Bastani Security
Book the Fire Drill
Free kit · For real-estate & mortgage teams · Toronto & GTA

The closing-day wire-fraud kit Then the wire instructions changed.

One spoofed email with "updated" wiring details can send a client's down payment to a thief, and it almost never comes back. This kit gives you the exact verification habit, the email red flags, a one-pager to hand clients, and a calm first-hour plan if money already moved. No sign-up wall on the value - read it, copy it, put it to work today.

  • The exact out-of-band verification SOP your team follows before any funds move - written so an admin can run it on day one
  • A closing-day email red-flags checklist agents can keep on the desk
  • A client-facing "how we protect your funds" one-pager you can brand and send
  • A clear, no-panic first-hour plan if funds were already sent - who to call, in what order, right now
Email me the editable pack

Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.

01

Why closing day is the target

This is business email compromise (BEC), and a real-estate or mortgage deal is the perfect setup for it: large sums, a hard closing date, and a dozen parties - agent, buyer, lawyer, mortgage broker, lender - all emailing each other. Antivirus never fires, because there's no malware. It's just a believable email at the worst possible moment. Knowing exactly how it unfolds is the first defence.

Weeks before closing, an attacker quietly gets into one mailbox in the chain - often through a single reused password or a convincing login page. They don't act yet; they read.
They study the thread silently: the names, the closing date, the tone, the trust-account language. They learn to sound exactly like your lawyer, your client, or you.
Right before funds move, a flawless email arrives with "updated" banking details and a note about a last-minute change. It matches everything the client has seen, so nobody questions it.
The money is wired and pulled within hours. By the time someone calls to confirm, it's gone - and the client is looking at you. The only reliable defence is a verification habit, not a tool.
One rule worth remembering: banking and wiring details effectively never change mid-deal. Treat any "updated" instructions as suspicious until you've verified them by voice on a number you already trust.
02

The out-of-band verification SOP (copy this)

"Out-of-band" just means: confirm the money instructions through a different channel than the one they arrived on. If the wiring details came by email, you verify by phone - using a number you already had, never the one in the email. This is the single habit that defeats almost every closing-day wire scam. Print it, tape it by the desk, and make it non-negotiable before any funds move.

Step 1 - Trigger: Any time wiring instructions, trust-account details, or a deposit destination arrive or change, the SOP starts. No exceptions, even if it "looks fine" and the deal is tight.
Step 2 - Use a known number, never the email: Call the lawyer's or brokerage's office on a number from your file, your contact list, or the firm's official website - never the number or reply-to in the new email. Attackers put their own "call to confirm" number right in the message.
Step 3 - Read the details back, don't ask yes/no: Read the account name, institution number, transit, and account number aloud and have them confirm each one. Don't ask "are these details right?" - a busy person says yes. Make them read theirs back to you.
Step 4 - Verify changes in person where possible: For a first wire or any change to instructions, confirm voice-to-voice with someone you can identify. Be extra careful with urgency, secrecy, or a "new assistant / new contact" you've never dealt with.
Step 5 - Independently confirm the client's receiving details too: Fraud also reroutes a seller's proceeds or a refund. Verify the client's banking the same way, with the client directly, on a number they gave you in person or earlier in the file.
Step 6 - Log it: Note who verified, the number called, the time, and that details were confirmed. One line in the file. It protects the client and it protects you.
Tool note: scenarios and reminders live where your team already works - surface this SOP in Lone Wolf, Dotloop, or Broker Bay closing checklists, and pin it in the deal's transaction folder so it travels with every file.
03

Closing-day email red flags (desk checklist)

Hand this to every agent and admin who touches a closing. None of these on its own proves fraud - but any of them means stop and run the verification SOP before money moves. Read the email like a skeptic, not like someone trying to clear their inbox before lunch.

"Updated" or "corrected" wiring or trust-account details arriving close to closing - the classic switch.
A reply-to or "call this number to confirm" that's different from the contact's normal address or your filed number.
Subtle look-alike domains: a swapped letter, .ca vs .com, "firmname-law.com" instead of the real one. Hover over the sender before you trust it.
Pressure and secrecy: "wire today," "don't tell the other side yet," "I'm in a signing, just handle it." Urgency is the scammer's favourite tool.
A reply that quotes the real thread perfectly but the money detail is new - the attacker has been reading along.
A first-ever payment instruction, or a "new assistant / new bookkeeper" you've never dealt with, sending banking details.
Slightly-off tone, grammar, or signature from someone you email all the time - trust the feeling and verify.
A "DocuSign" or "sign to release wiring instructions" link - go to the source platform directly, never the link in the email.
04

The client one-pager: how we protect your funds

Wire fraud works partly because clients don't know it exists - so they panic and act on a fake email before anyone catches it. Give clients this at the start of the deal, not the day funds move. Put it on your letterhead, send it with the agreement, and it does two jobs: it protects their money and it makes your brokerage look like the professionals who saw it coming.

Tell clients up front: "Wiring and banking details for this transaction will not change by email. If you ever receive a message saying they've changed, do not act on it - call us first on the number we gave you."
Give them one trusted phone number, in writing, and tell them to use only that number to confirm anything about money - never a number from an email.
Set the expectation early: "We and your lawyer will confirm wiring details with you by phone before any funds move. If that call doesn't happen, the wire doesn't happen."
Tell them what a scam looks like in plain words: a last-minute "updated banking details" email, urgency, secrecy, a slightly different address - and that real professionals will never rush them past a phone confirmation.
Give one instruction if they're unsure: "Stop, don't send, and call us. We would always rather take a five-minute call than chase a wire that's already gone."
Make it impossible to lose: a single page, your branding, your trusted number, dated. Clients keep it because it's about their largest cheque of their life.
05

If funds were already sent: the first hour

If a wire has gone to the wrong account, the next hour matters more than any other. Money can sometimes be frozen or recalled if you move fast - speed beats blame every time. Keep this where your team can grab it under pressure, because nobody thinks clearly in the moment. This is practical readiness, not legal advice; loop in counsel early.

Call the sending bank immediately and ask for a wire recall / SWIFT recall, and to flag the transfer as fraudulent. Minutes count - funds are often pulled within hours.
Have the client call their bank in parallel to do the same from their side, and to freeze any further transfers.
Contact the receiving institution if you can identify it, to report fraud and request a hold on the funds.
Report to the Canadian Anti-Fraud Centre (CAFC) at 1-888-495-8501 or antifraud-centre.ca, and file with your local police - you'll want the report numbers for the bank and any claim.
Preserve everything: don't delete the emails, headers, or texts. Screenshot the messages and the wiring details. This evidence helps the banks, police, and any insurer.
Notify your brokerage of record, the lawyer, and your insurer / E&O carrier promptly - and check whether crime or cyber coverage may apply.
Change the password and turn on multi-factor authentication on any mailbox that may have been compromised, so the attacker can't keep watching the thread or send a "correction."
Communicate calmly with the client by phone - they'll be frightened. Being the steady, organized one in the first hour is the difference between a near-miss and a lost client.
How to use this

Print the verification SOP and the first-hour plan and tape them where closings actually happen - by the admin's desk and the phone. The client one-pager belongs on your letterhead, sent at the start of every deal, not the day funds move. This kit is practical readiness, not legal, insurance, or financial advice - confirm trust-account and verification procedures with your lawyer and brokerage of record.

A checklist is a start. A drill makes it stick.

The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this toolkit become muscle memory. Three hours, on-site, with a scored 30-day plan.

Book the Fire Drill See the real estate & mortgage page →
Is this kit really free, or is it a sales funnel in disguise?

It's genuinely yours to use. Copy the SOP into your closing checklist, hand the one-pager to clients, tape the first-hour plan by the phone - no catch. If your team would rather rehearse the attack live instead of just reading about it, that's what our Cyber Fire Drill does, but the kit stands on its own.

We use Lone Wolf, Dotloop and Broker Bay - does this fit our workflow?

Yes. The verification SOP is built to live inside the closing checklists and transaction folders you already use, so it travels with every deal. The habits work the same no matter which platform you're on - the point is that the wiring details get confirmed by voice before money moves.

Reading a kit is one thing - how do we get our agents to actually do this under pressure?

That's the gap a document can't close, and it's exactly what The Cyber Fire Drill is for. We put your agents and admin through a safe, authorized closing-day wire-fraud attempt - no malware, no real money, no shaming anyone - so the verification habit is muscle memory when the real email lands. It's a live, roughly three-hour session for your whole office, $3,900 + HST, and you leave with this SOP tailored to your firm and a scored 30-day plan.

More resources in the resource library · questions? contact@bastani.org