Why Criminals Study Title Agencies
There is a reason your industry attracts this much attention. On any given afternoon, your office holds six figures of other people’s money, moves it on email-initiated instructions, and coordinates among buyers, sellers, lenders, and agents who have never met each other and often never speak by phone. That combination — high-value wire transfers, an email-driven workflow, and counterparties who cannot verify each other’s voices — is the exact anatomy of business email compromise.
The FBI’s 2025 Internet Crime Report puts numbers on it: $3.04 billion in BEC losses, the second-highest loss category the Bureau tracks, driven by a scheme that persistently targets home closings and wire transfers. Real estate fraud complaints alone accounted for $275 million in losses across 12,368 complaints. And those are only the incidents victims reported — a floor, not a ceiling, since a meaningful share of diverted closings are settled quietly between agencies, underwriters, and insurers without ever reaching IC3.
Scale matters to how this lands. For a national lender, a diverted wire is a loss line. For a five- or ten-person independent agency, one diverted closing wire is not a bad quarter — it can be the end of the business. The claim exhausts your coverage. The underwriter reassesses the relationship. And in a market that runs on referrals from a few dozen realtors and loan officers, the reputational damage compounds faster than any of it.
The Numbers Behind the Threat
- $3.04 billion: Reported BEC losses in 2025 — the second-largest loss category the FBI tracks.
- $275.1 million: Reported real estate fraud losses, across 12,368 complaints.
- Days to weeks: Typical attacker dwell time inside a compromised mailbox before the fraudulent wire instruction is sent.
- One: Number of diverted closing wires it takes to end a small independent agency.
How the Compromise Actually Happens
Owners tend to picture wire fraud as a single deceptive email arriving out of nowhere. It almost never is. The fraudulent instruction is the final move in a sequence that has been running quietly for days or weeks.
It starts with an account. Someone’s email is compromised — a processor’s, a realtor’s, a lender’s, sometimes yours — usually through a credential harvested elsewhere, a convincing phishing page, or password reuse that turns one unrelated breach into an entry point in your workflow. Notably, the compromised mailbox often does not belong to your agency at all. It belongs to a party in your transaction, which is why a program that secures only your own perimeter still leaves the fraud pattern intact.
Then the attacker waits. This is the part that surprises people. They do not send anything. They sit inside the mailbox reading transaction threads — learning your file numbers, your closing calendar, the names of your escrow officers, the way your agency signs off on emails, whether you use “wiring instructions” or “wire instructions.” They set a mail-forwarding or inbox rule so they continue to see everything even if the password changes, and frequently a rule that moves replies containing words like “wire” or “fraud” into an unread folder so the real account owner never sees the warning.
Then they wait for the moment of maximum time pressure. The day before closing, sometimes the morning of, the “updated wire instructions” arrive — inside a thread the buyer has trusted for six weeks, written in a voice they recognize, referencing the correct file number and the correct amount. Buyers do not fail to catch this because they are careless. They fail to catch it because by that point the attacker knows the transaction better than they do.
Here is the operative fact for anyone responsible for an agency’s security program: every stage of that dwell time produces telemetry. The sign-in from an unfamiliar location. The impossible-travel authentication — a session from your county at 9:14 a.m. and another from an overseas IP address at 9:41. The new mail-forwarding rule created on an account that has never had one. The mailbox accessed at 2:40 a.m. on a Sunday. The failed authentication burst that precedes the successful one. These signals exist in the logs of systems you already use.
The question ALTA and your underwriter are increasingly asking is not whether those logs exist. It is: who at your agency is looking at them?
What Pillar 3 Actually Expects
ALTA’s Best Practices framework is the de facto standard underwriters and lenders use to evaluate settlement agents, and its third pillar covers the one thing most agencies treat as paperwork: a written information security program protecting non-public personal information. That expectation is not arbitrary. Title and settlement companies are financial institutions for purposes of the Gramm-Leach-Bliley Act, which means the FTC Safeguards Rule applies to your operation the way it applies to a lender.
A compliant program is not a binder on a shelf. Read across Pillar 3 and the Safeguards Rule and the operational expectations are consistent: designate someone accountable for the program, assess your risks, maintain safeguards that detect unauthorized access to customer information, monitor the systems that hold and move NPI, keep and review logs of activity on those systems, and operate an incident response plan so a suspected compromise is contained and disclosed properly. The amended Safeguards Rule also carries a notification obligation — reporting qualifying security events affecting 500 or more consumers to the FTC within 30 days of discovery.
Underwriters translate all of that into audit questions that are uncomfortably specific:
- Who reviews your access and authentication logs, and how often? Name the person and show the cadence.
- How would you know if an employee mailbox started forwarding to an outside address?
- What happened the last time an alert fired? Not what your policy says should happen — what actually happened, on what date.
- How quickly would you detect unauthorized access to a file containing NPI?
- If a compromise were discovered today, could you determine what was accessed and when?
For most independent agencies, the honest answers are “no one, not really,” “we probably wouldn’t,” and “which alert?” The last question is often the most damaging, because the ability to scope an incident after the fact depends entirely on decisions made before it — whether logging was on, whether it was retained, whether anyone would recognize what they were looking at.
The Gap Is Arithmetic, Not Negligence
None of this stems from owners who do not care about security. It stems from math that does not work at agency scale.
You employ closers, processors, escrow officers, and title examiners. You do not employ security analysts, and there is no version of your P&L in which you do. The IT provider who manages your workstations is a valuable partner who resets passwords, patches servers, and keeps the office running — they are not watching authentication patterns at 11 p.m. on a Saturday, because nobody hired them to and their business model does not include it.
Meanwhile the attacker’s schedule is the inverse of yours. The compromise happens on a Saturday night, the reconnaissance happens over a holiday weekend, and the fraudulent instruction lands at 4:50 p.m. on a Friday when your team is closing three files at once and nobody has time to make a callback that takes eleven minutes.
Continuous monitoring is a 24/7/365 function. Doing it with people means multiple full-time analysts — a payroll line larger than most independent agencies’ entire technology budget. Outsourcing it to a traditional managed security provider has historically meant enterprise-anchored pricing plus alert forwarding, which relocates the problem rather than solving it: you still receive a queue of notifications that someone at your agency must interpret, and that someone is a closer with four files pending.
So the control gets written into the program because Pillar 3 expects it, the tooling gets purchased because the underwriter asks about it, and the operational half — someone actually reviewing what those tools produce — quietly never happens. That gap is invisible right up until the afternoon it becomes the only thing anyone wants to discuss.
What Detection Looks Like Across the Kill Chain
Consider a realistic compromise against a nine-person agency, and where each stage becomes visible.
- Saturday, 11:20 p.m. — Credential use from an unfamiliar location. A successful sign-in to a processor’s account from an IP address and device never associated with the agency. On its own: possible travel, possible a phone on a cellular network. In context: the first link in a chain.
- Saturday, 11:26 p.m. — Impossible travel. The same account authenticates from two geographies too far apart for the elapsed time. This one has almost no benign explanation, and it is exactly the kind of alert that sits unread in a console until Monday.
- Sunday, 12:04 a.m. — Inbox rule created. A forwarding rule to an external address, plus a rule filing anything matching “wire” into an obscure folder. This is the single highest-fidelity indicator of BEC in existence, and it is generated by the platform your agency already pays for.
- Sunday through Thursday — Anomalous mailbox access. Sustained reading activity outside business hours, concentrated on transaction threads. Individually mundane; as a pattern, reconnaissance.
- Thursday, 3:15 p.m. — Lateral phishing. Messages from the compromised account to other parties in the transaction, seeded to establish the fraudulent thread. Now your agency is the delivery mechanism for the attack on your own client.
- Friday, 4:50 p.m. — The wire instruction. The only step your existing controls are designed to catch — and the only one that depends on a human being under time pressure making the right call.
Notice the shape of it. Your callback procedure defends the last line. Everything before it — five days of visible attacker activity — is defended by nothing, because no one is positioned to see it. And the earlier stages are precisely where intervention is cheap: disabling a compromised session on Sunday morning is a password reset. Discovering the compromise on Friday evening is a claim.
The Same Week, Two Ways
- Unmonitored: Six detectable events accumulate across five days. Nobody reviews them. The wire leaves Friday. The loss is discovered the following Tuesday when the seller asks where the funds are. Recovery odds fall sharply after the first 72 hours.
- Monitored: The impossible-travel sign-in is investigated within minutes of firing. The forwarding rule — created six minutes later — corroborates it. Your designated contact is called Sunday morning with a complete picture. The account is reset, sessions revoked, rules removed, and the transaction proceeds normally. Total cost: one interrupted Sunday.
What Intruex Does About It
Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tools and logs you already have — leading endpoint and cloud security platforms, or nearly any log source via a standards-based interface — and investigates every alert those systems raise, around the clock.
For a title agency, that means the BEC kill chain gets watched at every stage, not just the last one:
- The signals that precede wire fraud are specialties, not afterthoughts. Suspicious sign-ins, impossible travel, off-hours access, new mail-forwarding rules, credential-stuffing patterns — the platform’s analysts are purpose-built for exactly these categories. Every alert is triaged, enriched with threat intelligence, and dispositioned with a confidence level and plain-language reasoning in minutes, not whenever someone next checks a console.
- Correlation is the point. An unfamiliar sign-in is ambiguous. An unfamiliar sign-in followed six minutes later by a forwarding rule on the same account, followed by off-hours access to transaction threads, is not ambiguous at all. Investigating alerts in relation to one another is what turns a list of maybes into a compromise narrative — the same capability we have written about in the context of attack narrative correlation.
- Real threats reach a human immediately. When the evidence says compromise, your designated contact gets an escalation with the full investigation attached: what happened, which account, what the attacker did, and what to do about it. That is the difference between disabling a mailbox on Sunday and explaining a diverted wire on Friday.
- Your audit answers write themselves. Every verdict carries a complete, replayable record — what was reviewed, what was found, who or what acted, and why. When the underwriter asks who reviews system activity and how often, the answer is “every alert, continuously,” and you can show the trail. Intruex also maps monitoring activity to major control frameworks, turning Pillar 3’s documentation burden into a report you pull rather than a project you run.
- Humans stay in charge of anything that matters. Response is recommendation-first and approval-gated; the only autonomous action — closing high-confidence benign alerts — is opt-in, threshold-controlled, and fully audited. Your team sees everything worth seeing and nothing that wastes their day.
None of this replaces your wire-verification procedures, your callbacks to known numbers, your policy of never accepting instruction changes by email, or your staff training. Keep every bit of it — those controls stop the attacks that get through. What monitoring replaces is the assumption, quietly baked into most agencies’ security programs, that detection will somehow happen without anyone staffed to do it.
What to Do This Quarter
Independent of any platform decision, these are the actions worth taking before your next underwriter review:
- Audit every mailbox for forwarding and inbox rules today. Not a sample — all of them, including principals’ and anyone who has left. Then set an alert for new rule creation.
- Turn on and retain authentication logging across your email tenant, title production system, and remote access. If logging is off, an incident cannot be scoped, and an unscopable incident is a worst-case disclosure.
- Enforce phishing-resistant MFA on email first. Email is where the transaction lives; it is the account that matters most and the one most often left on SMS codes.
- Write down who is called at 2 a.m. An incident response plan whose first step is “figure out who to call” has already lost the first hour.
- Extend wire-verification callbacks to instruction changes from any party — realtor, lender, seller — not just buyers, and to changes that arrive in an existing thread.
- Confirm your vendors’ breach notification terms. Your obligations start when you become aware; a vendor who tells you late has spent your clock for you.
- Answer the five underwriter questions above in writing. Where the honest answer is “no one,” you have found your gap, and you have found it before the auditor did.
The Economics Finally Work
The reason independent title agencies have never had real monitoring is not that owners do not care. It is that a 24/7 security function was an enterprise purchase, priced for organizations with security departments, and every attempt to scale it down produced either an unread alert queue or a bill nobody could justify against a closing volume of two hundred files a year.
An AI analyst team changes that arithmetic. Every alert investigated, every verdict explained, escalations only when they are real — documented continuously, at a cost that fits an independent agency rather than a bank. The compliance artifact your underwriter wants and the operational capability that actually protects the escrow account become the same thing, produced by the same process.
The Core Question
If a processor’s email account were compromised at 11:20 p.m. this Saturday — followed by an impossible-travel sign-in, an external forwarding rule at midnight, and five days of quiet reading through your closing files — who at your agency would notice, and on what day? If the honest answer is “when the buyer called about the wire,” the attacker had five days of uncontested access to the most sensitive workflow you operate.
Your escrow account will stay a target. The only variable you control is whether anyone is watching the approach.
Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (BEC and real estate fraud loss figures). ALTA Title Insurance and Settlement Company Best Practices, Pillar 3. FTC Standards for Safeguarding Customer Information (Safeguards Rule), as amended, including the security event notification requirement. Attack sequence described is a composite drawn from publicly documented BEC patterns targeting settlement services, not a specific incident.