
Title and escrow agencies get attacked for one reason: they move other people's money on a known schedule, and everyone involved communicates by email. These are the questions we get most from agency owners across the NY-NJ-CT metro — how the wire actually gets stolen, what regulators expect, and what to do in the first hour when one goes out the door.
Why title agencies get targeted
The short version: the money is big, the timing is public, and the whole transaction runs on email.
Why do criminals target title and escrow companies specifically?
Because the payout is large, predictable, and time-boxed. A closing date is public, the wire amount is knowable, and everyone expects last-minute instructions. The FBI's 2025 Internet Crime Report logged more than $275 million in real estate fraud losses from 12,368 victims, up from $173 million the year before, as NAR reported.
How does a closing wire actually get stolen?
Usually through a compromised mailbox, not a hacked wire system. An attacker gets into an agent's or attorney's email and reads the thread quietly for days. Then they send the buyer new wire instructions from a lookalike domain at exactly the right moment, and the money is gone within hours. Our guide to business email compromise covers the mechanics.
What single control stops the most wire fraud?
In our experience it's callback verification — calling a number you already had on file, before every wire, with no exceptions for familiar parties. It's a process control, not a product. MFA, email filtering, and domain authentication all reduce the odds of a compromised mailbox, but the callback catches the ones that get through anyway.
What regulators and partners require
Two federal and state frameworks likely apply to you, and your underwriters will ask about both.
Does the FTC Safeguards Rule apply to my agency?
Probably in practice, though you should confirm your specific services with counsel. The FTC's published examples of covered financial institutions name mortgage brokers, account servicers, and wire transferors — but not title agents specifically. If you handle the same non-public personal information, plan to meet the same bar regardless of how the definition lands.
Does New York's cybersecurity regulation cover title agencies?
If you're licensed as a title insurance agent in New York, yes. 23 NYCRR Part 500 defines a covered entity as anyone "operating under or required to operate under a license" under the Insurance Law. A limited exemption applies to agencies under 20 employees, under $7.5 million in gross annual revenue, or under $15 million in year-end assets — but it's a partial exemption, not a pass. See our NYDFS Part 500 guide.
What does a written information security program have to include?
The FTC's nine elements are the practical checklist:
- A designated qualified individual to run the program
- A written risk assessment
- Safeguards designed to control the identified risks
- Regular monitoring and testing of those safeguards
- Security awareness training for staff
- Oversight of service providers
- Periodic updates to keep the program current
- A written incident response plan
- An annual report from the qualified individual to the board
Is there an exemption for small agencies?
Partially. Under 16 CFR 314.6, institutions holding customer information on fewer than 5,000 consumers are exempt from four requirements: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual board report. The core safeguards still apply. Most title agencies cross 5,000 faster than owners expect, since every party to every closing counts.
What do underwriters and lender partners ask for?
Evidence of MFA on email, a written information security program, documented wire verification procedures, training records, and proof you can restore from backup. Many underwriters also ask where you stand against ALTA's Best Practices and information security guidance.
Have all of it in one folder before anyone asks. Assembling it under a deadline during a partner review is how small gaps turn into deal-breakers.
What to do about it
Three things decide how this goes: your email configuration, your wire process, and how fast you move in the first hour.
How do I stop attackers from spoofing my own domain?
Set up SPF, DKIM, and DMARC, then move DMARC to a reject policy once you've confirmed your legitimate senders pass. Without it, anyone can send email that appears to come from your agency to your buyers. Our email authentication FAQ walks through the setup order.
What happens the day a wire goes out to a criminal?
Speed decides the outcome. Call the sending bank immediately and ask them to initiate a recall, then file with the FBI's IC3 the same day. Funds are often recoverable in the first 24 to 72 hours. After that they usually aren't.
Will the FBI's Financial Fraud Kill Chain get my money back?
Only if the wire meets all of its conditions: international, $50,000 or more, a recall already initiated with the bank, and reported within 72 hours. Most domestic closing wires don't qualify, which surprises people at the worst possible moment. File with IC3 anyway and work the recall through the sending bank. Write this sequence into your incident response plan now, not during the call.
Do I need a dedicated IT provider, or can my closing software vendor handle it?
Your closing platform secures its own application. It doesn't secure your mailboxes, your workstations, your network, or your staff — which is where the actual attacks land. Those are separate problems needing separate ownership, whether that's an internal hire or an outside provider.
What should we fix first if we're behind on all of it?
In this order:
- MFA on every mailbox, no exceptions
- Callback verification written into the closing checklist
- DMARC moved to a reject policy
- Phishing training with tracked results
- A restore you've actually tested
Those five cover the paths attackers actually use. Everything else can follow once they're genuinely done.
Where to start
If you're not certain every mailbox is covered by MFA, start there this week. It's the control sitting underneath every other answer on this page.
For a second set of eyes on the whole picture, book a complimentary risk assessment. We'll review your email security, wire process, and backups, and give you a prioritized list. Our managed IT and security services cover the remediation if you want help executing it.
Joel Baum leads cybersecurity at The NetSys Group, which has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Discuss cyber security for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



