Skip to Content

Cyber Scammers Are Targeting Home Buyers and Sellers. Here’s How to Protect Yourself

Homeowner looking at computer at payment: online scams

A scammer often has to invest a lot of time and work cloning a pile of credit cards or stealing a thick file of identities to make tens or hundreds of thousands of dollars. So, it's no surprise they're increasingly targeting home buyers and sellers, who can deliver those sorts of sums in a single hit.

The FBI says it received 12,368 complaints about real estate cyber fraud in 2025. And reported losses came to $275,110,419. To be clear, that's not across all real estate fraud — just the online stuff.

There's a good chance that much of that money was stolen from consumers. That's because many mortgage lenders might not want to report crimes where they are the victims.

Bottom line (literally): it might be better to absorb the losses rather than publicly admit that a sophisticated financial services institution has fallen into a trap set by criminals. Companies care about reputational damage.

How Cyber Scams Work

Our interest in the topic was piqued (again) by a new YouTube video podcast from Allied Title and Escrow, LLC. The host interviewed a former CIA officer whose job had been to recruit assets, using the dark web and other sources to profile, hack, and understand potential spies.

The CIA agent explained that cyber scammers use the same techniques to target their victims. And the speed with which he could access key information on individuals and companies was scary.

Now, much of what we saw on the video went way above our heads. After all, the producers were trying to warn potential victims, not provide a how-to video for wannabe criminals.

However, it was clear that cyber scammers have a dizzying array of highly sophisticated tools at their disposal if they want to target an individual — perhaps one who's selling or buying a home at the time.

Some are already using AI to cut their workloads and speed up their processes. The FBI says $893,346,472 was defrauded with the help of AI last year across all cybercrime categories.

One Particularly Vicious Scam

A favorite scam to acquire the maximum amount of money is to intercept funds being transferred between consumers, lenders and closing agents. And the thieves' methodology is a sophisticated, multi-stage con.

They send an email containing a "Trojan horse," which is "a type of malware that typically gets hidden as an attachment in an email or a free-to-download file, then transfers onto the user’s device," according to Fortinet. The victim only has to click the link in one of these legitimate-looking emails for the virus to download onto his or her computer or smartphone.

"Once downloaded, the malicious code will execute the task the attacker designed it for, such as [to] gain backdoor access to corporate systems, spy on users’ online activity, or steal sensitive data," Fortinet continues.


So, using a Trojan horse, a criminal can spy on everything one does on one's computer or smartphone, including viewing all one's emails and texts, both in the archives and in real time as they're received. So, for example, the scammer could train AI to mimic a loan officer's writing style.

One morning, the loan officer writes requesting the down payment be transferred to the closing agent. Moments later, a second email arrives in the inbox saying something like: "Oops! The closing agent says there's a problem with that account. Please would you send the money instead to [different routing number]."

The second email looks every bit as legitimate as the first. But the second came from the scammers, and the account details are theirs.

Home buyers — and especially cash buyers — can lose tens or hundreds of thousands of dollars of their hard-earned savings in seconds to this scam.

Tips to Avoid Cyberscams

There's no such thing as 100% security, either online or in the real world. But, just as a homeowner upgrades door and window locks and installs a burglar alarm, a home buyer can act to protect the integrity of their online presence.

In both cases, the goal is to make life sufficiently difficult for the criminal that they move on to someone who's less well protected. Here are some tips:

  • 2FA — Two-factor authentication. Some sites offer 2FA, which adds another layer of security. The user receives a new, unique, one-time passcode via email or SMS for each login and must enter it along with the usual password to access the website. Opt in, when offered.
  • Read emails after caffeinating — Scammers often send emails containing Trojan horses in the middle of a Friday or Saturday night. They hope the recipient is either tired and drunk at 2 a.m. or is groggy from sleep (and preferably hungover) the next morning when they read it and click on the link. Hold off on checking your mail until your properly awake and aware.
  • Password managers create a unique, long, complicated and random password for every website. And users need to remember only the password manager's password to access them all because the software logs them in automatically. If a hacker compromises one website and finds the user's password, it won't open up all or most of the other accounts.
  • Scam software can alert users to current scams and when their identity has been hacked.
  • Virus protection software can scan incoming emails for viruses (including Trojan horses). And it will typically scan computer and smartphone drives to find and eliminate any viruses that have sneaked in. Schedule a scan before transferring large sums.
  • Especially when big sums are at stake, call someone relevant (such as the loan officer) you already know before pushing the Transfer button on the banking app. Use a phone number that's been used before (not one in a recent email) to reach them and explain you want to double-check everything.
  • Don't rely on anything being real. Spoofing phone numbers, which can make it look as if the bank, lender or another legitimate organization is calling, has been around for decades. And AI can create fake websites and email formats that are effectively identical to the real ones in a matter of minutes. If you're logging on during a sensitive time, type in the URL (site address); don't click on a link to the site in an email.

Home buyers needn't let the rise of real estate cybercrime in the U.S. cause sleepless nights. Each of the 12,368 complaints the FBI received last year was likely a nightmare for someone.

But the odds of an individual being caught up in one are still small. Realtor.com says there were 4.741 million homes sold last year, which means the chance is 0.2609%. Homebuyers can reduce that chance greatly by following our tips.

About The Author:

Peter Warden has been covering mortgage, real estate, and personal finance for 15 years. He has appeared on The Mortgage Reports, Credit Sesame, Bills.com, and other publications.

See how much home you can afford
9,420 people checked their eligibility today!