How to Protect Title Companies from Wire Fraud & Cybersecurity Threats | Title Agents Podcast Ep5

Episode Summary

Tom Cronkright shares his journey from wire fraud victim to founder of Certified, a technology platform protecting real estate transactions. This episode covers how cybercriminals have evolved their tactics using AI, why banks aren’t liable for most wire fraud, the gaps in cyber insurance coverage, and exactly what to do in the first hours after a fraud occurs. Tom explains seller impersonation fraud, payoff fraud, and how identity verification technology is becoming essential for every title transaction in America.

About Tom Cronkright

Tom Cronkright is the CEO of SunTitle, one of Michigan’s largest independent title agencies, and Executive Chairman of Certified, a fraud prevention technology platform backed by Arthur Ventures. After his agency was victimized by wire fraud in 2015, Tom testified as a lead witness for the Department of Justice in prosecuting the North American syndicate of the Nigerian Black Axe. A licensed attorney, real estate broker, and title insurance producer, Tom is a nationally recognized expert on cybersecurity and wire fraud in real estate transactions.

Key Takeaways

  • Wire fraud is a self-insured risk because cyber insurance policies typically cap social engineering coverage at $100,000 to $250,000, far below most transaction values.
  • Banks have no legal duty to flag unusual account activity, verify account name matching, or even respond to victim fraud inquiries under current UCC Article 4A provisions.
  • The first 24 hours after discovering wire fraud are critical for recovery; immediately contact the receiving bank, file an IC3 report, and alert the Secret Service field office before filing local police reports.
  • AI has eliminated the need for domestic cybercriminals in real estate fraud, allowing overseas actors to craft perfect emails and impersonate sellers without detection triggers.
  • Seller impersonation fraud on vacant land now requires identity verification before opening title, as fraudulent driver’s licenses and passports cost only $150 on the dark net.
  • Voicemails and video calls can no longer be trusted for payment instructions because voice cloning requires only 10 seconds of audio and deepfake video is now accessible to criminals.
  • Title agencies should establish relationships with their local Secret Service office and create a documented incident response plan that includes bank contacts and notification sequences.

Episode Chapters

Time Topic
00:00 Intro and guest background
02:45 Tom’s path from law to founding SunTitle
06:20 The 2015 wire fraud that changed everything
09:15 Building Certified as a non-technical founder
12:40 How cybercriminal tactics have evolved with AI
17:30 Why banks aren’t liable for wire fraud
22:10 The insurance coverage gap for social engineering
25:00 How Certified Payoff Protect and ID Match work
30:45 Best practices when you discover wire fraud
34:20 Seller impersonation and vacant land fraud
37:50 Voice cloning, deepfakes, and future threats
40:00 Closing thoughts and recommended resources

Full Transcript

Show Full Transcript (8,009 words)

We're not required to exchange bank information. And we saw that as a meaningful tool. Again, there's a world, Mo, that 12 months from now, we're using Certified Match to validate everybody's identity on the front end. And then we open up Tidal. In a world where change is the only constant, Mo Shamil stands at the forefront, guiding Tidal professionals to not just grow their businesses, but to master the art of innovation.

With every episode, you're handed the keys to unlock unparalleled growth and stay ahead of the curve. Get ready for a transformative journey. Hello, everyone. And welcome to another episode of Tidal Agents Podcast. I'm not sure about you, but really recently, especially the last couple of years, one thing keeps me up at night is cyber security and wire fraud.

And we used to be very ashamed of talking about it, but now it's not a matter of when, but it's a matter of when. It's really that scary. And I'm really glad to have one of the experts in the industry, Cronkwright, the CEO of SunTidal, and also Chief Executive, Certified. Welcome. Thanks for having me.

Pleasure. A little quick bio before we dive into some questions. Tom Cronkwright is the Executive Chairman of Certified, a technology platform designed to safeguard electronic payments from fraud. He co-founded a company in response to a wire fraud he experienced and the rising instances of real estate wire fraud. He also serves as the CEO of SunTidal, a leading title agency in Michigan.

Tom is a licensed attorney, real estate broker, title insurance producer, and a nationally recognized expert on cyber security and wire fraud. Quick question, Tom, what don't you do? Attorney, title producer, broker, tech company. That's a lot of... Yeah, look, we've got great people around us, Mo.

That's all I can say is we've really focused on building team and talent and process. And it really enables... I think I consider it an honor to be able to lead and influence the organizations that we're involved in. So I'm not a normal guy that had some maybe abnormal experiences and decided to do things about it, so... That's awesome.

Tell me a little bit about your background, where you grew up, where school do you went, did you go to, how you get started, and how did you get into title? Yeah, born and raised in West Michigan, family-owned hardware store, so very public-facing upbringing. And from there, Western Michigan University, studying finance and economics, and then off to law school, where I met my business partner and now best friend, have been for well over 20 years now, Lawrence Stutler. And we started off with some big law firms out of law school doing corporate and transactional work. And that led us to get exposed to the title industry in a way where we saw some easy improvements to at least the service level here on the West side of Michigan.

And just accountability, communication, owning and correcting mistakes, things that we just thought were, or should be table stakes in an organization. So we had a closing at the end of 2004, that thankfully went as bad as it did, because that was kind of the straw that led us to form SunTitle as an organization and found that the very next month. So fast forward, SunTitle has now grown into one of the largest agencies. We're still an independent agency here in Michigan, residential, commercial, construction, private, public work, you name it. So we love the business.

We'll be celebrating our 20th year in business this January. And I think for, I speak for probably a lot of your listeners. It's just, there's such a life impact on real estate, whether it doesn't matter, selling, buying, expanding a business, constructing a new development. Everybody gets excited around these transactions. So that's my title background.

The wire fraud background is interesting because SunTitle was victimized by a wire fraud in 2015. And it involved a commercial transaction, a cashier's check that we had received as part of the earnest money deposit. And ultimately we wired off of that check. And days later, the check bounced, notwithstanding all the assurances from a large bank that couldn't happen. But it did.

And that led us to two years of civil litigation in the state of Texas, and then being called as a lead witness by the Department of Justice to bring to justice those people that were ultimately behind it. And it ended up being the North American syndicate of the Nigerian Black Axe that was operating out of Toronto and then had a wholesale network here stateside. So I know that's a lot in two minutes, but out of that experience Certified was founded because what we had learned, especially during the trial prep and getting to know the lead investigators from the federal agencies and Department of Justice, that technology would have to play a role in preventing what not only we experienced, but learned, probably more importantly, learned during the federal trial. And it was really around social engineering and identity protection that we have to take on as an industry to enable the safe transfer of funds. So I'll stop there, Mo, if you want to backfill anything, I'll open it up.

That's a great story, really turning the lemon into a lemonade, and now Certified has been very successful. That experience could have easily got you out of business and bankrupt, but you really turned that negative experience to a very positive experience. And now you're on a mission to safeguard funds and educate in the title industry and the real estate industry as a whole to safeguard our customers' money and funds. Yeah, I mean, you go into these things and Lawrence and I, we felt like we were called to do this. This wasn't an optional thing for a couple of reasons.

It was good for the customer. It was good for the industry. But more importantly, we felt that it was only a matter of time and we were going to face the same threat again. And if it evolved and we didn't evolve, then here we are back, probably in a worse position. And you mentioned something, I think, critically important in that could have been a loss that was too great for us to sustain.

So for your listeners, I mean, they're after everything from the $1,000 earnest money deposit to the $22.5 million commercial payoff was our largest recovery we've done to date and anything in between. And there's some number, everybody has a number and there's some number that you just can't come back from. And that's where the solution and how the solution was created was specifically designed to say, okay, I've been there on the worst day and our customers have a right not to feel that. They have a right to protect themselves from that. And yeah, we're absolutely on a mission.

It's grown now into the most sophisticated and the most concerning risk that every transaction faces. And for listeners that are in the title or real estate space, it's a self-insured risk. You can't go to your ENO or cyber or Fidelity or anything and adequately buy up enough insurance to say, hey, my worst case scenario is X and I can only get something that looks like something much less than that as far as why as a policy, if I can get into it at all. What were the initial challenges you encountered while creating a tech company focused on fraud prevention coming from a real estate background? So there was a blessing and a curse.

The curse was I'm not a programmer. I'm not a technologist. I would have to ask that question if you have a... You know what I mean? Yeah.

I have a love-hate relationship with all technology in my life. The blessing is we're industry insiders and there's more technology chasing what they believe to be a need in an industry versus technology that comes from an industry insider having an intimate experience with the very problem they're trying to solve. And I think that will continue to be the edge that guides everything we do at Certified. I know how we're educating the industry and the fact that I have this duality of I'm fighting the same fight as everyone else every single day. There isn't a day removed that we're not seeing the threats and how they're evolving and changing and new threats on the landscape.

But it was ruthlessly hard. I mean, technology is... I was so humbled by the formation and ultimately getting Certified from startup to early adoption. And then now we're moving into the scale-up phase of the business. And I describe it in two frames.

One, all of us, if we're honest, are probably not as good as we think we are. But yet, we're also so much more capable of things that we don't think we're capable of. And it was those two bookends that I describe kind of the formation and getting to Certified to where it is right now. And then just Tyler and Ben and Matt and Katie and just their early team that we assembled was just mad. I mean, it was just absolutely...

I call them glass chewers. They will chew glass every morning for this industry. And none of them are from the industry, right? They just really bought into, hey, home ownership is something worth protecting. We're bleeding for this thing.

So Certified was bootstrapped or you raised money? Yeah. Yeah. It was originally bootstrapped for quite a while by Lawrence and I and Tyler. And then it really wasn't until we got early feedback.

Certified originally was just going to be a tool for the title agency. And we went down to an Ulta conference, reserved a private room, and then just showed all the underwriter leadership from the various companies what we were doing. And categorically, we said, well, wait a sec. They said, we were facing the same issue on claims or agency base or direct ops. And if you're willing to take some feedback, there's some more work to do here.

And then you could really go to market with a product that the industry would likely absorb. So it was that point where taking... an Alta conference, reserved a private room, and then just showed all the underwriter leadership from the various companies what we were doing. And categorically, we said, well, wait a sec, they said we were facing the same issue on claims or agency base or direct ops, and if you're willing to take some feedback, there's some more work to do here, and then you could really go to market with a product that the industry would likely absorb. So it was that point where taking that feedback, understanding that we had to expand, the expansion was not just solving the, we were just gonna solve the outbound side because we got hit by an outbound fraud, the seller net or the mortgage payoff or whatever, they were also concerned about the consumer inbound side.

That was an angle that we had not anticipated before we were thinking about going to market. So we raised capital, we raised your typical seed in early stage round, then we had a series A, and then a pretty significant series B just in the last, you know, 12 months. So I've been blessed with some great early partners and adopters, but also Arthur Ventures, who's been our lead investor on A and B has been, they're just really good at helping build teams and, you know, scalable tech companies. Congratulations to get to series A or B, that's some serious progress. It's Yeah, it is.

It's hard. I'll take that. It is hard. Yes. I'm a big on startups and I read a lot and it's just a massive and it's congratulations.

Well, you think you could read your book, you read a book a month and get through it, but you, you all, you just have to make, you have to go through it yourself. I don't know what else to say. Yeah. You got to skin your own knees and fall off the bike a few times before you're riding straight down the road. How have the tactics used by cyber criminals evolved in recent years, especially in the real estate sector?

Yeah. So it started out with mortgage payoffs in that was running pretty consistently 15, 16, 17, 18. And then in 17 and 18 we started to see some buyer side frauds and seller net. So they started to hit the consumer level a little bit and then COVID hit and then COVID was this reprieve a little bit. Not that they stopped, but if you look at the statistics from the IC3, they ran off and chased PPP and unemployment scams and all this other stuff.

And then the minute that fuel burned off, they came back to BEC and the numbers doubled like an almost double in the 12 month period. So they never went down. They always, it was just flatline for a couple of years. And then now we have the advancement of AI. And I think what's happened over the last 12 months in particular is they've been able to leverage AI and some other platforms to completely remove a layer in their organization.

So Mo, it used to be, you would have, you clearly have somebody stateside that understands real estate that could craft an email without the trigger words that we're all been trained to look for. And now with AI, most of these frauds, I was speaking to a reporter this morning, most of these frauds are originating overseas and we can see that through the signals and how we can detect where things are originating from through our systems. And then once they see that money's about to move or we're approaching a closing, then they engage the domestic money laundering network. Most of them are victims themselves. Most of them are unwitting money mules, and they've advanced both the ability to profile and socially engineer somebody better emails, more timely seller impersonation fraud with the IDs that they're presenting, but also they've advanced the ability to move money.

Because cryptocurrency went mainstream in that same. So a lot of things between AI cryptocurrency scarcity of houses, right? It's like this perfect, I call it cocktail, right? Where, and now the disruption within our commissions, the disruption a year ago with the banking system, like they're just on it. So I think they've settled in, they are in their own scale up phase because you could see the early days, 2015 was their beta.

They were just testing, probing and they're trying to figure their way through maybe a dark room. That is not the case. Now, playbooks, warehouses full of cyber bad actors that show up every single day and get paid for the work that they do. Unfortunately, seeing, I don't see it slowing down because the size of the transaction is just too compelling. When you couple that with the how much information you can glean on property ownership and active multiple listing service, it's in a lot of ways.

And I hate to say this, a smart industry, if you want to do bad things and monetize those bad things. And we've seen a ton of opportunity for them to do that. You mentioned, how does that kind of expand a little more on a, how do this bad actors leverage the U S based mules? And yeah, sure. Yeah.

I'd say this isn't a statistic I can necessarily back up other than our own experience over the last several years, nine out of 10 times when money is sent into an account, nine out of 10 times when money is sent into an account, because it always goes from the sender's account to the, to what they think is the title company or the seller, the mortgage service or whoever it's going from a domestic account to a domestic account. They're not saying, send the money to Hong Kong or Brazil or crack in crypto or something like that. The recipient of that in most cases is involved in a romance scam, in a romance scam, a work from home scam, an elderly abuse scam or something that they're caught up in. And they've typically been victimized themselves. So what do I mean by that?

They'll profile register of deeds on death certificates. They'll profile divorce filings. They look at social media on, you know, toggling between profile changes. So you have a recently widowed individual, right? We ran into this in our federal trial, eight victim witnesses.

Two of us were in the title space. Six of them were older retired females that were caught up in romance scams and were built out of their entire life savings. And what would have been the inheritance of their kids? So how do they do that? Right?

They profile on social media. They start to develop this relationship, preying on the emotion of loneliness and the need for acceptance in that they will typically at some point ask them for some money. Hey, I need to hire a lawyer. I want to visit you stateside. I want to get a visa.

There's something that is usually relational based that pulls more on their heartstrings and that gets them financially invested. And then at some point, they say, well, by the way, I'm a business person and I've got this deal closing. It's closing faster than I thought. And I need to use an account. Do you mind if I send you money into your checking account and then I'll give you instructions on what to do with it?

Oh, I know by the way, you can pay yourself back the 10 grand that you sent me. That's how they're flipped into or, Hey, I'm setting up a charity. I'm wondering if you go go to the bank and here's the corporate papers. And do you mind setting up an account? And then what they don't realize is they're essentially flipped or recruited into money laundering and they're a victim themselves.

And that's hard. I guess. So where does the responsibility lie with banks, especially like when you have a new bank accounts opened, does that trigger some new accounts within let's say 90 days and all of a sudden you get a six figure amount coming to that account. Doesn't that trigger? Okay.

Something is, it doesn't sound right here. So there's two things there. I'll take the first one is account opening. And the know your customer requirements that were established under Dodd-Frank during the financial crisis says that if you're a known bad actor, then we can see that. And you're not going to open an account in this institution.

That's the know your customer in a very simplified way, right? But know your customer could never determine the actual intent of what the account is being used for. So you have law abiding citizens, great customers, longstanding members of these banks. And all of a sudden a checking account that's been open for 10 years with no problem is now used to launder money in large sums, right? The banks and we're actually going to be releasing a white paper on litigation around wire fraud and the banks under UCC article four, a in those provisions essentially have complete flyover cover for any account activity, unless they know for a fact that it's being used for some unlawful or nefarious purpose, they don't have a requirement to account name matching.

They do not have a requirement to flag unusual or anomalous behavior in an account. They don't even have a duty that if you're standing at the teller window saying, I've been defrauded and I know the money landed in this, in this bank account, they don't even have to respond to a victim inquiry. And on the, in this easier, just fact patterns that we analyzed in these cases. So I think it's a shorter conversation to say, should the banks do more? Sure.

They should do more, but legally right now, unless there's actual proof of knowledge of a crime or some criminal intent, that's about ready to take place. As long as they verify, it's the account holder that is sending the money. Then in the account number matches, they don't even have to do name matching. They're essentially absolved of liability right now in the courts. And you think, I mean, Mo it's common sense, right?

Why aren't you doing more? Like you're in the best position. We got AI machine learning. Come on, man. We were involved in a recovery.

It was 22 and a half million dollars. The money left a Southern state and ended up in elementary school teachers checking account outside of Indianapolis. Never flagged, never flagged, never frozen, nothing. Right. And I'm assuming her average daily balance wasn't 22 and a half million dollars.

Let's call it a few thousand dollars. No flag at all. That's crazy. One of the scariest part is like the, even like insurance coverage, like that you think you're protected. We had a couple fraud cases pay off and one seller impersonation.

Luckily we're able to recover by 80 to 90% of the money, but there is a limit and what cyber policies, especially. checking account outside of Indianapolis, never flagged, never frozen, nothing, right? And I'm assuming her average daily balance wasn't 22 and a half million dollars. Let's call it a few thousand dollars. No flag at all.

That's crazy. One of the scariest part is like the, even like insurance coverage, like that you think you're protected. We had a couple fraud cases pay off and one seller impersonation. Luckily we're able to recover by 80 to 90% of the money. There is a limit and what cyber policies, especially for social engineering, like majority of them would only cover up to a hundred thousand dollars and it's very difficult to get requests more, more coverage.

And that's a scary part. I think you're protected. Then let's say you have a half a million dollar social engineering, you're stuck with a, you may get a hundred thousand dollars. We don't deny it. But most of the time they deny the claim, then you have to fight for it.

So you would hope for 400k, maybe 500k was case scenario. I agree. It was a few years ago that the insurance industry is usually 18 to 24 months behind. So there was a gap there where the policy and the endorsements and the amendments to the policy hadn't quite caught up with, I guess the advancement or the proliferation of wire fraud and real estate, but they quickly caught up and said, wait a second, that's just not part of our, you know, so social engineering should by definition sit on cyber, you know, not, you know, you know, is meant to say you have professional duties and standards either through common law or statutory or employer practice law and statutes. And we're going to ensure that if somebody forgets to do something and someone else's harm that you've got insurance for that.

Okay. We can all get our heads around that. The challenge with social engineering and wire fraud is it's hard to underwrite. So Mo, I'm a buyer of yours and they bad actor spoofs your domain. I'm wiring to what I believe to be is your organization and it's diverted.

And then I sue you because you should have, could have, maybe would have done more had you known, you know, I'm out. So that's an indirect loss, but it's a cost of defense and reputational risk. How do the London or the Singapore or the Caribbean insurance markets underwrite my propensity to see that this email is a scam versus something coming from one of your employees? You know, that, that's where it gets, it's like holding water in your hand. You know, you can do it for a second, but you can't do it at scale.

So you're exactly right on indirect losses. So I am the custodian of the funds and I have a mortgage payoff loss, or I have a seller net or a large commission. Then what are the conditions precedent for me to even get coverage? Right. And you're right.

A hundred, I've heard two 50 max, but that's max. And then you gotta be able to demonstrate the seven or eight things that had you done those. You probably wouldn't have the fraud in the first place. Self-insured risk. Definitely.

Definitely. Tricky. Can you explain how certified works and it's key features that help safeguard electronic payments? Yeah. Thank you.

So two things that certified does the easy, well, they're both easy, but on the mortgage payoff side, we created payoff protect, and that is an instant validation tool that anybody that's seeking to pay off a mortgage would simply put in the credentials in the payoff letter and we'll immediately decision whether or not this is a good payoff, a known fraudulent or something that we need to go down and we'll administer the callback. And we'll put that back into the record set for you guys to move forward. So think of it as I'm out of the callback business now I can instantly verify. And when you do, you're essentially insured by our policy backed by Lloyds. So it provides, and this is direct coverage.

This isn't something that is buried in some attachment. It's not right. It is a standalone, very unique policy to protect the title industry for payoffs, right? So that's something that I call it a no brainer, but it really is just get on it, put in the information. You'll save time.

You're not going to be on hold. We'll administer the callback and then we'll put that record back in. So that's the mortgage payoff side on the inbound side, the kind of indirect loss side for, you know, buyers, mortgage companies, other title companies on a direction of funds back-to-back were able to verify the identity of the sender and then securely transmit those wiring instructions and have confirmation that they not only receive them, but they agreed to follow those. And I say that because there will continue to be this risk that we have to manage of just user behavior. We send you the information, you agree to follow it.

We met our standard of care, but you got to follow it. I mean, you got to all the way to the day of funding, you got to follow it. And best practice right now is to get those wiring instructions through certified early in the transaction. We have been involved in recoveries where the purchase agreement was still in a counter offer phase. The buyer receives a solicitation because the attorney's email was compromised and wired the entire amount of a proposed cash to close and the purchase agreement wasn't even fully signed.

Wow. So that begs like, how early are they going to get to them? We don't know. We got to assume it's day one. Right.

The other thing that certified does is it provides the ability to confirm where the money is being sent, confirming the identity and bank credentials of the seller, confirming where commissions are going, a direction of funds. I got to send it to another title company because somebody is moving out of state or they couldn't control title on the other end. And then we just launched ID match. So we announced this actually two days ago. I was going to ask you about it.

I saw it on LinkedIn. So ID match is thinking of it as like a next level validation tool for the credentials that are being presented by a buyer or seller. Our use case in our title agency is to thwart seller impersonation fraud. So vacant lands, we use ID match and we use it before we even open up title to confirm that it is actually the real property owner in fee. And then we will open up title.

And if they don't do that, we've caught frauds through this. This is a very active system and a very active landscape. And the nice thing about that is it sits early and we're not required to exchange bank information at that point. And we saw that as a meaningful tool. Again, I think there's a world mode that 12 months from now, we're using ID, we're using certified match to validate everybody's identity on the front end.

And then we'd open up title. And then if that changes, right? So now I have a validated, now if somebody starts to impersonate at the end, I've got like this marker or this instance codified in my TPS system of this was Mo and these are the credentials he presented. Well, why he presented a mission driver's license. What's with the Iowa driver's license or the passport?

See what I'm saying? So it'll be kind of fun to see how bad actors are trying to get around that. And we'll be able to detect that early because of what we did on the front end. Does that match the ID or with the property records? Make sure that those match.

Yeah, I won't be able to get into the tech, but know that it was a big build to create ID match, I mean, or certified match. We wanted it out about a year ago and we had sourced so much information and vendor partners to create the product. So it's not just one thing, Mo, it's kind of a waterfall, if you will, just like certified technology is a waterfall between digital and KBA and tokenization and bank account credentials. There's so much going on behind the scenes, but it's not just one thing. It's kind of a waterfall to make sure that what's being presented matches, not just what the DMV has, but a series of other factors.

So I know there's best practices, Alta publishes and kind of it's becoming very common. If you want to reiterate, what's the best practice when you are fall victim to cyber fraud? I know time is the essence. That's the rule number one. I think the best practice is before you fall victim that you actually create a meaningful incident response plan.

And that's something the certified team is working on more intentionally this year is to really educate around the idea that if you have an IRP, run that out, like appoint the people individual or internally on who's going to do what, who needs to be notified and what is that like sequence of notification. For example, the first thing that you would do is you would contact your bank or the bank of the consumer and have them look into the transfer and they would notify the receiving bank and alert them that this was a fraud, like something's wrong. And that receiving bank then has the ability to look into the edit account and put what's called the security hold or a freeze on those funds. The first thing you have to do is get as many signals to the receiving bank that what you just received should not be able to leave that account. It used to be that you'd have four or five days to recover funds.

Now it's like today or tomorrow and with real time payments, it's going to be like now or five minutes from now, right? Because that's how fast that rail is going to be able to enable the movement. And then having a conversation with your bank, regional banks and smaller banks are challenging because I can't tell you how many times I've been on a call with a wire desk or the bank president walking them through how to do what they need to do. How do you contact a large financial institution where the money is now sitting? You think, well, that's simple Simon stuff and they've never done it.

So make sure you run that out with your bank. If I called you today, who would I need to call and do you have a list of all the main financial institutions and their fraud departments where you could light that red phone to red phone connection up? The second thing would be file an IC3 report, ic3.gov, alert federal law enforcement of the incident. They're going to ask you for a bunch of information surrounding the incident and then contact your local secret service office, your FBI field office. I encourage everybody to develop a relationship with their closest secret service field office.

That team is absolutely phenomenal at victim intelligence, wire fraud intelligence. where you could light that red phone to red phone connection up. The second thing would be file an IC3 report, ic3.gov, alert federal law enforcement of the incident. They're gonna ask you for a bunch of information surrounding the incident, and then contact your local Secret Service office, your FBI field office. I encourage everybody to develop a relationship with their closest Secret Service field office.

That team is absolutely phenomenal at victim intelligence, wire fraud intelligence. They have a whole GEOC center in DC that we're intimately connected with, and that's what they do around the clock is just help victims get their money back. And then from there, the prosecutorial side of it and the investigative side of it, depending on the circumstance, could light up. Then you have your insurance company, you've got your underwriter, and you might have other constituents in the transaction to be aware of and notify. And then lastly, you might need to file a police report.

It's not a bad idea, but just know that if you're sitting there in the local police office and you're filling out some form at some clerk, it's going to be an interstate issue, and their jurisdiction is likely not gonna be there. Ultimately, they're gonna say, look, it crossed state lines, it went from bank A to bank B in a completely different state, and it's federal. And you could be burning very, very valuable calories and time trying the local level versus the federal level where they have rails built to help you on an expedited basis. Or just contact us, recoveryatcertified.com. We help victims around the clock, seven days a week, and we address hundreds of millions of dollars a year that's lost, unfortunately, just in real estate.

So you do recommend contacting the Secret Service directly as well? Yep, I do. If you want to shortcut everything I just said, you would contact Recovery at Certified, and then we'll walk you through what to do next step. We walk you through the whole harmless and indemnity and that whole process. We can get on the phone with your bank.

So yeah, the DIY is the beginning. Otherwise, call us, Recovery at Certified, and we'll put you in self-checkout lane. Yeah. What trends do you see? Things are evolving, especially now with AI is getting scarier and scarier.

What trends do you see coming in the near future? And what's kind of the best way for us as title agents to help mitigate those risks? Yeah, I think one of the big things that we see is the level of impersonation is gonna continue to advance. So for everyone listening, if you're working on a vacant land transaction, and I don't care if you're an agent, you're a buyer or a seller, you're in the brokerage side of it, you have to assume that you are not dealing with that property owner until you have properly validated their identity. And we're to that point on vacant or non-owner occupied properties right now.

The advancement of, it's 4 cents right now on the dark net to purchase a full identity workup. And it's about $150 to get a driver's license or a passport that will pass most scanners and come back to the real property owner with the money mules picture on it. So we've just done this quantum leap. And then with AI and the ability to replicate a voice, I was speaking to the International Right-of-Way Association yesterday morning and the gentleman putting it on, I said, speak to my iPhone for, I'm just gonna record this conversation we're having for 10 seconds. I did that.

And then three minutes later, I had mocked up his whole voice and I played that for the group. And they were just gasping, right? And there's platforms out there. So, and then you have platforms like Spoof Card that can mask phone numbers. So you have a world now where, well, I could send you a voicemail directly to your voicemail, not even ring.

And you think, man, that was weird. I didn't see it ring. And then it would be my voice instructing you to look at an email for an outgoing payment. And it wasn't me at all. So we can't trust in any way voicemails that are either directing somebody to an email or a text about payment or requesting payment itself.

Again, we have to independently verify. And that kind of stinks because that was one of those markers where it's like, well, I've been doing business with this person for 19 years, right? And I recognize the voice. I know his family. And he's telling me that he's in back-to-back closings or showings and I need to pay this HOA or I need to pay the seller wants a wire now.

And here's the email that he sent me and I'll see you at the four o'clock closing. And voicemails are anything directing towards funds payment or the engagement that would lead to a funds payment has to be independently verified. And then with the deep fake issue that came up in February of the multinational company, even video conferencing will be compromised. So I think of it, Mo, it's interesting because I think of it in terms of we have multi-factor authentication for everything. We have it for our bank.

We have it for Zoom. But what's the MFA for us as human beings? Is it a passcode? Is it- We do implement a passcode within our company. We're never instructed to send anything.

If anybody sounds like me, seems like me, ask them for the passcode. Right, yep. Is it a passphrase daily or transaction? So I think it's may sound a little bit like military spy stuff, but you have to. I mean, passphrases are being used by the military every single day now.

Don't trust me. I look like me, but it may not be me. No, exactly. And I think that's where we're going. So identity verification is going to be a must.

Technology, education, awareness plays into that. But I also think we're going to have to really think about how we verify each other's identity, even in in-person communications. Because somebody yesterday at this IRWA session, he's like, well, why don't we just go to checks? If I show up to a closing, then I can get a check and we can resolve this whole thing. I said, yeah, that only works if you've met the person before.

But in a normal closing, this is how it actually works. Most lenders don't even meet their clients face-to-face right now until the closing. That is a true statement. If they come to the closing. They don't.

The majority of them don't. If they come to the closing, right? So I have somebody walking into us on title office, our agency, and I've never met Mr. and Mrs. Smith.

I'm waiting. So the notary, our receptionist puts them in the closing room and, hey, would you like the coffee and this and that? And the notary comes in. One of the first things they'll ask for is to say, hey, while you fill out this form about your identity, the Patriot Act form, could I get a copy of your ID? And then I'll go make a copy of that for the file.

I mean, that's typically how a closing starts, right? And if you think about it, it's like, okay, two strangers walked in a door, sat down. Another stranger entered the room, asked for a piece of plastic to which they can say, okay, you were the strangers I was looking for. This is fantastic. Let's do the most important thing that you've ever done in your life financially over the next 10 minutes as a seller and 40 minutes on an FHA loan package, right?

And I said to him, I said, if you don't have a preexisting relationship, it doesn't matter. Fraudsters are willing to sit in front of a mobile notary. They're willing to sit in front of a coffee shop or a library and sign as if they are the borrower or sign for mortgage fraud or sign on the behalf of the property owner for seller impersonation fraud. I talk about how do you kind of prove identity of a person. I'm big on digital closings and Ron, I think that's the future and I think that's where we need to go.

I truly believe there'd be a higher level of security and a lot of people kind of talk it down or they think it's more fraud in digital closings or Ron, but I truly believe like with multiple authentication and re-asking the questionnaire, only you knows, but it provides some additional securities. I don't know what your thoughts about that. I believe in that. I subscribe to that. I know there've been instances, at least I've heard, where they had been able to get through some of those Ron filters.

I think if you couple, if you move that up funnel though, and if you use a platform like Certified where we have some identity markers on the front end and they're kind of re-verified through Ron and you train your people to say, hey, we got the ID here. Is it the same ID being presented here? We got the phone number here and email. Is there anything different about that? I think then I would much rather do a Ron under that circumstance than send a notary, even if it's one of the underwriter owned notary services, a national network, because they don't have that ability.

They're just looking at the piece of plastic. They're looking at the passport and I couldn't agree enough that on balance, a Ron provides filters that human beings just would never, we just wouldn't know. Well, getting very close to the end here. Do you have a favorite quote that you can share with us? I do.

My favorite quote is, if you work it hard, it's easy. And if you work it easy, it's hard. Very deep. I love it. How about a favorite book or recent book you read that you want to share with us?

I'm an avid reader, not reader, I'm an avid listener in audibles and podcasts. I'm listening right now. Books are, it's the whole saying that when the student's ready, the teacher will be found. I'm trying in my world to move from quarterback to coach to ultimately maybe an owner or somewhere between coach and owner, in the progression of personal development. And that means empowering people.

So I'm listening right now to The Infinite Game by Sinek and just recently listened to The Founder's Mentality. And The Founder's Mentality was a fascinating framing around companies that grew to a certain size, the Wall Street types to come in and run it, but you lose the texture and you lose the personality of the organization and the agility along the way. And I think for most of us on, of your listeners, we're all entrepreneurs, whether or not, you know, the grandfather or the father started it, or this was something I'm sure you started your company as did we. founders mentality was a fascinating framing around companies that grew to a certain size, the Wall Street types to come in and run it, but you lose the texture and you lose the personality of the organization and the agility along the way. And I think for most of us on, of your listeners, we're all entrepreneurs, whether or not, you know, the grandfather or the father started it, or this was something that, well, I'm sure you started your company as did we.

Those two in particular recently have been on top of the list. I'm not sure. I read Proverbs at night just to center myself. Sure. If you read, if you listen to the founders podcast, it's a great podcast, but all you name it's every founder from Steve Jobs to Bill Gates to Warren Buffett.

It's an incredible podcast. I haven't, but I got in my journal now, buddy. I'm going to, I'll do that. Can't wait to listen to Simon Sinek is one of my favorites. I haven't read that book yet.

It's a good one. I love listening to good content. So thanks for asking. Any last words to our listeners? No, I would just say, you know, stay alert and stay curious in this area.

I think we're on a journey. If somebody is, if there's any vendor or underwriter or somebody saying that, you know, we have a cybersecurity in a box and all you need to do is sign here, this statement of work, it just doesn't exist. I had a fascinating two calls yesterday and today around dark net data and around DMARC and advanced endpoint email opening protection and detection. So know that I'm as much a student as I am a teacher in this area. And I think we all need to do that.

And if you're trying to go this alone, you really can't. IT was always about the computer works at Prince. I can get to the internet, but this world of cybersecurity and identity protection and data security and infrastructure and wire, I mean, we can go on and on about all the different layers. Each one of them is a discipline in an industry in and of itself. And what I encourage you to do is if you get far enough along the journey, the narrative flips, and now you're able to distinguish yourself in market because you are doing the things mo like you're doing and that we're doing and others aren't in real estate agents and banks and attorneys and developers and builders.

Some of them will take note of that. So there's a winning strategy here on the backend. Well, thank you so much. I'm really grateful for your time and for your wisdom. And I'm sure we'd love to have you on again, especially with the things that are evolving all the time and things change rapidly.

Thank you. Have a wonderful day. Yeah. Mo, thank you. Take care.

And that's a wrap on today's journey with Mo Shamil from the Title Agents podcast, reminding you that mastering the art of innovation is key in the title industry's fast-paced world. If you're finding it tough to keep up with the changes and challenges, remember, you're not alone. Our calendar is open for you. Find the link in the show notes and let's connect. Make sure to hit subscribe to not miss out on strategies that elevate and insights that empower.

Together, we'll navigate the future of the industry. I look forward to our next meeting in the upcoming episode. Keep pushing, keep innovating, and see you in the next episode.

Top Producer?

Build your book at Alltech — DC's #1 title company.

Join Alltech →

Agency Owner?

Sell some chips off the table. Keep your future.

Partner With Us →