Wire Transfer Fraud and Cyber Security
Bottom line: Do not let your guard down. Start from the
assumption that any email in your in-box could be a targeted attack from a
criminal.
Prevention
Follow this guidance to avoid becoming a victim:
· Immediately contact all parties to all of your upcoming
transactions and inform them of the possibility of this fraud. Attorneys,
escrow agents, buyers, sellers, real estate agents, and title agents have all
been targeted in these scams. You can also download and distribute NAR’s
online fraud prevention handout, accessible here. Also available at the bottom of this section.
· If possible, do not send sensitive information via
email. If you must use email to send sensitive information, use encrypted
email.
· Immediately prior to wiring any money, the person sending
the money must call the intended recipient to verify the wiring
instructions. Only use a verified telephone number to make this call.
· Do not trust contact information in unverified
emails. The hackers will recreate legitimate-looking signature blocks
with their own telephone number. In addition, fraudsters will
include links to fake websites to further convince victims of their legitimacy.
· Never click on any links in an unverified email. In
addition to leading you to fake websites, these links can contain viruses and
other malicious spyware that can make your computer – and your transactions –
vulnerable to attack.
· Never conduct business over unsecured wifi.
· Trust your instincts. Tell clients that if an
e-mail or a telephone call ever seems suspicious or “off,” that they should
refrain from taking any action until the communication has been independently
verified as legitimate.
· Clean out your e-mail account on a regular basis. Your
e-mails may establish patterns in your business practice over time that hackers
can use against you. In addition, a longstanding backlog of e-mails may contain
sensitive information from months or years past. You can always save important
e-mails in a secure location on your internal system or hard drive.
· Change your usernames and passwords on a regular basis,
and make sure your employees and licensees do the same.
· Never use usernames or passwords that are easy to guess.
Never, ever use the password “password.”
· Make sure to implement the most up-to-date firewall and
anti-virus technologies in your business.
Damage
Control
If you believe your e-mail or any other account has been
hacked, or that you or a client has otherwise been a victim of online fraud,
you should take the following steps:
· If money has been wired via false wiring instructions,
immediately call all banks and financial institutions that could possibly put a
stop to the wire.
· Contact your local police.
· Contact any clients or other parties who may have been
exposed during the attack so that they take appropriate action. Remind them not
to comply with any requests from an unverified source.
· Change all usernames and passwords associated with any
account that you believe may have been compromised or otherwise made vulnerable
by the attack.
· Report any fraudulent activity to the Federal Bureau of
Investigations via their Internet Crime Complaint Center. More information can
be found by clicking here (link is external).
· Brokers should report any fraudulent activity to their
state or local REALTOR® association so that the associations can send out
alerts or take other appropriate action, including contacting NAR.
This advice is not all-inclusive, and real estate
practitioners should work with Information Technology and cybersecurity
professionals to ensure that their e-mail accounts, online systems, and
business practices are as secure and up-to-date as possible.
Be aware that these emails are extremely
convincing. Many sophisticated parties have been duped. No one should
assume that they are “too savvy” to recognize the fraud. In addition, no
one should assume that they are “too small a target” to be on these criminals’
radars. This fraud is pervasive, convincing, and constantly evolving.
For more information on this and other cyberscams, as
well as further information on cybersecurity best practices, visit these
resources:
http://speakingofrealestate.blogs.realtor.org/2015/05/19/alert-wire-fraudsters-targeting-real-estate-transactions/
http://www.realtor.org/law-and-ethics/protecting-your-business-and-your-clients-from-cyberfraud
http://www.realtor.org/articles/request-to-redirect-funds-should-trigger-caution
http://www.realtor.org/topics/data-privacy-and-security
http://www.realtor.org/topics/risk-management
http://www.realtor.org/articles/internet-security-best-practices
http://www.realtor.org/topics/realtor-safety/articles
http://www.realtor.org/law-and-ethics/protecting-your-business-and-your-clients-from-cyberfraud
http://www.realtor.org/articles/request-to-redirect-funds-should-trigger-caution
http://www.realtor.org/topics/data-privacy-and-security
http://www.realtor.org/topics/risk-management
http://www.realtor.org/articles/internet-security-best-practices
http://www.realtor.org/topics/realtor-safety/articles
NAR Video CLICK HERE
SCR Legal Update: Hacking and Wiring Scams Click Here