Victims told the FBI they lost $3.05 billion to business email compromise and $275.1 million to real estate fraud in calendar year 2025, according to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, published in April 2026.1 The controls that stop most of it are plain: confirm every payment instruction by calling a number you already had, never accept a change to wire or deposit instructions by email, protect mailboxes with multi-factor authentication and session controls, and put payment changes through a written two-person procedure. If money goes out anyway, call the sending bank and file at ic3.gov right away, because the FBI's own data shows funds can still be frozen when the report is fast.21
This guide describes what the sources say and what operators typically do. It is not legal advice.
What the FBI's 2025 report shows
The IC3 report covers complaints received from January through December 2025. IC3 took in 1,008,597 complaints with $20.877 billion in reported losses, a 26% increase in losses from 2024.1 Two crime types matter most to brokerages and management firms.
| IC3 crime type | 2025 complaints | 2024 complaints | 2025 losses | 2024 losses | Report pages |
|---|---|---|---|---|---|
| Business email compromise (BEC) | 24,768 | 21,442 | $3,046,598,558 | $2,770,151,146 | 7, 8, 25, 26 |
| Real estate | 12,368 | 9,359 | $275,110,419 | $173,586,820 | 7, 8, 25, 26 |
Source: FBI IC3, 2025 Internet Crime Report.1
By that table, real estate losses rose about 58% in one year and complaints about 32%. BEC was the second-largest loss category behind investment fraud, and its losses work out to roughly $123,000 per complaint, against roughly $22,000 for the real estate category.1
IC3 defines real estate fraud as loss of funds from a real estate investment or fraud involving rental or timeshare property, and it files each complaint under only one crime type (pp. 60, 62).1 A diverted closing wire can land in either bucket; the report itself groups "BEC/Real Estate" together when counting fund-freeze cases and uses that label for one closing case (pp. 18, 23).1 Neither line alone is a full count of real estate wire fraud.
Three more figures are worth showing your team:
- Older clients. Complainants 60 and over filed 2,473 real estate complaints with $123,671,936 in losses, and reported $568,048,472 in BEC losses (pp. 45, 46).1
- AI. Businesses reported more than $30 million in 2025 losses to BEC scams involving AI, including voice cloning used to request wire payments (p. 39).1
- Freezes happen. IC3's Recovery Asset Team ran 3,900 Financial Fraud Kill Chain incidents in 2025 covering $1,163,919,846 in attempted theft and froze $679,013,183, a 58% success rate (p. 17).1
The Federal Trade Commission's data points the same way. People reported losing about $16 billion to fraud in 2025, the highest on record, and $3.5 billion of that to imposter scams.3 Imposter scams were the most reported fraud category for the ninth year in a row, with more than 1 million reports.4 A spoofed title officer, agent or property manager is an imposter scam.
How business email compromise works in a closing
The FBI defines BEC as a scam aimed at businesses or individuals who regularly send wire transfers, carried out by compromising email accounts, phone numbers or virtual meeting apps through social engineering or computer intrusion (p. 59).1 In a sale, the criminal gets into a mailbox on one side of the deal, or registers a lookalike address, reads the thread, and sends "updated" wire instructions near closing day.
The 2025 report describes two closings. In March 2025, a senior citizen in Missouri closing on a property received a compromised email from the "title company" with instructions for a wire of more than $1.3 million to a fraudulent account. In August 2025, buyers received an email impersonating their own attorneys and sent more than $449,000. In that case the buyers' bank and the attorneys could not get the receiving bank to act, but after the buyers filed with IC3, the Recovery Asset Team asked for a freeze and the receiving bank confirmed the full amount was still on hold (p. 23).1
A June 16, 2026 FBI alert describes criminals who impersonate owners of vacant parcels using fake driver's licenses or passports, free email addresses and internet phone numbers, contact a local agent and title company to list and sell the land, and route the proceeds to a co-conspirator attorney in another state.5 Its red flags are checkable at listing intake: a seller who will only communicate by email, text or internet phone and will not meet; pressure to close fast, sometimes below market; thin knowledge of the property and missing surveys or tax records; a request to wire proceeds abroad or to an account in a different name; and deeds notarized in a foreign country.5 It suggests a certified letter to the owner's address on the tax record to confirm the seller is real.5
How it works in property management
Management firms move money on a predictable schedule, which makes them targets. A Federal Reserve analysis lists three ways BEC criminals pull money out of business accounts: deceiving authorized users into sending funds, pretending to be the authorized user, and trying to get added as an authorized party on the account or the banking platform.6
In a management office, that looks like this:
- Owner payee change. An email that appears to come from an owner asks you to send this month's distribution to a new account.
- Vendor invoice redirect. A familiar vendor's invoice arrives with new banking details. The same Federal Reserve piece, citing an industry survey, lists vendor impersonation and third-party impersonation among the most common BEC tactics.6
- Tenant payment redirect. A criminal inside your mailbox, or on a lookalike domain, tells residents that rent now goes to a new account.
Multi-factor authentication is necessary, but 2026 showed it is not enough. In May 2026 the FBI warned about a phishing kit, first seen in April 2026, that tricks users into entering a device code on a real sign-in page, which hands the attacker access tokens to email, chat and file storage without a password or another MFA prompt.7 In September 2026 it warned about "consent phishing," where a user approves a malicious app's access request. That access can only be revoked by invalidating the token in the account's security settings, not by changing the password, and it can bypass both passwords and MFA.8
Controls that stop most diverted payments
No single control stops everything, so firms layer them.
| Control | What it stops | Basis |
|---|---|---|
| Call back to a number already on file before acting on any new or changed payment instruction | Spoofed and compromised email | FBI tells businesses to verify changes in account information through a secondary channel or two-factor authentication2; FTC says to contact the organization using a number you know is real, not one in the message9 |
| Written rule: wire and deposit instructions are never changed by email alone | Last-minute "updated instructions" | Same FBI guidance; make it a disclosed firm policy |
| MFA on email, banking and accounting systems, plus limits on device-code sign-in and review of third-party app consents | Account takeover, token theft | Federal Reserve lists MFA6; FBI recommends restricting device code flow7 |
| Dual approval and pre-agreed code words for payment changes | A single employee being fooled | Federal Reserve lists dual verification and code words6 |
| Positive Pay and ACH blocks on operating and trust accounts | Altered or counterfeit checks, unapproved debits | Federal Reserve describes both as bank-set tools that hold transactions that were not pre-approved for review610 |
| Daily reconciliation and transaction alerts | Late discovery | Federal Reserve check fraud resource10 |
| Show full sender addresses and check them on mobile | Lookalike domains | FBI BEC tips2 |
The callback has to go to a number you already had. A number from the email or a text is part of the scam. Use the number from the signed management agreement, the vendor's onboarding file, or the title company's published main line.
Tell clients in writing, early. Put a short notice in the listing agreement, the buyer representation agreement, the management agreement and the tenant welcome packet: we will never send or change payment instructions by email, and you should call us at a number you already have before you send money. The notice only works if staff never accept an emailed change themselves.
Positive Pay is a bank product. The Federal Reserve describes it as a service the bank sets up for business accounts; its materials do not address trust accounts specifically.610 Ask your bank whether it can cover your trust and escrow accounts. See our trust accounting guide.
Start at onboarding. Collect bank details through a verified channel and record the callback number at the same time. Fold both into your owner onboarding, vendor onboarding and staff onboarding steps.
Listing hijacking and fake rental ads
The FTC describes two versions of the rental scam. In one, scammers copy the photos, description or virtual tour from a real listing, replace the agent's contact information with their own and repost it on another site. In the other, they invent listings for homes that are not for rent or do not exist. Either way they collect an application fee, deposit or first month's rent, or harvest Social Security numbers and pay stubs for identity theft, then disappear.11 The FTC also warns that scammers copy listings from landlords who use self-tour services and send renters a code to the lockbox to make the fraud look real.1112
In a December 2025 Data Spotlight, the FTC said people reported nearly 65,000 rental scams with about $65 million in losses from January 2020 through June 2025, with a median reported loss of $1,000. About half of reports in the year ending June 2025 said the scam started with a fake ad on a single large social media platform, and 16% said it began on an online classifieds site. People 18 to 29 were three times more likely than other adults to report losing money to a rental scam.12 The same Spotlight notes that many real landlords report their listings being copied, and that scam warnings posted inside homes have tipped some renters off.12
What managers typically do:
- Publish every available unit on your own website, with one phone number and one application link. The FTC tells renters to check the rental company's own site and treat a listing missing from it as a possible scam.11
- Say on the listing and on the site that you never take application fees, deposits or rent by wire transfer service, gift card or cryptocurrency. The FTC tells renters that anyone insisting on those methods is running a scam.11
- Post a notice inside self-tour units giving your real contact details and saying the home is not offered anywhere else.
- Search your addresses and photos weekly and report copies to the hosting site, local law enforcement, ReportFraud.ftc.gov and your state attorney general, as the FTC directs.11
Some states now treat this as a serious crime. Florida Statute 817.0311 makes it a first degree felony to list or advertise real property for sale knowing the purported seller has no title or authority, or to rent or lease property knowing you have no ownership or leasehold interest in it. It was created by chapter 2024-44 and amended by chapter 2025-112.13 Texas added Penal Code section 32.57, effective September 1, 2025, which makes it a first degree felony to knowingly list or advertise residential property for sale, rent or lease without title or authority, or to sell, rent or lease it without that title or authority. It gives a licensed broker or agent, lender or title company a defense to the selling and leasing offense if it did not know the other party lacked authority.14
Both statutes turn on what the person knew. A documented identity and title check at intake is how a firm shows it did not know. If a fake listing puts a stranger in a vacant unit, see our squatter laws guide.
The first hour after a fraudulent wire
The FBI's guidance is short: time matters. Work in this order.
- Call the sending bank immediately. The FBI says to contact the originating financial institution as soon as fraud is recognized to request a recall or reversal, along with a Hold Harmless Letter or Letter of Indemnity, and that doing this quickly may reduce or eliminate losses.2 Ask what your bank will do, because the FBI notes that institutions have different policies (2025 report, p. 17).1 If it was a client who wired the money, they make this call to their own bank; you help them do it.
- File at ic3.gov, whatever the amount. The FBI asks for a detailed complaint with full transaction and banking details, because IC3 may be able to help banks and law enforcement freeze funds (2025 report, p. 17).12 Type www.ic3.gov into the browser. In July 2026 the FBI warned that criminals are impersonating IC3 and FBI staff to target people who were already scammed, running spoofed complaint sites and offering to "recover" money. IC3 will never contact victims directly by phone, email or social media, and never charges to recover funds.15
- Call the other parties by phone. Title, escrow, the lender, the other agent and your broker of record need to know that the thread is compromised before anyone else wires money on it.
- Lock the mailbox properly. Reset passwords, sign out all sessions, remove unknown devices and revoke third-party app permissions. The FBI notes that consent phishing access survives a password change until the token is revoked.8
- Preserve evidence. Keep the phishing emails with full headers, suspicious login times and IP addresses, and any unauthorized devices or sessions; these are the details the FBI asks for in reports.7
For a renter who paid a fake landlord by bank transfer, the FTC's advice is the same in substance: report it to the bank or credit union immediately and ask it to reverse the payment, then report it at ReportFraud.ftc.gov.16
Notifying clients and regulators
Breach notice laws can apply even when no money moves. If a criminal got into a mailbox holding tenant applications, the question is whether personal information was accessed. Florida's statute is one example. Its definition of personal information includes a name combined with a Social Security number, a driver's license or passport number, or a financial account number with the code needed to access it, and also a username or email address combined with a password. A covered business must notify each affected Florida resident no later than 30 days after it determines a breach occurred, and must notify the Department of Legal Affairs within 30 days if 500 or more Floridians are affected. Law enforcement can ask in writing for notice to be delayed.17
Other states set their own definitions, deadlines and regulator thresholds, so check your state's statute with counsel. Your real estate commission's trust account rules and your errors and omissions policy may also set reporting steps after a trust account loss. Log those deadlines on your compliance calendar. State license law summaries are at /states.
What to do now: fraud prevention checklist for brokerages and PM firms
Policy
- Adopt a written rule that payment instructions are never created or changed by email alone, and that every new or changed instruction gets a callback to a number already on file.2
- Require a second person to approve any change to owner, vendor or tenant payment details, and agree on code words with high-value clients.6
- Add the "we never change wiring instructions by email" notice to every agreement, welcome packet and email signature.
Accounts and systems
- Turn on MFA for email, banking and accounting systems.6
- Restrict device-code sign-in and review third-party app permissions on every mailbox every quarter.78
- Ask your bank about Positive Pay and ACH blocks on operating, trust and escrow accounts.610
- Reconcile accounts daily and turn on transaction alerts.10
Listings and intake
- Verify the identity and title of every new seller or owner client, and be wary of the seller who will not meet, wants speed and wants proceeds sent abroad.5
- Publish every vacancy on your own site, state your accepted payment methods, and post contact notices inside self-tour units.1112
- Search your addresses and photos every week and report copies.11
Incident response
- Keep a one-page card at every desk: bank fraud line, ic3.gov, broker of record, IT contact, title contacts.2
- Train staff every quarter on the closing and owner-payment scripts in this article, including AI voice requests.1
Sources
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2026, April 16). 2025 IC3 annual report (Internet Crime Report covering complaints received January 1 to December 31, 2025). Retrieved October 7, 2026, from https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- Federal Bureau of Investigation, Internet Crime Complaint Center. (n.d.). Business email compromise (BEC). Retrieved October 7, 2026, from https://www.ic3.gov/CrimeInfo/BEC
- Federal Trade Commission. (2026, June 15). FTC data show people reported losing $3.5 billion to imposter scams in 2025 [Press release]. Retrieved October 7, 2026, from https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
- Federal Trade Commission. (2026, May). New trends in reports of imposter scams [Consumer alert]. Retrieved October 7, 2026, from https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2026, June 16). Protect your property from illegal sales through parcel owner impersonation (Alert No. I-061626-PSA). Retrieved October 7, 2026, from https://www.ic3.gov/PSA/2026/PSA260616
- Federal Reserve, FedPayments Improvement. (2025, December 8). From insight to action: Classifying ACH and wire fraud for better defenses against business email compromise. Retrieved October 7, 2026, from https://fedpaymentsimprovement.org/news/blog/from-insight-to-action-classifying-ach-and-wire-fraud-for-better-defenses-against-business-email-compromise/
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2026, May 21). Kali365 phishing-as-a-service kit hijacks [cloud productivity suite] access tokens (Alert No. I-052126-PSA). Retrieved October 7, 2026, from https://www.ic3.gov/PSA/2026/PSA260521
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2026, September 1). Malicious cyber actors gain access to victim accounts through consent phishing (Alert No. I-090126-PSA). Retrieved October 7, 2026, from https://www.ic3.gov/PSA/2026/PSA260901
- Federal Trade Commission. (n.d.). How to avoid imposter scams. Retrieved October 7, 2026, from https://consumer.ftc.gov/features/how-avoid-imposter-scams
- Federal Reserve, FedPayments Improvement. (2025). Preventing check fraud: A resource for businesses. Retrieved October 7, 2026, from https://fedpaymentsimprovement.org/wp-content/uploads/preventing-check-fraud-a-resource-for-businesses.pdf
- Federal Trade Commission. (2026, June). Rental listing scams. Retrieved October 7, 2026, from https://consumer.ftc.gov/articles/rental-listing-scams
- Federal Trade Commission, Division of Consumer Response and Operations. (2025, December 22). Rental scams hit home with $65 million in reported losses [Data Spotlight]. Retrieved October 7, 2026, from https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/12/rental-scams-hit-home-65-million-reported-losses
- Florida Legislature. (2026). Section 817.0311, Florida Statutes: Fraudulent sale or lease of real property. Retrieved October 7, 2026, from http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0800-0899/0817/Sections/0817.0311.html
- Texas Legislature. (2025). S.B. No. 1333, enrolled version, 89th Legislature, Regular Session (adding Penal Code sections 32.56 and 32.57). Retrieved October 7, 2026, from https://capitol.texas.gov/tlodocs/89R/billtext/html/SB01333F.htm
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2026, July 20). FBI warns of scammers impersonating the IC3 (Alert No. I-072026-PSA). Retrieved October 7, 2026, from https://www.ic3.gov/PSA/2026/PSA260720
- Federal Trade Commission. (2026, June). What to do if you were scammed. Retrieved October 7, 2026, from https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
- Florida Legislature. (2026). Section 501.171, Florida Statutes: Security of confidential personal information. Retrieved October 7, 2026, from http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0500-0599/0501/Sections/0501.171.html
Published October 7, 2026. Updated October 7, 2026. Laws change. Each rule shows its source and the date it was last checked. Read the statute and talk to a local attorney before acting. Report a correction.