The email looks exactly right. Right sender name, right signature block, right tone — maybe even a real prior thread quoted underneath it. It says the bank changed, or the title company switched processors, or the draw account needs to be updated before Friday's disbursement. Someone on the finance side updates the wire instructions, sends the payment, and the money is gone in minutes. No malware was involved. No firewall was breached. The email account was real — it just wasn't being used by the person everyone thought.

This is business email compromise, and it's become one of the most costly forms of cybercrime for exactly the industries that move money the way construction and real estate do: large sums, tight deadlines, and deals that run almost entirely over email between people who may never meet face to face.

Why This Industry Is a Preferred Target

Attackers don't chase every business equally — they chase the ones where a single successful email produces a large payout, fast. Construction and real estate check every box:

The real takeaway

BEC doesn't fail because someone was careless. It works because the email genuinely looks legitimate — often from a real, compromised account with real prior history. The defense isn't "read more carefully." It's a verification step that doesn't rely on email at all.

How the Attack Actually Unfolds

Most BEC attacks follow a similar pattern, whether the target is a general contractor, a real estate brokerage, or a title company:

  1. Access. The attacker gets into a real inbox — usually through a phished password with no MFA in the way — belonging to someone in the deal chain: a vendor, an agent, an executive assistant.
  2. Observation. Rather than acting immediately, they often sit quietly, reading email traffic to learn the deal timeline, the dollar amounts, and how the people involved normally communicate.
  3. The switch. Right before funds are due to move, they send new wire instructions — from the real account, or a lookalike domain one character off — timed to arrive when someone's rushing to hit a deadline.
  4. The wire. Once money leaves via wire transfer, it's typically gone within minutes and almost never recoverable, unlike a check or a card charge.

What Actually Stops It

None of this requires expensive technology to defend against. It requires a process that doesn't trust email alone to authorize money movement:

Questions worth asking this week

  • Do we have a written rule that wire instructions are never changed based on email alone?
  • Is MFA enabled on every email account tied to a deal, draw, or closing?
  • Would our finance team know to call a known number, not one from the email, before sending a large wire?
  • Have we ever checked whether a lookalike domain of our company name has been registered?

What to Do Next

Most firms don't find out their email security has a gap until after a wire is already gone. An IT Risk Assessment reviews exactly the controls that stop BEC — MFA coverage, email authentication, and account access — before it becomes a six or seven figure loss. If your firm handles closings, draws, or subcontractor payments, our Construction & Real Estate IT services are built around exactly this risk.