Cybersecurity, Wire Fraud, AI & E&O: Risk Prevention & Reporting
Real estate professionals are increasingly targeted by cybercriminals using sophisticated schemes designed to exploit the fast-paced, high-stakes nature of real estate transactions. Among the most damaging threats is wire fraud, often involving intercepted, manipulated, or fraudulent communications that result in funds being sent to the wrong account.
At the same time, the use of artificial intelligence (AI) tools is growing throughout the real estate industry. AI can be a valuable business tool, but agents must understand the data privacy and liability risks associated with entering confidential client or transaction information into AI platforms.
This guide outlines important practices and guidelines to help safeguard CENTURY 21 Redwood Realty agents, clients, and transactions from cyber threats, wire fraud, data misuse, and potential liability.
Training Resource
Watch the recorded Cyber + Wire Fraud Prevention Webinar to reinforce your knowledge of cybersecurity and wire fraud prevention.
1. General Cybersecurity Best Practices
Agents are responsible for taking reasonable steps to protect their accounts, devices, client information, and transaction data.
Protect Your Accounts
- Enable MFA/2FA on email and other information-rich systems, including your CRM, transaction management systems, and other business applications whenever available.
- Use a password manager to securely generate, store, and manage unique passwords.
- Embrace passkeys when they are available as an alternative to traditional passwords.
- Use unique passwords for your business accounts. Never reuse the same password across multiple systems.
- Regularly update devices and software to address known security vulnerabilities.
- Be cautious when accessing sensitive accounts over public Wi-Fi and log out of sensitive accounts when they are no longer in use.
Be Alert for Phishing and Fraud
Train yourself to recognize fraudulent emails and other suspicious communications.
Watch for:
- Unexpected requests for money or sensitive information
- Unusual senders or email addresses
- Typos, unusual wording, or changes in tone
- Urgent or threatening requests
- Requests to change payment or wiring information
- Unexpected links or attachments
- Communications that appear to come from a client, lender, title company, attorney, or other transaction participant but seem unusual
Do not rely solely on the appearance of an email. A compromised account can make a fraudulent message appear to come from a legitimate person.
Review Your Email Settings
Criminals who gain access to an email account may create hidden rules or filters that automatically divert or delete messages.
Regularly review your email settings and filters for anything you did not create.
Email Is Not a File Cabinet
Do not rely on email as your long-term document storage system.
- Archive older emails periodically and move them off the server/cloud when appropriate.
- Maintain important transaction records in the appropriate approved systems.
- Limiting the amount of sensitive information retained in an email account can reduce the amount of information exposed if the account is compromised.
Protect Personally Identifiable Information (PII)
Personally Identifiable Information (PII) can include information such as names, property addresses, financial details, Social Security numbers, account numbers, and other information that could identify or expose a client.
- Do not email sensitive information unnecessarily.
- Use appropriate secure platforms when transmitting confidential information.
- Store sensitive documents in approved systems.
- Destroy PII when you are finished with it rather than retaining unnecessary copies.
- Protect files stored on your computer using appropriate device encryption and security tools.
- Never share passwords or account credentials.
2. Wire Fraud Awareness & Prevention
Wire fraud is one of the most significant cybersecurity threats facing the real estate industry.
Criminals may:
- Hack or spoof email accounts to impersonate agents, lenders, title companies, attorneys, or clients.
- Monitor transaction communications.
- Send fraudulent wiring instructions.
- Attempt to redirect closing funds to fraudulent accounts.
- Use compromised email accounts to make fraudulent requests appear legitimate.
Even when an agent does not directly handle client funds, the agent can still become an entry point for an attacker.
The Golden Rule: Verify Before Money Moves
Never rely solely on an email, text message, or electronic communication to verify wiring or other electronic money-transfer instructions.
Any electronic money transaction should be verified by telephone using a phone number you already have on file or obtained from a trusted source—not a phone number provided in the suspicious communication.
Be Especially Cautious About Changes
Treat last-minute changes to:
- Wiring instructions
- Bank account information
- Payment instructions
- Closing information
- Contact information
as potential red flags.
If something changes unexpectedly, stop and independently verify the request.
3. Protect Your Clients From Wire Fraud
Agents should educate clients about wire fraud early in the transaction and remind them again as closing approaches.
Educate Clients Early
Clearly explain that:
- Cybercriminals may attempt to intercept or manipulate transaction communications.
- Wiring instructions should always be independently verified.
- Clients should never assume that an email containing wiring instructions is legitimate.
- Clients should contact the title company or attorney directly using trusted contact information to verify wiring instructions.
Call the Client 10 Days Before Closing
Approximately 10 days before closing, call the client directly to remind them about the risk of wire fraud.
Use this conversation as an opportunity to reinforce:
- Never trust unexpected changes to wiring instructions.
- Never send money based solely on an email or text.
- Verify instructions by telephone using a trusted number.
- Confirm the account information before sending funds.
- Contact the title company or attorney immediately after sending the wire to confirm receipt.
Verify Electronic Money Transactions
Before a client sends money electronically:
- Call the appropriate title company, attorney, or other trusted party.
- Use a telephone number already on file or obtained independently.
- Do not use the phone number contained in a suspicious or unexpected email.
- Confirm the recipient, account information, and instructions.
- After the wire is sent, confirm receipt with the intended recipient.
Do Not “Reply” to Suspicious Financial Emails
When responding to financial or wiring-related communications, do not simply click Reply.
Instead:
- Use Forward when appropriate.
- Manually enter the correct recipient's email address.
- Independently verify the recipient before sending.
This helps avoid continuing a conversation with a compromised or spoofed email account.
4. Cybersecurity & Client Disclosure
Agents should provide clients with the Cybersecurity and Wire Fraud Prevention Notice early in the transaction and have the clients complete the acknowledgement portion.
The notice is available in:
ZipForms → Redwood Library → Global Templates/Checklists
A downloadable copy is also available here:
Download Cybersecurity and Wire Fraud Prevention Notice
The notice should be provided at the applicable point in the transaction, including when the client signs the Listing Agreement or Buyer Agency Agreement, as required by Redwood's current procedures.
5. AI Tools & Client Privacy
Artificial intelligence tools—including large language models such as ChatGPT and other AI platforms—can be useful for drafting, brainstorming, summarizing, and other business tasks.
However, agents must understand that the type of AI account being used matters when handling confidential information.
Consumer vs. Commercial/Enterprise AI
Distinguish consumer-tier and commercial/enterprise AI accounts.
Consumer tiers:
- ChatGPT Free/Plus
- Claude Pro
- Gemini Personal
Commercial/Enterprise tiers:
- ChatGPT Team/Enterprise
- Claude for Work
- Microsoft 365 Copilot
Baseline Rule
Never upload confidential client documents to a free or consumer-tier AI model.
Agents should use only AI tools and account types that are appropriate for confidential business information and whose terms provide appropriate data protections.
6. Uploading Contracts & Legal Documents to AI
Real estate documents can contain significant amounts of sensitive information.
Examples include:
- Executed contracts
- Offers
- Inspection reports
- HOA documents
- Names
- Property addresses
- Financial information
- Other client or transaction information
Uploading these documents to an AI platform can create additional privacy and liability risks.
If an AI tool is being used to summarize or analyze a document:
1. Use an Appropriate Enterprise-Grade Model
Use a commercial or enterprise-tier AI platform when confidential business information must be processed, and verify that the applicable terms provide appropriate data protections.
2. Redact PII Before Uploading
Whenever possible, remove sensitive information before providing a document to an AI tool.
For example:
- Replace a client's name with “Buyer A.”
- Replace an exact property address with “Property X.”
- Remove unnecessary financial figures.
- Remove other information that identifies the client or transaction.
3. Review Data-Control Settings
When using a consumer-tier AI tool for general brainstorming or other non-confidential purposes, review the platform's data-control settings and disable model-improvement/training options when available and appropriate.
7. AI Data & Sharing Risks
Agents should understand that information entered into an AI platform may create risks beyond the immediate conversation.
Be Careful With Shared Chat Links
Do not share AI conversations containing confidential client or transaction information.
Depending on the platform and settings, a shared conversation may make the conversation accessible to others and, in certain configurations, potentially discoverable through search engines.
Do Not Assume AI Conversations Are Private
Before entering information into an AI tool, understand:
- What information the platform collects
- How uploaded documents are handled
- Whether information may be used for model training or improvement
- Who can access shared conversations
- What the account's privacy and data-control settings provide
When in doubt, do not upload confidential client or transaction information.
8. E&O: Claims & Potential Claims
Cybersecurity incidents, mistakes, and other events may create potential Errors & Omissions (E&O) issues.
Agents should not wait until a situation becomes a lawsuit before raising a concern.
The following are matters that may need to be reported:
- Actual lawsuits — Any suit naming the agent, agents, or brokerage.
- Demands received — Written or verbal demands for money or corrective action.
- Threats of a claim — Any threat that a claim or lawsuit may be brought.
- Regulatory complaints — Disciplinary proceedings, commission complaints, or complaints to another regulatory body.
- Potential claims — Knowledge of something that may reasonably be expected to result in a claim.
When in Doubt, Report Early
Having prior knowledge is the number one reason for E&O claim denials if an insured knew about a claim or potential claim but did not report it in time. Agents should err on the side of caution and report concerns early while referring to the applicable policy for specific requirements and deadlines.
Who to Report
Agents must reach out to their office EVP or Principal Broker (Click here to learn the Principal Broker for each state) if they have a potential E&O claim.
9. If You Suspect Fraud or a Cybersecurity Incident
If you believe an email account, transaction, document, or client communication may have been compromised:
STOP
Do not continue the suspicious communication or send additional information or funds.
VERIFY
Independently contact the appropriate party using trusted contact information.
REPORT
Notify your office EVP or Principal Broker (Click here to learn the Principal Broker for each state) as soon as possible and preserve relevant emails, messages, documents, and other information related to the incident.
If money has already been sent or fraudulent wiring instructions may have been acted upon, act immediately. Contact the appropriate financial institution and transaction parties without delay.
Key Takeaway
Stop. Verify. Protect. Report.
Cybersecurity is everyone's responsibility. Every agent plays a role in protecting client information, transaction funds, and the brokerage.
‼️When handling sensitive information or money:
Verify before you trust.
🤖When using AI:
Protect client information before you upload.
📋When something goes wrong or could become a claim:
Report early rather than waiting.