← Sep 22 Tuesday, September 22, 2026 Latest →
22
Tuesday
September 2026
7 min read

Seller Impersonation Fraud Is Evolving. Is the Mortgage Industry Evolving Fast Enough?

AI, business email compromise and increasingly sophisticated identity fraud are changing the risk profile of mortgage closings. Lenders need to rethink what “verification” means before the money moves.  

For years, the mortgage industry has spent a lot of money on spotting borrower fraud at the start of the loan process. But one of the growing fraud threats today may show up later—when the loan is approved, the closing is set, and hundreds of thousands of dollars are about to move.

Seller impersonation fraud and business email compromise and wire diversion schemes are coming together into a closing-table threat. AI is making that threat more sophisticated.

The numbers show that this is not just a theoretical problem.

The FBI’s Internet Crime Complaint Center reported that $20.9 billion in internet-crime losses were reported in 2025 for a 26 percent increase from 2024. Business email compromise alone accounted for $3 billion in reported losses during that year.

The FBI has described business email compromise as a $55 billion scam calculating than $55.4 billion in exposed losses from domestic and international incidents reported between October 2013 and December 2023.

For mortgage lenders, the message is clear: the closing table has become a cybersecurity perimeter.

Seller impersonation is accelerating

Seller impersonation fraud generally involves a criminal pretending to be the owner of a property and trying to sell or otherwise transact against property that the criminal does not own.

The American Land Title Association’s latest research shows how quickly the problem is evolving.

ALTA’s 2026 Seller Impersonation Fraud Study, based on answers from 245 title professionals in 40 states the District of Columbia and the U.S. Virgin Islands found that 59 percent of firms had least one seller impersonation attempt in 2025. That is than double the 28 percent reported in ALTA’s earlier study.

More concerning 45 percent reported an attempt in the month before compared with 19 percent in earlier research. Among firms that reported a fraud attempt one in four also reported a paid claim linked to seller impersonation. Of those that disclosed claim costs half reported costs above $100,000.

MBA NewsLink previously highlighted the earlier ALTA findings that 28 percent of title companies had at least one seller impersonation attempt in 2023.

This means lenders should not see seller impersonation as a title company problem. If a fraudulent seller reaches closing the lender, settlement agent, title insurer, warehouse provider and consumer can all be part of—and potentially victims of—the compromised transaction.

AI changes the economics of fraud

Intelligence adds another dimension.

The old warning signs of fraud—a written email, awkward grammar, a questionable identification document or an implausible explanation—are becoming less reliable.

Generative AI can help criminals produce letters imitate professional communications and quickly create transaction-specific stories. Synthetic images, altered documents, AI-generated voices and advanced video technology mean that a phone call or video conference should not automatically be treated as proof of identity.

Criminals can gather available property and personal information create a convincing identity profile and talk to transaction participants in a way that looks increasingly legitimate.

The industry’s response cannot simply be “We spoke to the seller.”

The better question is: What independent data confirms that the person we spoke with is actually the property owner?

Business email compromise remains the gateway

AI may be changing fraud. One of the industry’s most persistent weaknesses remains familiar: email.

FinCEN describes business email compromise schemes as attacks against organizations that routinely do wire transfers and rely on email. In estate criminals may compromise—or convincingly impersonate—trusted parties and then change payment instructions.

FinCEN’s analysis of real-estate business email compromise found that the common victims were people and entities in the title and closing process. 88 Percent of incidents first sent fraudulent money to accounts at U.S. Depository banks showing that employees cannot assume a domestic bank account makes instructions legitimate.

The FBI has documented the real-estate connection. From 2020 to 2022 reports of business email compromise incidents, with a real-estate link rose 27 percent while reported losses rose 72 percent. Reported losses reached about $446 million in 2022.

The MBA has also been sounding the alarm. At the 2025 Compliance and Risk Management Conference representatives from law-enforcement talked about the mortgage industry’s exposure to fraud. An FBI supervisory special agent highlighted BEC that targets home closings, where victims are tricked into wiring transaction funds to criminals.

Employee training may be the overlooked control.

Technology matters. Lenders should not think that technology alone can stop these attacks.

Criminals often use behavior instead of breaking security systems. They create urgency. They impersonate parties. They slip into email conversations. They wait until closing, when employees feel pressure to get the transaction funded.

That turns employee training into an issue, not just a cybersecurity exercise.

Funding, closing, post-closing, accounting, warehouse, servicing and vendor-management personnel should learn to spot flags. These flags are changes to wire instructions slightly altered email domains, changes in beneficiary names or banks, unusual urgency requests to skip normal procedures, and instructions that tell employees to use a new telephone number or email address.

One rule must be very clear:

Wire instructions should never be changed only because an email says they have changed.

The FBI recommends using a communication channel or two-factor authentication to check changes in account information.

Verification should happen through a set independently checked communication channel—not the telephone number, link or email address that appears in the message asking for the change.

The solution is verification.

The industry must go past identity verification and move toward identity, counterparty, and transaction verification.

That means checking the seller’s relationship to the property validating settlement professionals checking bank-account data spotting transaction anomalies authenticating changes to wire instructions and setting up escalation steps that let employees halt transactions before funds leave the institution.

ALTAs latest research backs that layered approach. Ninety-four percent of firms that responded used fraud-detection tools which they found helpful averaging 5.3 tools per firm. Identity verification, direct seller contacts, and multifactor authentication were among the rated defenses.

There is another lesson in the government’s recovery statistics: speed matters after a fraudulent wire is found.

FinCEN said in April 2026 that its Rapid Response Program had stopped $1.8 billion in stolen funds since it began, including about $425.2 million linked to business email compromise. FinCEN stresses the need to report cyber-enabled fraud quickly to law-enforcement so that authorities can freeze or recover stolen funds.

Recovery should be the last line of defense.

The better strategy is to stop the wire from being misdirected in the first place.

Mortgage lenders have spent decades building systems to decide if a borrower, property and loan are acceptable for credit and collateral risk. The next step is to apply the discipline to the people, companies, and payment instructions around the closing.

Because in an AI-enabled fraud world seeing a driver’s license is not enough. Getting an email is not enough. Hearing a voice is not enough. And increasingly, even seeing someone on a screen may not be enough.

Trust at the closing table must come from verified data.

For mortgage lenders, that quickly becomes the difference between completing a transaction and financing a fraud.

Sources: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report and BEC public-service advisories; Financial Crimes Enforcement Network, Business Email Compromise in the Real Estate Sector and Rapid Response Program data; American Land Title Association, 2026 Seller Impersonation Fraud Study; and Mortgage Bankers Association/MBA NewsLink industry reporting.

Get the Commentary

80,000+ mortgage professionals get this every weekday morning.


By submitting this form, you are consenting to receive marketing emails from: . You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact