Why Criminals Study Title Agencies

There is a reason your industry attracts this much attention. On any given afternoon, your office holds six figures of other people’s money, moves it on email-initiated instructions, and coordinates among buyers, sellers, lenders, and agents who have never met each other and often never speak by phone. That combination — high-value wire transfers, an email-driven workflow, and counterparties who cannot verify each other’s voices — is the exact anatomy of business email compromise.

The FBI’s 2025 Internet Crime Report puts numbers on it: $3.04 billion in BEC losses, the second-highest loss category the Bureau tracks, driven by a scheme that persistently targets home closings and wire transfers. Real estate fraud complaints alone accounted for $275 million in losses across 12,368 complaints. And those are only the incidents victims reported — a floor, not a ceiling, since a meaningful share of diverted closings are settled quietly between agencies, underwriters, and insurers without ever reaching IC3.

Scale matters to how this lands. For a national lender, a diverted wire is a loss line. For a five- or ten-person independent agency, one diverted closing wire is not a bad quarter — it can be the end of the business. The claim exhausts your coverage. The underwriter reassesses the relationship. And in a market that runs on referrals from a few dozen realtors and loan officers, the reputational damage compounds faster than any of it.

The Numbers Behind the Threat

  • $3.04 billion: Reported BEC losses in 2025 — the second-largest loss category the FBI tracks.
  • $275.1 million: Reported real estate fraud losses, across 12,368 complaints.
  • Days to weeks: Typical attacker dwell time inside a compromised mailbox before the fraudulent wire instruction is sent.
  • One: Number of diverted closing wires it takes to end a small independent agency.

How the Compromise Actually Happens

Owners tend to picture wire fraud as a single deceptive email arriving out of nowhere. It almost never is. The fraudulent instruction is the final move in a sequence that has been running quietly for days or weeks.

It starts with an account. Someone’s email is compromised — a processor’s, a realtor’s, a lender’s, sometimes yours — usually through a credential harvested elsewhere, a convincing phishing page, or password reuse that turns one unrelated breach into an entry point in your workflow. Notably, the compromised mailbox often does not belong to your agency at all. It belongs to a party in your transaction, which is why a program that secures only your own perimeter still leaves the fraud pattern intact.

Then the attacker waits. This is the part that surprises people. They do not send anything. They sit inside the mailbox reading transaction threads — learning your file numbers, your closing calendar, the names of your escrow officers, the way your agency signs off on emails, whether you use “wiring instructions” or “wire instructions.” They set a mail-forwarding or inbox rule so they continue to see everything even if the password changes, and frequently a rule that moves replies containing words like “wire” or “fraud” into an unread folder so the real account owner never sees the warning.

Then they wait for the moment of maximum time pressure. The day before closing, sometimes the morning of, the “updated wire instructions” arrive — inside a thread the buyer has trusted for six weeks, written in a voice they recognize, referencing the correct file number and the correct amount. Buyers do not fail to catch this because they are careless. They fail to catch it because by that point the attacker knows the transaction better than they do.

Here is the operative fact for anyone responsible for an agency’s security program: every stage of that dwell time produces telemetry. The sign-in from an unfamiliar location. The impossible-travel authentication — a session from your county at 9:14 a.m. and another from an overseas IP address at 9:41. The new mail-forwarding rule created on an account that has never had one. The mailbox accessed at 2:40 a.m. on a Sunday. The failed authentication burst that precedes the successful one. These signals exist in the logs of systems you already use.

The question ALTA and your underwriter are increasingly asking is not whether those logs exist. It is: who at your agency is looking at them?

What Pillar 3 Actually Expects

ALTA’s Best Practices framework is the de facto standard underwriters and lenders use to evaluate settlement agents, and its third pillar covers the one thing most agencies treat as paperwork: a written information security program protecting non-public personal information. That expectation is not arbitrary. Title and settlement companies are financial institutions for purposes of the Gramm-Leach-Bliley Act, which means the FTC Safeguards Rule applies to your operation the way it applies to a lender.

A compliant program is not a binder on a shelf. Read across Pillar 3 and the Safeguards Rule and the operational expectations are consistent: designate someone accountable for the program, assess your risks, maintain safeguards that detect unauthorized access to customer information, monitor the systems that hold and move NPI, keep and review logs of activity on those systems, and operate an incident response plan so a suspected compromise is contained and disclosed properly. The amended Safeguards Rule also carries a notification obligation — reporting qualifying security events affecting 500 or more consumers to the FTC within 30 days of discovery.

Underwriters translate all of that into audit questions that are uncomfortably specific:

For most independent agencies, the honest answers are “no one, not really,” “we probably wouldn’t,” and “which alert?” The last question is often the most damaging, because the ability to scope an incident after the fact depends entirely on decisions made before it — whether logging was on, whether it was retained, whether anyone would recognize what they were looking at.

The Gap Is Arithmetic, Not Negligence

None of this stems from owners who do not care about security. It stems from math that does not work at agency scale.

You employ closers, processors, escrow officers, and title examiners. You do not employ security analysts, and there is no version of your P&L in which you do. The IT provider who manages your workstations is a valuable partner who resets passwords, patches servers, and keeps the office running — they are not watching authentication patterns at 11 p.m. on a Saturday, because nobody hired them to and their business model does not include it.

Meanwhile the attacker’s schedule is the inverse of yours. The compromise happens on a Saturday night, the reconnaissance happens over a holiday weekend, and the fraudulent instruction lands at 4:50 p.m. on a Friday when your team is closing three files at once and nobody has time to make a callback that takes eleven minutes.

Continuous monitoring is a 24/7/365 function. Doing it with people means multiple full-time analysts — a payroll line larger than most independent agencies’ entire technology budget. Outsourcing it to a traditional managed security provider has historically meant enterprise-anchored pricing plus alert forwarding, which relocates the problem rather than solving it: you still receive a queue of notifications that someone at your agency must interpret, and that someone is a closer with four files pending.

So the control gets written into the program because Pillar 3 expects it, the tooling gets purchased because the underwriter asks about it, and the operational half — someone actually reviewing what those tools produce — quietly never happens. That gap is invisible right up until the afternoon it becomes the only thing anyone wants to discuss.

What Detection Looks Like Across the Kill Chain

Consider a realistic compromise against a nine-person agency, and where each stage becomes visible.

Notice the shape of it. Your callback procedure defends the last line. Everything before it — five days of visible attacker activity — is defended by nothing, because no one is positioned to see it. And the earlier stages are precisely where intervention is cheap: disabling a compromised session on Sunday morning is a password reset. Discovering the compromise on Friday evening is a claim.

The Same Week, Two Ways

  • Unmonitored: Six detectable events accumulate across five days. Nobody reviews them. The wire leaves Friday. The loss is discovered the following Tuesday when the seller asks where the funds are. Recovery odds fall sharply after the first 72 hours.
  • Monitored: The impossible-travel sign-in is investigated within minutes of firing. The forwarding rule — created six minutes later — corroborates it. Your designated contact is called Sunday morning with a complete picture. The account is reset, sessions revoked, rules removed, and the transaction proceeds normally. Total cost: one interrupted Sunday.

What Intruex Does About It

Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tools and logs you already have — leading endpoint and cloud security platforms, or nearly any log source via a standards-based interface — and investigates every alert those systems raise, around the clock.

For a title agency, that means the BEC kill chain gets watched at every stage, not just the last one:

None of this replaces your wire-verification procedures, your callbacks to known numbers, your policy of never accepting instruction changes by email, or your staff training. Keep every bit of it — those controls stop the attacks that get through. What monitoring replaces is the assumption, quietly baked into most agencies’ security programs, that detection will somehow happen without anyone staffed to do it.

What to Do This Quarter

Independent of any platform decision, these are the actions worth taking before your next underwriter review:

The Economics Finally Work

The reason independent title agencies have never had real monitoring is not that owners do not care. It is that a 24/7 security function was an enterprise purchase, priced for organizations with security departments, and every attempt to scale it down produced either an unread alert queue or a bill nobody could justify against a closing volume of two hundred files a year.

An AI analyst team changes that arithmetic. Every alert investigated, every verdict explained, escalations only when they are real — documented continuously, at a cost that fits an independent agency rather than a bank. The compliance artifact your underwriter wants and the operational capability that actually protects the escrow account become the same thing, produced by the same process.

The Core Question

If a processor’s email account were compromised at 11:20 p.m. this Saturday — followed by an impossible-travel sign-in, an external forwarding rule at midnight, and five days of quiet reading through your closing files — who at your agency would notice, and on what day? If the honest answer is “when the buyer called about the wire,” the attacker had five days of uncontested access to the most sensitive workflow you operate.

Your escrow account will stay a target. The only variable you control is whether anyone is watching the approach.

Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (BEC and real estate fraud loss figures). ALTA Title Insurance and Settlement Company Best Practices, Pillar 3. FTC Standards for Safeguarding Customer Information (Safeguards Rule), as amended, including the security event notification requirement. Attack sequence described is a composite drawn from publicly documented BEC patterns targeting settlement services, not a specific incident.