Skip to content
← All insights

Seller impersonation succeeds on infrastructure your internal controls never touch

Published October 2, 2026·4 min read

The first sign is often a change in payment details, sent from an address that looks legitimate, just when everyone wants the deal closed. The request is polite, specific and urgent, and the person receiving it has been trained to move fast.

National Mortgage Professional reported on 1 October that the American Land Title Association's 2026 Seller Impersonation Fraud Study found 59% of title firms had at least one seller impersonation attempt in 2025, more than double the 28% in earlier research. Forty-five percent reported an attempt in the month before the survey, and among firms that had one, one in four also had a paid claim; half of those that disclosed costs put them above $100,000. The same piece notes the FBI counted $20.9 billion in internet-crime losses in 2025, with business email compromise accounting for $3 billion.

That is the point where most commentary lands: train staff, verify identities, never change wire instructions from an email alone. All of those measures are necessary. But the numbers should prompt us to look one step earlier in the chain. The fraudster does not begin with the email to your finance team. That email is simply the final step in a chain that started outside your perimeter.

When an attacker can harvest public property records, create convincing synthetic documents and build an identity profile, the better question is which independent data can confirm the owner, the counterparty and the payment instructions. The source piece quotes the old response as "We spoke to the seller." In an AI-enabled fraud world, the article argues, that is no longer enough.

What the source does not say, because it is written for mortgage lenders, is how much of that chain runs through assets your organisation never sees in a transaction file: a lookalike domain, a cloned document, a social profile that makes an invented intermediary credible. Those assets are built in public, often in the days before contact begins. If nobody is watching for them, your first detection is the moment someone asks why a payment went to the wrong account.

This is where the outside-the-perimeter view becomes important. For a finance, property or legal team, the practical control is continuous discovery and takedown of impersonating assets, not another layer of internal attestation. That is what digital risk protection does: it watches for lookalike domains, cloned login pages, executive impersonation and leaked credentials, and uses registrar relationships to remove them quickly, typically within 24 to 48 hours. The goal is to make the fraudster's entry point expensive before the transaction instruction arrives.

The ALTA study shows firms are already using multiple tools, averaging 5.3 per firm, and nearly all of the responding firms said those tools were helpful. But the tools described are mostly verification tools: identity checks, direct seller contact, multifactor authentication. None of those finds a domain registered last Tuesday. That gap is what an external asset review is for.

A check before the next transaction

If your organisation handles property completions, investor payments, or any customer-facing brand where an invoice can be changed at the last minute, there are three checks that cost far less than dealing with a fraud loss. First, map the external assets an attacker would use to impersonate you: your domain variations, key executives' profiles, standard forms. Second, ask whoever runs brand or fraud monitoring whether they can see new registrations in near real time, and how long takedown takes. Third, test the process from the outside: if a new domain appeared tomorrow, who would know?

These questions ask a supplier to demonstrate the monitoring, the takedown path and the alert routing in concrete terms. A vendor questionnaire completed at a single point in time will not answer the first question. What matters is whether the monitoring is continuous, whether takedowns are actually executed through registrar relationships, and whether the alerting reaches someone who can stop a payment.

The decision already in front of you

For organisations reviewing fraud controls this quarter, the article moves the conversation from identity checks to transaction verification. Its central claim is that the closing table is now a perimeter. The assets that make fraud convincing sit outside that perimeter, and the speed at which they are removed can determine whether a transaction goes through safely or ends up funding a fraud. If the decision in front of you is whether to extend monitoring beyond your own digital estate, the 59% attempt rate should end the argument about whether this is an edge case; the only question left is how soon you can test it.

If you do not know where your impersonation exposure sits, a conversation about where that exposure sits is a fast way to find out before a transaction does.

  • seller impersonation
  • business email compromise
  • digital risk protection
  • external attack surface
  • fraud prevention
  • third-party risk

Share this post

Ready to get started?

Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.