Buying a house in Ontario means moving a very large sum of money on a fixed date through people you met three weeks ago. Every part of that arrangement is normal. All of it is also, from a criminal’s point of view, close to ideal. Real estate wire fraud works by inserting one email into a sequence of legitimate emails, at a moment when everyone involved is expecting exactly that kind of message. The Law Society of Ontario’s guidance on fraud in real estate transactions has warned the profession since 2004, and the warnings have grown steadier as the method has shifted from forged documents toward compromised inboxes.
Real estate wire fraud does not require anyone to be careless
The persistent myth is that victims were sloppy. Someone clicked something obvious, ignored a spelling mistake, missed the warning signs everybody reads about.
That is not what these files look like.
In a Canadian case documented by the Canadian Lawyers Insurance Association, a farmland sale closed for nearly 400,000 dollars, paid into the firm’s trust account as expected. The client had provided a void cheque from a local credit union, which established the payment instructions. Then the lawyer’s email account was compromised. Using the lawyer’s actual mailbox, not a lookalike domain, the intruder read the file, understood the transaction, and sent the real estate assistant a message changing the payment instructions to a small bank in a different jurisdiction.
Consider what the assistant saw. An email from her own lawyer, in the correct thread, about the correct file, at the correct point in the closing. No spelling errors, because a real person wrote it. No suspicious domain, because the domain was theirs.
There was nothing to catch. That is the entire design.
The window is narrow, and everyone is watching the wrong things
Closing week compresses the risk into a few days. Funds move, instructions get confirmed by email because that is how the industry runs, and every participant is juggling several files at once. A brokerage assistant handling four closings in one week is processing dozens of routine banking messages. Attention is the scarce resource, and fraudsters are spending it deliberately.
They also do their homework first. An intruder sitting quietly in a mailbox will often wait weeks, reading, learning the vocabulary of the office and the rhythm of a file, before writing anything. When the message finally goes out, it names the correct property, the correct closing date, and the correct amount, because all of that was sitting in the inbox to be read.
Broader fraud data lines up with the pattern. Analysis of business email compromise campaigns through the second quarter of 2026 found that between 87 and 92 percent of first-contact messages carried no financial request at all. They opened a conversation. The money came later, once the relationship had been established, and by then nothing about the exchange looked unusual to the target.
The Canadian Anti-Fraud Centre received 108,878 fraud reports in 2024, covering more than 638 million dollars in reported losses, and it repeats in every publication that only a small share of victims ever come forward. Professional firms have a particular reason not to. Reporting a compromised mailbox means telling clients that their file was read by a stranger, which is a conversation most practices will do a great deal to avoid. The published numbers are therefore a floor, not a measurement.
Why Ontario concentrates the exposure
In this province, almost everyone buying or selling a home is legally required to use a lawyer, which means millions of dollars pass through trust accounts belonging to lawyers on both sides of every deal. The structure protects consumers in most respects. It also creates a small number of predictable places where all the money in a transaction sits at a known time.
Regulators have started acknowledging the limits of oversight here. A Toronto firm accused of misappropriating more than seven million dollars from clients had passed a Law Society spot audit in 2022 without concerns being raised, a case reported by CBC in 2025 and now before disciplinary proceedings. That matter involves internal theft rather than an outside intruder, so the mechanism is different. The lesson transfers anyway: trust accounts are where the pressure lands, and routine financial checks are not designed to detect deliberate deception.
| Point in the transaction | What the criminal needs | Typical delivery | Practical countermeasure |
| Deposit on acceptance | Brokerage trust account details | Email from a compromised agent mailbox | Deposit instructions confirmed by phone before first transfer |
| Mortgage advance | Timing of lender funding | Access to lawyer or broker inbox | Lender confirms account details through its own channel only |
| Balance due on closing | Buyer’s readiness to wire same day | Reply within an existing legitimate thread | Callback to a number from the retainer, never from the email |
| Seller proceeds payout | Seller’s banking coordinates | Late change of instructions, framed as urgent | Written policy that instructions never change by email alone |
| Post-closing adjustments | A trusting assistant and a quiet week | Follow-up message referencing real file numbers | Second approver on any outgoing trust disbursement |
| Any point, any file | An unmonitored mailbox | Silent access, sometimes for weeks | Alerting on new forwarding rules and unusual sign-ins |

Real estate offices are protecting a treasury with consumer-grade email
A brokerage or a small conveyancing practice will typically be running a standard business email subscription with default settings. That covers spam and known malware competently. It does not model who normally writes to whom, does not flag when an internal account starts behaving unlike itself, and offers nothing at all against a genuine message sent from a genuine account by the wrong person.
Contrary to how the problem is usually framed, the fix is not mainly about filtering incoming mail. It is about noticing compromise of your own accounts, which is a different discipline: watching for mailbox rules that quietly forward or delete messages, for sign-ins from places nobody visited, for a mailbox suddenly reading files it has no reason to open. Firms that handle client funds need protection built around how legal and real estate practices actually exchange money rather than a generic filter tuned for a marketing department.
What actually moves the odds
Three habits, none of them expensive.
First, the callback rule, stated in writing and given to clients at the start of the retainer: payment instructions are issued once, they never change by email, and any message claiming otherwise will be verified by telephone on a number the client provided in person. Say it early and say it plainly. Clients who hear the rule in week one do not argue with it in week six.
Second, treat the mailbox as part of the trust account. If a compromised inbox can redirect funds, then inbox security is financial control, not an IT preference. That reframing tends to unlock the small budget these measures need, because a managing partner who will not approve a security line item will usually approve a control on client money.
Third, slow down the one moment that matters. Everything about closing week rewards speed, which is precisely why the single step of confirming banking coordinates deserves to be the step nobody rushes. Thirty seconds on the phone against a six-figure irreversible transfer is not a difficult trade.
A fourth measure belongs on the list for any office with more than a handful of staff: multi-factor authentication on every mailbox, enforced rather than offered. Most compromises of professional inboxes begin with a stolen password rather than anything more sophisticated, and a second factor removes the cheapest path in. It is not sufficient on its own, since session tokens can still be stolen by attackers who sit between a user and a real sign-in page, but it eliminates the volume attacks that make up the bulk of attempts.
Then there is the client side, which most firms treat as somebody else’s problem. Buyers are the least protected party in the chain: no IT department, a personal email account, and a once-in-a-decade transaction they have no basis for judging. A single page in the closing package, written plainly, explaining that nobody from the office will ever email new banking details, does more good than any amount of internal policy. It costs a paragraph.
The wire itself offers no protection. Once funds arrive in a receiving account they are usually gone within the hour, and recovery depends almost entirely on how quickly the bank is alerted. There is no chargeback on a closing.
Ontario buyers already accept a long list of protections they never think about: title insurance, statutory holdbacks, trust obligations enforced by a regulator. A phone call before the money moves belongs on that list, and so does a mailbox somebody is actually watching. It is stranger that neither is standard practice yet than that anyone would suggest adding them.
You must be logged in to post a comment.