation is logged against the right contact.
- 03Strata Technology
Strata Technology helps councils and strata management companies run the corporation's information well: where bylaws, minutes and financial statements live, how owners access them, how virtual meetings run and how personal information is protected.
Further reading
- 01Protecting Borrower Data: Security for Mortgage Brokers
How mortgage brokers can safeguard income, identity and credit information while keeping applications moving quickly.
- 02Strata Data Governance in BC: Records, Owners and Privacy
A practical guide for strata councils and managers on keeping records safe, accessible and handled in line with BC privacy law.
- 03BCFSA Compliance Workflows: Technology for Managing Brokers
How managing brokers can use ordinary systems to supervise, record and evidence compliance with BC real estate licensing rules.
Take it to your next leadership meeting
Guidance is only useful when someone acts on it. If this article raised questions about your own office, development or portfolio, bring the checklist above to your next leadership meeting and assign an owner to each item. ITRE offers a free thirty-minute consultation to help you decide what to do first and what can wait.
Speak with an advisor
To discuss any of this in the context of your business, call (604) 632-4959 or write to [email protected]. You will speak with a senior advisor, and the guidance on this site is reviewed by Ali Sedighi, MBA. There is no obligation, no lock-in and no sales script.
Questions and answers
- How common is payment-redirection fraud in real estate?
- It is among the most common serious frauds affecting real estate professionals in Canada, which is why regulators, banks and insurers repeatedly warn about it. Firms of every size are targeted, because closings involve large sums and tight timelines.
- Is multi-factor authentication enough on its own?
- It removes the most frequent route in but is not sufficient alone. You also need alerting on mailbox rules, domain protection and a call-back procedure, because attackers sometimes compromise a counterparty rather than your own systems.
- Who should perform the call-back?
- A second person who did not receive the request, using a telephone number already on file. The request itself, however convincing, is never used as the source of the number.
- Do clients need to be trained too?
- Yes. A short written notice at the start of every transaction, telling clients that you will never change payment instructions by email, is inexpensive and effective.
- Can ITRE provide legal advice about liability?
- No. We implement technical controls and procedures. Questions of liability and notification belong with your lawyer, and we are glad to work alongside them.