View all Managed IT services →
View all IT Services →
View all Cybersecurity services →
View all Cloud services →
Network Management & Security
Network Management Network Security

In the Phoenix metro, the businesses most exposed to this particular attack are not the ones people expect. They are title agencies, escrow offices and real estate brokerages between five and fifty staff. They move other people’s money on a published schedule, they coordinate with parties they have never met in person, and Arizona publishes most of the reconnaissance an attacker needs for free.

Axio Networks supports businesses in exactly that range across Scottsdale, Phoenix, Tempe, Chandler, Mesa, Gilbert and Fountain Hills. Across our client base, phishing is the initial access method in effectively every intrusion attempt we see, and we remediate several business email compromise and fraudulent wire attempts a month. Almost none of them reach a user’s inbox, because they are filtered before delivery. The ones that matter are the ones that would have landed somewhere with no filtering, no monitoring and nobody reviewing alerts.

What follows is how the attack actually runs against a Valley title office, what the current lure looks like, and the five points where it breaks. The company described is composite. The methods, the public data sources and the observations about what we find during onboarding are real.

Arizona publishes your org chart for free

The reconnaissance phase of this attack does not require a breach, a purchase or any special skill. It requires a browser and about twenty minutes.

The Arizona Department of Real Estate public database is free and requires no login. Search a brokerage and it returns the licensed employee roster, branch offices, the designated broker and branch managers, plus employment history and any disciplinary actions for individual licensees. For an attacker, that is an org chart maintained by the state, with the person who has authority helpfully identified by title.

The Maricopa County Recorder makes recorded documents searchable by name at no cost, and unofficial copies can be viewed online for free. Deeds and deeds of trust are included. That means an attacker can search a party’s name and read who is transacting, on what property, for how much, and which title company handled the last one.

Put those two sources together and the attacker no longer has to guess when money is moving or who is handling it. Arizona corporate filings fill in the registered entity and agent. None of this is scraped, stolen or bought. It is published, and it is not going to stop being published.

This matters because it removes the step most people assume protects them. The attacker is not casting a wide net and hoping. They know your closing coordinator’s name, they know who signs off on a wire, and they can see that a transaction is in flight.

The lure that is actually working right now

The phishing email that gets through today does not look like a phishing email. It looks like Dropbox, or it looks like DocuSign, because it is Dropbox and it is DocuSign.

The pattern we see most across title, escrow and real estate clients is an attacker using a legitimate, paid-for Dropbox or DocuSign account to send a real notification about a real file. The document itself carries the credential stealer. Every technical signal that email security is built to check comes back clean:

This is why “train your staff to spot phishing emails” has stopped being a sufficient answer on its own. There is nothing to spot. A closing coordinator who receives twenty DocuSign notifications a week and correctly opens all twenty is not being careless when she opens the twenty-first.

Defending against this is a filtering and detection problem, not an attentiveness problem. It needs email security that evaluates the payload and the behaviour rather than the sender’s reputation, and it needs something watching the endpoint for what happens after the file is opened.

What the credential is actually for

The stolen credential is rarely used to encrypt anything on day one. It is used to read.

Once inside a mailbox, the attacker is looking for the transaction calendar: which closings are scheduled, which lender is involved, who the buyer is, what the wiring instructions normally look like, and how your office phrases them. They will often create an inbox rule that quietly forwards or files messages so they can keep reading without the mailbox looking unusual.

The dwell time is the point. An attacker who sends a fraudulent wire request on day one is guessing. An attacker who has read three weeks of your correspondence knows the buyer’s name, the closing date, the exact amount and the tone your escrow officer uses. The fraudulent email is a copy of a real one, sent at the moment a real one is expected.

The wire

The loss event in this vertical is usually not the ransom. It is the wire.

The FBI’s Internet Crime Complaint Center recorded $275.1 million in real estate fraud losses across 12,368 complaints in 2025, and $3.04 billion in business email compromise losses across 24,768 complaints. Total reported cybercrime losses reached $20.8 billion, up 26 percent year over year. Real estate and title sit at the intersection of both categories, which is why this vertical draws the attention it does.

The mechanics are mundane. A message arrives that appears to come from a party already in the transaction, providing wiring instructions for the first time or correcting instructions sent earlier. The account details are the attacker’s. The funds move once, and they are gone.

Whether any of that is recoverable depends on a policy detail most businesses have never checked. Fraudulent wire losses usually sit under a separate social engineering or funds transfer fraud endorsement with its own sublimit, not under core coverage — we cover that, and what else gets denied, in cyber insurance for Arizona small businesses.

Five places this attack breaks

None of these are exotic. Most of them are capabilities already bundled into tools a business is already paying for, which is exactly why they get missed.

1. Filtering that does not trust the sender’s reputation. Because the Dropbox and DocuSign lures pass every authentication check, the control that matters is inspection of the payload and the behaviour, not the envelope. When we deploy email security for a new client, we deliberately run it in learning mode first so it can ingest that client’s normal traffic before it moves into enforced mode. Title and escrow offices send and receive an unusual volume of legitimate documents, and a filter tuned on generic assumptions will either miss the real threat or bury the team in false positives.

2. Detection on the endpoint. Huntress goes on every machine on day one of onboarding, before anything else is tuned. If a credential stealer executes from an opened document, that is where it surfaces. The email layer is a filter with a failure rate; the endpoint layer is what catches the thing that got through it.

3. Control at the network edge. A Sophos XGS firewall covers the other half of the same problem. Huntress works at the device level and the XGS works at the network level, and the reason we run both is that this attack chain crosses between them. Command-and-control traffic leaving a compromised workstation is a network event, not an endpoint one.

4. Phishing-resistant sign-in. Passkeys have become genuinely easy to deploy, particularly now that they sync through password managers, and we see very little client resistance to them compared with a few years ago. A stolen password is worth nothing against a passkey, and a captured session token is worth much less against Conditional Access policies that require a known, compliant device. Microsoft has had number matching enabled by default for Authenticator push notifications since May 2023, which closed the simpler push-bombing attack, so the current bypass worth defending against is adversary-in-the-middle proxying.

5. Somebody actually reading the alerts. This is the one we see fail most often, and it is worth being blunt about. At nearly every business we onboard, the problem is not that security tools are absent. It is that the tools that exist were never fully configured, nobody owns them, and nobody is watching what they produce. Alerts fire into an empty room. This is the entire argument for managed detection and response over another unmanaged licence. Everyone involved is trying their best; it simply drifts that way on its own when it is nobody’s specific job. Microsoft 365 Business Premium will raise an alert when a new inbox forwarding rule is created. That alert is only worth something if it lands somewhere a person looks.

The wire verification rule we give every client

This is the single control that stops the loss even when everything upstream has failed, and it costs nothing.

Any time you receive wiring instructions for the first time, or a request to change instructions you already have, you verify by voice before any money moves. That part most people know. The part that gets skipped is how you get the number.

Do not call the number in the email. If the message is fraudulent, the number in it is the attacker’s, and they will confirm their own instructions convincingly. If you have an established relationship, call the contact you already have on file. If it is a first-time counterparty, look the company up independently, go to their website, call the main number listed there, and ask to speak to the specific person by name. Then verify the details with them directly.

It adds a few minutes to a closing. It is the difference between a near miss and a wire that cannot be recalled.

What we actually find in the first week

We onboard new clients the same way every time, and the findings are consistent enough to be worth publishing.

The first pass is a health check across every system: cleanup, updates, correct applications installed, everything current and optimised, so there is a known-good baseline to work from. Huntress is deployed day one so the environment stays clean while the rest is being tuned. Email security goes in next, in learning mode before enforced mode.

The finding that comes up without fail, at essentially every onboarding, is a plain-text password file. A passwords.doc on somebody’s desktop, or an Excel sheet with every login in it, unencrypted. There is always at least one. It is never malicious and it is rarely the person you would guess — it is usually the most organised person in the office, who needed a system and built one.

That file is the reason a single opened document can escalate from one mailbox to the whole business. It is also the fastest thing on this list to fix, and it is why a password manager is a security control rather than a convenience.

Three questions to send your IT provider

If you want to know where you stand without commissioning an assessment, these three cover most of where the attack above succeeds.

  1. Are we using phishing-resistant sign-in — passkeys, FIDO2 keys or Windows Hello for Business — for anyone who touches wires, finance or administration?
  2. Is external email forwarding blocked at the tenant level, and would we know if someone created a forwarding rule today?
  3. Where do our security alerts go, and who read the last one?

The third question is the one that tends to produce a pause.

Frequently asked questions

Why are title and escrow companies targeted more than other small businesses?

Because they move large sums on a schedule that is partly public, and they routinely transact with parties they have not met. An attacker who reads a mailbox for two weeks can time a fraudulent wire request to a real closing. The FBI recorded $275.1 million in real estate fraud losses in 2025 alongside $3.04 billion in business email compromise losses, and this vertical sits where those two categories overlap.

How do phishing emails from Dropbox and DocuSign get past email filtering?

Because they are genuinely from Dropbox and DocuSign. Attackers use legitimate paid accounts on those platforms to send real notifications about a real hosted file, and the file carries the credential stealer. SPF, DKIM and DMARC all pass, and the link points to a domain with an excellent reputation. Filtering that scores the sender rather than the payload has nothing to catch.

Is security awareness training still worth doing?

Yes, but not as the primary control. Training helps people question an unexpected wiring change or an out-of-pattern request. It does not help someone identify a genuine DocuSign notification as hostile, because there is no visible tell. Treat training as one layer and put the weight on filtering, endpoint detection and sign-in that cannot be phished.

What is adversary-in-the-middle (AiTM) phishing?

The attacker hosts a proxy that mirrors a real login page, such as Microsoft 365. The victim enters credentials and approves the MFA prompt as normal, the login genuinely succeeds, and the proxy captures the resulting session token. Because the session is already authenticated, standard MFA does not stop it. Phishing-resistant methods and device-compliance policies do.

We already have Microsoft 365 Business Premium. Are we covered?

You are licensed for a great deal of what you need, which is not the same thing. In most environments we take over, the capability was purchased and never configured, and the alerts it generates were never routed to anyone. The gap is almost always configuration and monitoring rather than licensing.

What should we do first if we think a wire has already gone out?

Contact your bank immediately and ask them to initiate a recall, then report it to the FBI at ic3.gov. Speed matters more than anything else — recall attempts have a far better chance within the first 24 to 72 hours. Preserve the email evidence rather than deleting it, and get your IT provider into the mailbox to establish what was accessed and for how long. If systems were encrypted as well as drained, that becomes a ransomware recovery engagement.

Sources and further reading

Talk to an IT team in Scottsdale

Most of the gaps described above are closed by controls that are already bundled with tools small businesses pay for — the work is turning them on and keeping them on.

Axio Networks is a managed IT and cybersecurity provider based in Scottsdale, Arizona. Founded in 2019, we support small and mid-sized businesses across the Phoenix metro — Scottsdale, Phoenix, Tempe, Chandler, Mesa, Gilbert and Fountain Hills — with an under-30-minute average response time.

Start with a free IT assessment, call 480-602-2946, or email [email protected].

Related: Cybersecurity services · Security assessments & audits