Wire fraud took $446 million from US real estate transactions in 2024. Miami is a top-3 target market because of foreign-buyer volume and rapid closings. Here's the exact 2026 attacker playbook against Miami agents — and how to actually stop it.
Step 1: Inbox compromise (where it always starts)
Attacker buys a stolen credential on the dark web for ~$80, or phishes an agent into entering their M365 password on a fake login page. They access the inbox via web Outlook from a residential IP they bought to look local.
Step 2: Reconnaissance (silent, 2-6 weeks)
They don't act immediately. They install auto-forwarding rules to a hidden mailbox, watch for closing-related emails, identify the title company, the loan officer, the buyer's email address. They take notes on writing style, signature, when the agent typically emails.
Step 3: The intercept (timing is everything)
When the title company sends wire instructions to the buyer, the attacker:
- Deletes the legitimate email from the buyer's view via auto-rule
- Sends a replacement from a spoofed agent address with attacker-controlled wire instructions
- Includes the exact buyer name, property address, closing date — pulled from earlier emails
- Buyer wires $400K to the attacker's mule account, thinking it's the title company
Step 4: Cash-out (under 6 hours)
The mule wires to a Bitcoin exchange. The Bitcoin is moved through mixers. By the time the buyer realizes — usually when they call the title company to confirm — the money is gone, untraceable.
Who pays?
Almost always the buyer. Insurance might cover some. Then the buyer sues the brokerage. The brokerage's E&O insurance gets pulled in. Legal fees alone hit $50-200K even if you win.
The 5 controls that actually stop this
1. DMARC enforcement on your domain (free)
Prevents anyone from spoofing emails from @yourbrokerage.com. Without DMARC, attackers can send mail "from" you that lands in inboxes. With DMARC enforced, those mails go straight to spam or bounce. Setup: 1 hour for someone who knows DNS.
2. Phishing-resistant MFA for every agent (cheap)
Not SMS MFA — attackers SIM-swap that. Use a real authenticator app (Microsoft Authenticator, Authy) or, better, a YubiKey for every agent. Microsoft Defender for Office 365 + conditional access blocks 99% of inbox-takeover attempts.
3. Conditional access by country (free with M365)
Your Miami agents shouldn't be logging in from Lagos. Set up conditional access policies that block sign-ins from countries you don't operate in. Auto-block + alert.
4. Verbal wire confirmation policy (free, hardest)
Mandate: every buyer must call the title company at a number from a separate source (not from the email) to verbally confirm wire instructions before sending. This single rule stops almost all consummated frauds. Get it in the buyer's contract.
5. Monthly phishing simulation for the team (low cost)
Microsoft Attack Simulator or KnowBe4. Send realistic fake phishing to your team monthly. Track who clicks. Train repeatedly. We see click rates drop from ~28% to ~3% in 6 months.
What we deploy for Miami real estate clients
Standard managed package:
- M365 Business Premium with DMARC enforced and Defender for O365 in Strict mode
- Conditional access blocking 200+ high-risk countries
- YubiKeys for managing brokers, soft MFA for agents
- Monthly phishing simulations + quarterly training
- Annual tabletop exercise on what to do when a wire fraud is attempted
If you run a Miami brokerage, please at least do #1 (DMARC) this week. See our real estate IT package or call (786) 422-0705 for a free 30-min vulnerability audit.