Email security guide

7 signs your title company's email has been hacked

Before a closing wire is redirected, a criminal has usually been reading a mailbox for days or weeks. These are the signs to look for, and most take two minutes to check.

How the attack usually goes

A staff member enters their password on a convincing fake sign-in page. The criminal logs in and doesn't touch anything. They read. They learn which files are closing, who the buyers and lenders are, and how your processors phrase things. Days later, right before funding, the "updated wiring instructions" arrive, sometimes from the real mailbox.

The good news: a break-in leaves traces. Here's where to look.

The seven signs

  1. Inbox rules nobody created. This is the classic. Look for rules that move, delete, or mark as read any message containing words like "wire," "payment," or "invoice," or rules with blank or odd names. In Outlook: Settings, then Mail, then Rules.
  2. Forwarding you didn't set up. A mailbox quietly sending a copy of everything to an outside address. In Outlook: Settings, then Mail, then Forwarding.
  3. Sign-ins from places your staff aren't. Microsoft 365 and Google both keep a sign-in history showing location and device. A login from another country at 3 a.m. is hard to explain.
  4. Sent or deleted messages the user doesn't recognize. Check Sent Items and Deleted Items, including the "recoverable items" folder.
  5. Clients replying to emails you never sent. Or asking why the wiring instructions changed.
  6. Unexpected two-step prompts or password reset notices. Someone is trying your password. If a staff member approves a prompt they didn't start, treat it as a break-in.
  7. New apps with access to the mailbox. Criminals sometimes get a user to approve an app that can read mail without the password. Check the account's connected apps.
Check the whole office, not one mailbox. If one account was phished, others probably received the same email.

If you find one of these

  1. Don't delete the evidence. Screenshot the rule or forwarding address first.
  2. Reset the password and sign out every session. A password change alone doesn't end an active session.
  3. Remove the rules, forwarding, and any unfamiliar apps.
  4. Turn on two-step sign-in for that mailbox and every other one.
  5. Review open files. Call the parties on any closing in the next two weeks, using phone numbers you already trust, and confirm the wiring instructions.
  6. If a wire already went out, follow the first-hour response steps now.

Depending on what the criminal could see, you may have notification duties under state law and the FTC Safeguards Rule. Talk to counsel and your insurance carrier.

Make it hard to do again

  • Two-step sign-in on every mailbox, with older sign-in methods that bypass it turned off.
  • Sign-in alerts and mailbox auditing, reviewed by a person.
  • Block automatic forwarding to outside addresses.
  • Lock your domain against forgery, so criminals can't simply fake your address instead. Check yours in seconds.

Setting up and watching these controls is the core of what Title Office Guard does for Maryland title agencies.

Common questions

How do criminals use a hacked title company mailbox?

They read quietly to learn which closings are coming up, who the parties are, and how your team writes. Then, close to funding, they send changed wiring instructions from the real mailbox or a look-alike address, and hide the replies with inbox rules so the real user never sees them.

What is the most common sign of a compromised mailbox?

An inbox rule the user didn't create. Criminals add rules that move or delete messages containing words like wire, invoice, or payment, or that forward copies to an outside address.

Does changing the password fix a hacked mailbox?

Not by itself. You also need to sign out all active sessions, remove any inbox rules and forwarding the criminal added, check for apps that were granted access, and turn on two-step sign-in. Otherwise the criminal can stay in.

How do we stop a mailbox from being hacked in the first place?

Turn on two-step sign-in (multi-factor authentication) for every mailbox, block older sign-in methods that bypass it, turn on sign-in alerts and mailbox auditing, and train staff to recognize fake sign-in pages.