How Builders Can Protect Themselves Against a New Type of Fraud 

Account takeovers are growing more common, so builders need stronger controls before funds move.

4 MIN READ

The real estate industry remains a primary target for cybercriminals, with one in every four parties in a transaction now targeted by online crooks—and of those, one in 20 becomes a victim.

While wire fraud and identity theft are familiar threats, a new era of sophisticated tools has escalated the danger. Today’s schemes are more than just deceptive emails; they are multilayered attacks designed to bypass standard security and result in devastating consequences.

For instance, account takeovers are one type of cybercrime that is sharply on the rise. A form of identity impersonation fraud, account takeovers involve cybercriminals impersonating financial institutions to steal money or information. Targets can be individuals, businesses, and organizations of varied sizes. With its high-cost transactions, real estate has emerged as a prime sector for fraudsters to target, with builders of all sizes at risk alongside title and escrow agents.

In an account takeover, cybercriminals impersonate the victim’s financial institution, typically through social engineering techniques, such as texts, calls, and emails, or through fraudulent websites, to gain access to their account. From there, the fraudsters compromise internal systems, capture banking credentials, alter security settings, and ultimately, steal funds directly from the victim’s accounts.

These attacks have been particularly successful because of their multilayered approach. Criminals are sharing keystroke-logging malware, often introduced through a previously compromised transaction party, that captures banking login credentials.

From there, fraudsters change online banking profiles and security protocols and add their own devices to receive multifactor authentication (MFA) codes, allowing them to initiate and approve fraudulent wire transfers directly.

Both the American Land Title Association (ALTA) and the FBI recently issued warnings about account takeovers, with ALTA stressing the “dangerous and increasingly sophisticated” nature of this type of fraud.

This ability to bypass typical protections has led to an uptick in account takeovers and significant financial losses for those affected. ALTA reported that this tactic had led to over $5 million in losses in the first two months of 2026, while the FBI Internet Crime Complaint Center (IC3) reportedly received more than 5,100 complaints regarding account takeover fraud since January 2025, resulting in over $262 million in losses.

Despite the sophistication of account takeover attacks, there are best practices builders can follow to mitigate their exposure and risk.

  1. Require MFA and dual controls for account changes within your financial institution.

Adding extra layers of authentication before allowing any account changes can stall or prevent total takeovers by removing the ability to easily change security settings, initiate or approve wires, and enroll new devices. With multifactor and dual approval, a second authorized user can prevent a fraudster from gaining unilateral control if one user’s credentials are compromised.

ALTA has outlined best practices for identity verification to guide account holders as these types of fraud attempts increase.

  1. Stay cautious even when communications appear to come from trusted sources.

Caution is the name of the game in preventing account takeovers, so make sure to give a closer eye to communications—including emails, texts, and phone calls—even when they appear to come from a trusted party. 

Verify unexpected attachments, details, or requests by calling a known, trusted number, verified independently from the communication you received.

  1. Implement proper internal processes in case something does happen, with clearly defined paths to escalate the issue.

Fraudsters often take advantage of how a sense of urgency affects decision-making, using urgency-inducing language in their communications to prompt the account holder into quick action before they think things through.

Train staff to recognize and be wary of urgency-based manipulation tactics, and if something does happen, follow internal processes to properly escalate the issue. In wire fraud cases, every minute counts, and recovery of funds becomes much harder after the first 24 hours.

As fraud attempts and the technology behind them grow increasingly sophisticated, it’s important to know there are steps you can take to better protect yourself and your business. With account takeovers in particular, the best way to reduce the risk is to remain vigilant, add additional protections, and implement a clearly defined escalation process.

Contact a First American Home Builder Services Division representative today to learn more about fraud risk and how home builders can protect themselves.

Upcoming Events

  • Q3 Housing Market Forecast: Midwest Outlook

    Webinar

    Register Now
  • Turning Builder Data into Mortgage Opportunity

    Webinar

    Register Now
  • What’s Ahead in Housing: Find Your Next Revenue Move

    Webinar

    Register Now
All Events