Cybersecurity Threats and Their Impact on Real Estate Transactions

Standard

Imagine arriving at your real estate closing only to learn that the county’s property records are unavailable. If the documents can’t be recorded, then the transaction may be left hanging in the air. Depending on lender funding requirements, the closing attorney may not be able to disburse the funds, and the buyer may not be able to receive their keys until recording is available. It sounds far-fetched, but it’s exactly the type of disruption that recent cyber-attacks on county governments have made possible.

Most people never think about their county recording office until they’re buying or selling real estate. Deeds, mortgages, easements, plats, liens, and other documents are quietly recorded every day, creating the public record that establishes who owns property and what interests affect it. It’s a system that has worked for generations because it relies on one simple principle: the public records must be accurate, complete, and accessible.

Recent events in South Carolina serve as a reminder that this system is more fragile than many people realize.

A recent cyber attack disrupted access to property records and other county services, temporarily preventing normal operations. While the details of the investigation continue to emerge, the incident highlights just how dependent modern real estate transactions have become on digital access to public records. Unfortunately, this is not an isolated event. Several South Carolina counties have experienced technology failures, ransomware attacks, or other disruptions in recent years.

Cyber security, however, is only one challenge facing county recording offices.

Many counties across the state operate with limited budgets and skeleton crews. Employees often process hundreds of documents each day while balancing increasing demands and aging technology. Even the most dedicated public servants can struggle when resources are stretched thin. Under staffing and insufficient training increase the likelihood of recording errors, indexing mistakes, or delays in processing documents – all of which can create headaches for property owners years later.

The integrity of the public record is essential because virtually every real estate transaction depends on it.

Before issuing title insurance, conducting a closing, or approving a mortgage loan, attorneys and title professionals examine the public records to confirm ownership and identify any issues affecting the property. They are looking for deeds that properly transferred title, unreleased mortgages, judgments, tax liens, easements, restrictive covenants, and countless other matters that could affect ownership rights.

If those records are unavailable because of a cyber attack, the transaction may be delayed. Buyers may not be able to close on schedule. Sellers may miss contractual deadlines. Lenders may refuse to fund loans until title can be verified. Even a short interruption can create significant inconvenience for everyone involved.

More concerning are situations where records have been altered, corrupted, or improperly indexed. The public recording system functions because people can trust that what they find is complete and accurate. Preserving that trust requires not only secure computer systems but also adequate staffing, proper training, and ongoing investment in the offices that maintain these records.

Although county governments bear much of the responsibility for protecting these systems, cybercriminals often gain access through surprisingly simple methods.

Many cybersecurity incidents begin not with sophisticated hacking tools but with social engineering. Rather than attacking computers directly, criminals manipulate people into providing passwords, opening malicious attachments, or clicking fraudulent links. These phishing emails are designed to look legitimate and frequently impersonate trusted organizations, coworkers, financial institutions, or government agencies.

While this blog focuses on real estate law, cyber attacks and scams aren’t limited to real estate transactions. Anyone, not just government employees, can become a target. A few simple precautions can dramatically reduce the risk of becoming a victim. Be cautious of unexpected emails requesting urgent action. Verify unusual requests through a separate phone call or trusted contact information rather than responding directly to the email. Avoid opening attachments or clicking links unless you are confident they are legitimate. Enable multi-factor authentication (“MFA”) whenever possible, and keep software updated to address known security vulnerabilities.

These habits protect more than your personal information. They help protect the institutions that communities depend upon every day.

County recording offices rarely make headlines when everything is working properly. Yet they perform one of the most important functions in our legal system by preserving the history of property ownership and ensuring that buyers, sellers, lenders, and attorneys can rely on the public record.

As counties continue modernizing their technology, cybersecurity must remain a priority. At the same time, we should not overlook the importance of investing in the people responsible for maintaining these records. Secure systems, well-trained staff, and accurate public records are not simply administrative conveniences: they are essential to protecting property rights and keeping South Carolina’s real estate market functioning smoothly.

Two new fraud scams

Standard

The fraudsters keep updating their repertoires!

Fraudsters are creative! It seems as soon as we learn and educate our staff members about new fraud schemes, the swindlers change their schemes to keep us on our toes. I wanted to pass along two new schemes that recently came to my attention.

The first was reported in our company publication, Fraud Insights, and it involved a residential sale in Las Vegas. An astute title insurance company employee, Larissa Conrad, was able to frustrate the fraudster’s plans. Here’s how the scheme unfolded. On March 7, Larissa sent an estimated closing statement to the listing agent. The closing involved the payoff of a Wells Fargo mortgage. The listing agent purportedly sent back to Larissa, by email, an “updated” payoff statement. Larissa compared the two payoff statements carefully. The wiring instructions were particularly troubling:

Larissa called the payoff lender and confirmed her suspicion that the second payoff was from a fraudster. She then called the listing agent, using a trusted telephone number, and reported that someone was posing as him in the transaction and sending emails from an account that looked like his. She wired the correct payoff amount using the correct wiring instructions, saving $153,300.37.

The second scam, involving texting, was reported by CyberheistNews. The victim receives a text asking whether a password reset for a Gmail account has been requested. If not, the text advises, please reply with the word “STOP”. If the victim replies with “STOP”, the next text urges the victim to send a six-digit numerical code in order to prevent the password from being changed. By sending the code back to the attacker, the victim is enables the bad guy to complete the password change and to have access to the account and all its email.

Remember that Google and other companies will not ask whether you don’t want to do something with your account. A reply to a text like this often notifies the fraudster that a valid telephone number has been reached.

two factor authentication

A two-factor authentication process is highly recommended because it provides an additional layer of security and makes it harder for attackers to gain access. The victim’s password alone is not enough to pass a two-factor authentication process. Typically, the first authentication factor would be based on knowledge (a password) and the second factor would be based on possession (of an ID card, a token or a smartphone, for example). Ask your IT professionals for assistance is keeping your accounts safe by using this process.

And, as always, the best advice may be to keep schooling yourself about the various scams as they are reported. I’ll do my best to help!