Managed IT for title companies that stops wire fraud.
Title company cybersecurity and ALTA Best Practices controls for firms where every closing moves a large wire on a predictable schedule. One compromised inbox can redirect a high-six-figure transfer before anyone picks up a phone.
What a wire fraud actually costs a title company
In one closing we responded to, an attacker took over a closer’s inbox and sent fraudulent wire instructions on a real pending transaction: a high-six-figure wire, moving on a real deadline, to the wrong account. We documented the entire response in our BEC wire fraud incident report. That is the scenario every title company is one bad login away from, every single day it has closings on the calendar.
The math is brutal because there’s no partial version of this loss. A wire that clears to a fraudulent account is gone. Recovery through the bank’s fraud department is possible in the first hours, unlikely after that. Beyond the money: a lost closing, a client relationship that doesn’t survive the story, a call to your E&O carrier, and in most states a breach notification review. None of that is optional once the wire clears.
Why title companies specifically get targeted
Attackers target title and escrow companies because the transaction structure does the targeting for them: a large, time-sensitive wire, coordinated by email, between parties who have often never spoken by phone. Compromise one mailbox (a closer, an escrow officer, a lender’s loan coordinator) and you have visibility into which deals are closing this week and for how much.
In our BEC case, the attacker didn’t send one fraudulent email and disappear. They stayed logged into the account and created mail-blocking rules against the firm’s funding desk and a coworker who would have caught the fraud, an attempt to keep the scheme alive long enough for the wire to actually move. That’s the pattern we look for in every closing-day compromise: not just the fraudulent email, but the filters and forwarding rules an attacker sets up to keep watching.
Where the door was left open
The entry point in that incident was multi-factor authentication enrolled but not enforced at the tenant level. The account “had 2SV” in the sense that the user had set it up, but Google Workspace only challenges for 2SV when a sign-in looks suspicious, and the attacker’s login never tripped that heuristic. Password alone got them in. That gap (the difference between MFA turned on for a user and MFA enforced across a tenant) is one of the most common findings we see auditing title company email systems, and it is entirely closable before it costs anyone a closing.
What does ALTA Best Practices cybersecurity actually require?
The American Land Title Association Best Practices framework exists largely because of title company wire fraud. Pillars on wire fraud prevention and information security call for:
- Verified, out-of-band confirmation of any change to wire instructions
- Documented information security controls (not a one-page policy in a drawer)
- An incident response plan underwriters and lenders can review
- Technical measures that make spoofed sender domains harder to pull off
We build ALTA Best Practices cybersecurity as real controls: enforced MFA (tenant-wide, not optional), email authentication (DMARC/SPF/DKIM), monitoring for mailbox rules and odd logins, and the documentation trail a Best Practices review expects to see. That is managed IT for title companies, not a binder of unused policies.
Is it safe to wire money through a title company?
The wire itself is how real estate closes. The risk is not “title companies are unsafe”; it is unsecured email and weak remote-access habits around that wire. Safe practice is out-of-band verification to a number on file before funds move, plus email and identity controls that make BEC harder. We document that program and run the IT underneath it.
How Limehawk builds the wire fraud prevention program
Every title company we work with gets the same baseline, then we layer on what the firm’s transaction volume and closing software require:
- Enforced MFA, tenant-wide. Not optional, not per-user opt-in.
- Email authentication and filtering, DMARC/SPF/DKIM plus the core security suite’s email filtering included in every managed plan.
- Out-of-band wire verification procedures, documented steps for confirming any change to wire instructions by phone, to a number on file, before funds move.
- Monitoring for compromise indicators, mailbox forwarding rules, new inbox filters, and sign-ins from unexpected locations, the exact signals that showed up in our BEC case.
- Staff training, closing-day social engineering recognition for the people who actually receive the fraudulent emails.
- Documentation for ALTA and underwriter review, the controls and audit trail written down, not just configured.
This runs on top of our standard managed IT and security baseline: Month-to-month managed IT, 24/7 monitoring, endpoint detection and response, and patch management included, with a <15 minute response commitment on anything critical. No multi-year contract; month-to-month.
Book fifteen minutes with Corey Watson to review your email security and wire verification controls before a closing, not after.
Title company IT, plainly explained
Straight answers about fit, scope, and how we work.
Send a message →Why are title companies such a common wire fraud target?
Every closing routes a large wire through the title company on a predictable timeline, and the coordination happens almost entirely over email. An attacker who compromises one inbox (a closer, an escrow officer, a lender contact) can insert fraudulent wire instructions into a real transaction and walk away with the funds before anyone checks a phone number.
What does a business email compromise actually cost a title company?
In the case documented in our BEC incident report, the funds at risk were high six figures on a single closing. Beyond the wire itself, a successful fraud means a lost closing, a client who no longer trusts your firm, likely notification obligations, and a conversation with your E&O carrier. The cost of prevention is a rounding error next to that.
Does Limehawk provide ALTA Best Practices cybersecurity support?
Yes. We build controls around the ALTA Best Practices framework (wire fraud and information security pillars): email authentication, enforced MFA, verified wire-instruction procedures, and the documentation trail underwriters and lenders expect in a review.
Is it safe to wire money to a title company?
The wire is normal; unsecured email around the wire is not. Safe closings use out-of-band verification to a number on file before funds move, plus email and identity controls that stop BEC. That is the program we run for title company IT.
Is enrolling in MFA enough to stop this?
No, and that gap is exactly what caused the incident in our BEC report: the account had multi-factor authentication enrolled but not enforced at the tenant level, so a clean-looking login slipped through on a password alone. We configure and verify enforcement, not just enrollment.
What's included in the wire fraud prevention program?
Email security and authentication (DMARC/SPF/DKIM), enforced multi-factor authentication across the tenant, out-of-band wire instruction verification procedures, monitoring for the mailbox rules and forwarding filters attackers use to hide fraud in progress, and staff training on closing-day social engineering.
What does this cost?
Base managed IT and security is month-to-month with a 3-user minimum and no multi-year contract. That includes 24/7 monitoring, EDR, patch management, and email security. Security awareness training is available as an add-on. We'll walk full rates on a call.