The email looks exactly right. Right sender name, right signature block, right tone — maybe even a real prior thread quoted underneath it. It says the bank changed, or the title company switched processors, or the draw account needs to be updated before Friday's disbursement. Someone on the finance side updates the wire instructions, sends the payment, and the money is gone in minutes. No malware was involved. No firewall was breached. The email account was real — it just wasn't being used by the person everyone thought.
This is business email compromise, and it's become one of the most costly forms of cybercrime for exactly the industries that move money the way construction and real estate do: large sums, tight deadlines, and deals that run almost entirely over email between people who may never meet face to face.
Why This Industry Is a Preferred Target
Attackers don't chase every business equally — they chase the ones where a single successful email produces a large payout, fast. Construction and real estate check every box:
- Big, routine wires. Draw requests, closing funds, subcontractor payments, and earnest money all move as normal business, not as rare, scrutinized events.
- Deadline pressure. Closings and draw schedules run on hard dates, which pushes people to act fast and double-check less.
- Fragmented communication. A single deal can involve a buyer, seller, agent, title company, lender, and general contractor — all emailing each other, all trusting that the person on the other end is who they claim to be.
- Public deal information. Permit filings, MLS listings, and project announcements make it easy for an attacker to identify an active deal and time an attack around it.
The real takeaway
BEC doesn't fail because someone was careless. It works because the email genuinely looks legitimate — often from a real, compromised account with real prior history. The defense isn't "read more carefully." It's a verification step that doesn't rely on email at all.
How the Attack Actually Unfolds
Most BEC attacks follow a similar pattern, whether the target is a general contractor, a real estate brokerage, or a title company:
- Access. The attacker gets into a real inbox — usually through a phished password with no MFA in the way — belonging to someone in the deal chain: a vendor, an agent, an executive assistant.
- Observation. Rather than acting immediately, they often sit quietly, reading email traffic to learn the deal timeline, the dollar amounts, and how the people involved normally communicate.
- The switch. Right before funds are due to move, they send new wire instructions — from the real account, or a lookalike domain one character off — timed to arrive when someone's rushing to hit a deadline.
- The wire. Once money leaves via wire transfer, it's typically gone within minutes and almost never recoverable, unlike a check or a card charge.
What Actually Stops It
None of this requires expensive technology to defend against. It requires a process that doesn't trust email alone to authorize money movement:
- Callback verification. Before sending or changing any wire, call a phone number you already have on file — never one provided in the email — and confirm verbally with a known contact.
- Multi-factor authentication on every email account with access to financial communications, so a phished password alone isn't enough to get in.
- A written policy that no wire instructions are ever changed or accepted based on an email request alone, no exceptions, no matter how urgent it sounds.
- Domain monitoring to catch lookalike domains (a swapped letter, an extra hyphen) registered to impersonate your firm, your title company, or your bank.
Questions worth asking this week
- Do we have a written rule that wire instructions are never changed based on email alone?
- Is MFA enabled on every email account tied to a deal, draw, or closing?
- Would our finance team know to call a known number, not one from the email, before sending a large wire?
- Have we ever checked whether a lookalike domain of our company name has been registered?
What to Do Next
Most firms don't find out their email security has a gap until after a wire is already gone. An IT Risk Assessment reviews exactly the controls that stop BEC — MFA coverage, email authentication, and account access — before it becomes a six or seven figure loss. If your firm handles closings, draws, or subcontractor payments, our Construction & Real Estate IT services are built around exactly this risk.