BEC Wire Fraud at a Title Company: How We Stopped a High-Six-Figure Loss
Home>Incident Reports>BEC Wire Fraud at a Title Company: How We Stopped a High-Six-Figure Loss
Time to contain
~2.5 hrs
Funds at risk
high six fig.
Funds lost
$0
Root cause
MFA not enforced
★ TL;DR
Attacker took over a title closer's Google Workspace inbox via password-only login (2SV enrolled but not enforced). Sent fraudulent wire instructions on a real pending closing, then created mail-block rules to hide the thread from coworkers. We forced a password change, killed sessions, and — most importantly — phoned the counterparty out-of-band before the wire moved. Zero loss.
People are sending emails from her actual account changing wiring instructions, we need to shut down whoever it is.
— Title company owner, on the call
Incident
Timeline
08:47Attacker sends benign-looking email referencing the pending closing — likely a probe to confirm the inbox is live.
09:04Fraudulent wire instructions sent to the closing agent on the other side of the deal.
11:02Attacker creates mail filters blocking incoming email from the firm's funding desk and another closer who would have spotted the fraud.
11:30Legitimate user regains access; password forced change.
12:03Secondary password change forced via backup code to kill any lingering session.
Investigation
What we ruled out (technical investigation)
Response
Why this worked (and why it almost didn't)
Outcome
Key takeaways
Takeaway
BEC attackers don't send one email and leave — they stay logged in and manipulate the inbox in real time. Look for block rules and filters during every compromise investigation.
Takeaway
2SV enrolled is not 2SV enforced. Google only challenges on suspicious signals, so a clean-looking login gets through on password alone.
Takeaway
The phone call to the counterparty is the single most valuable thing you can do in the first hour of a BEC — email them and the attacker can still intercept.
Takeaway
Every wire-instruction change should be verified out-of-band, by phone, to a number on file, before a penny moves.
Takeaway
Credential-only compromises can be fully remediated by password change plus session invalidation — but only if you're sure nothing else was touched.