Showing posts with label transactions. Show all posts
Showing posts with label transactions. Show all posts

Tuesday, December 29, 2015

HACKERS CONTINUE TO PERPETRATE WIRE TRANSFER FRAUD IN REAL ESTATE TRANSACTIONS



About one year ago, our column dealt with the subject of wire transfer fraud in real estate transactions. Regrettably, the topic is still a current one. On December 15, NAR issued an alert on the subject. Anecdotally, incidents have increased in the Southern California area. The nature of the scam is unchanged, so what was said last year is still on point. It goes as follows.

Wire transfer instructions are emailed to the buyer. The buyer complies with the instructions to the letter. The next day, escrow contacts the buyer asking if the money has been sent yet. The buyer checks with his bank and is assured that the funds have been transferred out. When the money has still not shown up, everyone begins to retrace steps. As it turns out, the wiring instruction was bogus. The email came from an address that looked very much like that of the escrow or title company, but it was not actually theirs.

And the recipient bank account? It was real; it just wasn't the correct one. And, yes, it has been emptied out by now.

The scheme has been perpetrated by hackers, and it has been going on around the country for a while now. Chicago Title put out an alert that described the steps involved. We summarize them here:

First, hackers identify the email accounts of real estate agents and brokers. Then they hack directly into the accounts "and identify emails referencing pending real estate deals. From these strings of emails, the hackers pull out specific details about the deal, such as: (a) the parties' names, (b) the title company involved, (c) the escrow officer in charge of the deal, and (d) other information specific to the transaction."

Next, they send fraudulent email "directly to the buyer or lender, making it look like it was sent by the real estate agent, mortgage broker, or escrow agent. These fraudulent emails now direct the buyer and/or lender to wire the funds necessary to close escrow directly to a different bank account than provided in the preliminary report or in the escrow instructions. Obviously, this new bank account is controlled by the hacker, not the title company or the escrow holder."

Then, if the buyer, or the lender, does not detect the fraud, "the money is wired to the bogus account controlled by the hacker and is immediately withdrawn. Due to the amounts involved and the complex nature of investigating and prosecuting wire fraud, the odds are that the authorities will do nothing to help in these instances." [my emphasis]

For the most part, prevention recommendations tend to focus on the non-secure nature of most email accounts. It's a fair bet that most real estate agents do not have secure accounts and they can be easily hacked. But, in a world where Target, Sony, and the Defense Department get hacked, it is not plausible to think that most agents, escrow companies, and clients are ever going to enjoy a very high level of security.

While suggestions like two-factor authentication and encrypted emails may have their place, it is refreshing that a practical, non-technical word of advice comes from, of all places, an alert put out by the Silicon Valley Association of REALTORS®. To wit:

"Buyers and sellers should confirm all email wiring instructions directly with the escrow officer by calling the escrow officer on the telephone. In that conversation, the correct account number information should be repeated verbally before taking any steps to have the funds transferred."

Certainly, if wiring instructions are changed via email, the buyer should confirm that by phone with the escrow officer and the buyer's real estate agent.

Source: RealtyTimes, Bob Hung
http://realtytimes.com/consumeradvice/buyersadvice1/item/41183-20151229-hackers-continue-to-perpetrate-wire-transfer-fraud-in-real-estate-transactions

Tuesday, November 17, 2015

Cybercriminals Targeting Real Estate Transactions


It used to be banks and major retailers that were the target of cyber criminals, but now it seems they are also setting their sights on us Realtors. As an active real estate agent who has closed numerous deals, I know there is a wealth of data that is accumulated during the course of a real estate transaction, but I use encryption to protect that data. Be that as it may, I know of many agents who aren't as tech savvy who are putting their clients at risk by being careless with their information.

SAN DIEGO, Nov. 14, 2015 /PRNewswire/ -- Small real estate businesses, agents and their clients are fast becoming the targets of sophisticated cyber scammers. That's according to panelists at the Risk Management and License Law Forum yesterday at the 2015 REALTORS® Conference & Expo, who discussed potential threats and offered tips for agents to protect themselves and their businesses and clients from cyber-attacks.

Melanie Wyne, National Association of Realtors® technology policy expert said that while we often hear in the news about large companies falling victim to hackers, small businesses, which often lack the vast technology and legal teams of larger businesses, actually account for the majority of attacks. "Small businesses need to pay just as much attention as large companies to possible cyber threats," she said.

Darity Wesley, founder of the Lotus Law Center, said hackers are seeking personally identifiable information, data that could potentially identify a specific individual, such as credit card or bank account information, login credentials, employment details or a physical address, e-mail address, and phone or social security number.

"Most people don't know the vast amount of data stored about them in a variety of systems," said Wesley. "Identity thieves can do a lot of damage with this information; your credit and whole life could be ruined."

Wyne said data breaches can impact real estate businesses in three main ways: businesses can suffer from financial harm from expenses resulting from the breach; legal risks from lawsuits from clients or others impacted by the hack; and reputational risks from having to publicly disclose the hack. She said commercial properties are also vulnerable from hacks into their automated or building control systems.

While cloud and free email services are convenient for business they are never completely secure, and Wyne recommended that Realtors® research the level of security those companies are employing before using their services and storing information or documents into them. She also recommended that agents ask these services to be indemnified in the service is hacked. Wesley said anyone using a free email service for business should encrypt emails with client data; she recommended visiting lifehacker.com (then search on "encryption") for great tips for encrypting emails.

Jessica Edgerton, NAR associate counsel shared that in recent months, real estate professionals have reported an upswing in a particular wire scam, where a hacker breaks into an agent's email account and obtains information about upcoming real estate transactions. After monitoring the account, the hacker will send an email to the buyer as he or she nears closing, posing as the agent or someone from the title company and requesting that the buyer wire transaction-related funds. Edgerton recommended that agents inform their clients at the beginning of any transaction about this scam and that if buyers do receive an email about wiring funds that they immediately call the agent on the phone.

Currently, the majority of laws governing data security are at the state level, although NAR has been advocating federal law for years. Therefore, Wyne also said it's important for agents to know the state laws regarding data security and privacy that affect their organization, especially since some states have enacted laws that require businesses to have proactive security programs in place.

All of the speakers recommended strong passwords and developing a data security program and implementing and maintaining safeguards to protect private data. A privacy policy disclosing some or all of the ways the business collects, shares, protects, and destroys personal client information is also a good business practice.

Source: National Association of Realtors
http://www.prnewswire.com/news-releases/cybercriminals-targeting-real-estate-transactions-300178856.html