Security
Protecting Deposits From Phishing and Wire Fraud: A Realtor's Playbook
A practical playbook for agents to stop fake payment instructions, spoofed emails and compromised inboxes from putting a client's deposit at risk.
Few moments in real estate are as tense as a deposit or closing payment. A large sum, a tight deadline and a trusting client are exactly what fraudsters look for. The usual attack is not a technical masterpiece. It is an email that looks like it came from a lawyer, a notary or you, with new payment instructions that arrive at the worst possible time. This playbook explains how these scams work and gives you a set of habits and settings that make them much harder to pull off.
How the scam usually works
Attackers either break into a mailbox, often through a stolen password or a phishing page that looks like a real login, or they create a lookalike address that differs by a single character. Once inside the conversation, they watch for an upcoming payment and then send a polite message with updated bank details.
Because the email sits in a genuine thread, uses the right names and refers to real dates, it looks normal. By the time anyone notices, the money may have moved through several accounts. Quick action is vital, but prevention is far cheaper.
Rule one: verify by phone, every time
The strongest control is a human habit: any new or changed payment instruction is confirmed by calling a phone number you already trust, such as one from your own records or the firm's official website, never one in the email. Tell your clients about this rule at the start of every deal and put it in writing in your onboarding message.
Make it social, not awkward. 'We always confirm payment details by phone' is a normal professional statement, and clients usually appreciate it.
Lock down your own inbox
Turn on multi-factor authentication for email, using an authenticator app or passkey rather than text messages where possible. Use a unique, strong password stored in a password manager. Check your mailbox rules and forwarding settings regularly, because attackers often add hidden rules that copy or hide messages.
Publish email authentication records for your domain, known as SPF, DKIM and DMARC. They make it much harder for criminals to send messages that appear to come from your address, and they help your genuine emails reach inboxes.
Spot the warning signs
Be suspicious of urgency, secrecy and changes. Watch for subtle address differences, unexpected attachments, requests to move to a different channel and sign-in pages reached through email links. When in doubt, open the site by typing the address yourself rather than clicking.
Share examples with your team. A five-minute monthly look at a recent suspicious message teaches more than a long annual lecture.
Have a response plan before you need it
If you suspect fraud, speed matters. Contact your bank and the receiving bank immediately, then tell your brokerage, the lawyer or notary and the police. Change passwords, sign out all sessions and review mailbox rules from a trusted device. Report the incident as your brokerage and regulator require, and keep records.
Print a one-page card with the phone numbers you need. In the middle of a crisis, nobody wants to search for them.
Build safe habits into your process
Add the verification step to your checklist, send clients a short fraud warning at the start of every transaction and avoid sending sensitive documents as plain attachments where a secure link is available. Keep software and devices updated, and use separate browsers or profiles for banking and general browsing if it helps.
No set of measures can guarantee that an attack will never succeed. The aim is to make you a harder target than the next agent and to limit the damage if something does go wrong.
Your checklist
- Turn on multi-factor authentication for email and CRM
- Use a password manager with unique passwords
- Publish SPF, DKIM and DMARC for your domain
- Review mailbox rules and forwarding every month
- Tell clients: payment changes are confirmed by phone
- Keep a printed incident contact card
- Run a short phishing example review each month
Where this fits in your tech plan
Good guidance works best as part of a joined-up setup rather than a one-off fix. These RealtyIT services address the topic of this guide directly.
Cyber Protection for Agents
Cyber protection for agents focuses on the threats that really hit real estate: fake wire instructions, spoofed lawyer emails, credential theft and ransomware. We combine simple tools with habits you can keep up while you are busy.
Closings move large sums of money on short deadlines, which makes agents and their clients attractive targets. Most attacks succeed through a rushed click or a believable email, so training and a verify-by-phone rule matter as much as software.
See the Cyber Protection for Agents service →Email & Calendar Security
Your email is the keys to every deal. We turn on multi-factor sign-in, publish SPF, DKIM and DMARC so nobody can easily fake your address, and watch for the hidden forwarding rules attackers use to quietly read your mail.
Wire-fraud scams against real estate usually begin with a compromised or spoofed inbox. A few hours of setup closes the most common doors and gives you a clear drill for the moment something looks wrong, which is when most of the damage can still be stopped.
See the Email & Calendar Security service →Mobile Device Management
Mobile device management (MDM) lets a team or brokerage apply the same safety rules to every phone that touches client data, without peeking at personal photos or messages. We set it up with plain-language rules agents can live with.
Agents run their business from a phone. That phone has your CRM, your email, your signing apps and your client list. If it is lost or an agent leaves, you need a clean way to remove business data without a fight over personal devices.
See the Mobile Device Management service →Want help putting this in place?
RealtyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with friendly, hands-on tech support for agents. If this topic matches something you are wrestling with, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-English view of your options and a fixed price if you want us to do the work.
Quick answers
What should I do if a client already sent money?
Call the client's bank and the receiving bank immediately, then notify your brokerage, the lawyer or notary and the police. Speed improves the chance of recovery.
Does DMARC stop all fake emails?
No, but it makes it much harder to spoof your exact domain. Lookalike domains and compromised accounts still need other controls.
Are text-message codes safe enough?
They are better than nothing, but authenticator apps and passkeys are stronger.
Should clients be warned in writing?
Yes. A short written notice at the start of each transaction sets expectations and makes verification feel routine.
Can RealtyIT run a drill for my team?
Yes. Our Cyber Protection for Agents service includes a wire-fraud drill and a call-back script.
Keep exploring
- Google Workspace for RealtorsService
- Microsoft 365 for RealtorsService
- Email & Calendar SecurityService
- Team Onboarding TechService
- Real Estate TeamsSector
- New AgentsSector
- New Licensee Laptop and Phone Setup: A First-Week GuideInsight
- AI Assistants for Showing Scheduling: What Works and What to AvoidInsight
- Speed-to-Lead Automation for Realtors: Reply in Minutes, Not HoursInsight
- IT support in CoquitlamLocation