Blog · AI Fraud Defense
Published April 10, 2026

Anatomy of a $250,000 deepfake wire fraud call.

A real-shape walkthrough of how AI-driven voice cloning is being used against title and settlement firms in 2026, and the controls that actually defend against it. Approximately 6 minutes.

A Tuesday morning at a small title firm in upstate South Carolina. Two business days before closing. The seller's "voice" calls the closing processor.

Voice matches. Phone number matches the one on file. Tone matches. The request: new wire instructions, account at a different bank, "the old one closed." The processor updates the file. The wire goes out at 2:00 PM. By 4:30 the money is gone — split across three accounts, two of them already empty by close of business.

The seller never made the call. They were on a flight to Charlotte.

This is the shape of AI-driven wire fraud in 2026. It is not theoretical. It is not state-actor sophistication. It is consumer-grade tooling pointed at a workflow that was designed in an era when nobody could clone a voice.

How the attack actually gets built

The attacker's pipeline is short. They harvest public audio of the target — a real estate podcast, a marketing video on the firm's website, a recorded Zoom from a closing platform, even a voicemail greeting. Thirty to sixty seconds of clean audio is enough. They feed it to a voice synthesis model that runs on consumer hardware. They spoof caller ID using a service that costs less than a coffee. They wait for the right transaction.

The "right transaction" is one with two specific properties. First, there is a known closing date that gives them a deadline. Second, there is at least one party — usually a remote seller — who has not been in the title firm's physical office. The attacker calls the firm during business hours, plays a script generated to match the closing context, and asks for one specific thing: change the wire destination.

From the processor's seat, the call is unremarkable. It sounds like the seller. The caller knows the file number. The caller knows the closing date. They sound a little stressed, like anyone changing their wire instructions at the last minute. The whole conversation takes four minutes.

Why title and settlement firms specifically

The math is brutal in the attacker's favor. Title firms execute large, time-sensitive wires with multiple counterparties — sellers, buyers, lenders, attorneys — often across firms that have never met in person. The window between "wire instructions sent" and "funds disbursed" is short. The dollar amounts are six and seven figures. Every party assumes good faith. That combination is the highest-value target in financial workflows under $5 million.

ALTA tracking data and FBI IC3 reports both show wire fraud against title and settlement steadily climbing for five consecutive years. The 2024–2025 jump was the first one that the industry could not blame on remote work. It was the first jump driven by AI.

The control that actually works

The single highest-impact control is also the most boring: a documented callback protocol executed against a phone number captured at engagement, with no exceptions made under time pressure. Three details matter.

The number must be captured at engagement, not from the request. If you call back the number on the email or the caller-ID, you are calling back the attacker. Capture phone numbers when the file opens, store them with the file, and call that number for any wire instruction change. No exceptions. No "I'll just text them at this new number to confirm."

The protocol must be in writing and disclosed to all parties. A real seller should not be surprised when you call them back. The policy is published in your engagement letter and in the closing instructions. Attackers exploit unexpected friction; a documented protocol removes the social-engineering lever.

The team must be allowed to slow the closing down. The most common reason callbacks get skipped is closing-date pressure. If your culture rewards speed over verification, you will lose a wire eventually. Write it into the policy that any team member can pause a wire pending callback verification, and that pausing is never a performance issue.

What doesn't work, yet

Voice biometrics and AI-deepfake detection software are improving fast, but they are not yet deterministic defense. They produce probability scores, not yes/no answers, and the production-grade models lag the attacker tools by 12 to 18 months. We will recommend voice-detection tooling when the false-positive rate is low enough not to break closings. We are not there yet.

Cyber insurance is also not the safety net most firms assume it is. Many policies exclude "voluntary parting with funds," which insurers argue includes wires sent based on social engineering — even AI-assisted social engineering. Some policies require specific deepfake riders. Review your policy language with counsel and your broker before assuming the loss is covered.

Where Caveo fits

We work with title and settlement firms to audit the actual workflow — not the policy as written, the workflow as executed — and to identify the specific gaps an AI-driven attacker would exploit against that firm. The free Caveo Scan covers the public-facing half: which executives have enough public voice samples for a clone, which lookalike domains exist, where your brand is being impersonated. The full audit covers the rest, including the wire workflow.

If you want to see what an attacker can already see about your firm before they pick up the phone, that is what the scan is for.

Run a free exposure scan. Find out what an AI-driven attacker can see about your firm in 48 hours.

Request free scan