Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Brian and Wendy VanDoeselaa were in the final days of buying a condo in West Michigan when new wiring instructions arrived. The email appeared to come from the mortgage professional they had been dealing with for weeks. The phone that rang afterwards displayed a number Brian already recognised. The person speaking sounded like the lender he had spoken to before. He wired 66,000 dollars to the account he was given.
CNN reported the case on 15 September 2026. CertifID, the fraud prevention firm that later reviewed the transaction with the couple, attributes it to AI voice cloning combined with spoofed email and a spoofed caller ID. The part worth sitting with is not that a buyer was fooled. It is which safeguard failed. Brian confirmed the instructions by voice, which is exactly what homebuyers are told to do.
The couple found out on the morning of the closing. The title company rang to check they would be bringing the certified funds, and the sellers were already driving in from another part of Michigan. Brian believed he had paid days earlier. The 66,000 dollars had never reached anyone handling the real closing.
The mechanism is three ordinary tricks stacked in the right order. The first is business email compromise, or BEC, where an attacker gets sight of a transaction, usually through the mailbox of one of the parties, learns who is involved and waits for the moment a large payment is expected. The second is caller ID spoofing, which is not really hacking. The number your handset displays is a field the calling system fills in rather than something the network verifies, so over an internet phone line it can be set to any number the caller likes, including one already saved in your contacts. The third is the voice. Cloning software needs only a short audio sample, and mortgage officers, estate agents and title staff are among the most publicly audible people in any transaction: webinars, listing videos, podcast appearances, outgoing voicemail greetings. Stack the three and every channel a buyer might use to check the instructions reports back that the instructions are fine.
Sixty-six thousand dollars is a modest figure in this category and a ruinous one for the couple who lost it. CertifID's 2026 wire fraud data puts buyer cash-to-close fraud, the exact pattern here, at 30 percent of the cases it accepted for recovery, with a median loss of 239,850 dollars. Mortgage payoff fraud carries a median of 389,125 dollars. These schemes do not take a slice of a transaction, they take the transaction.
The lesson generalises well past property, and it lands on a control most finance teams believe they already have. Look at any process where someone is cleared to move money once they have confirmed the request by phone, and ask what that confirmation actually tests. If the call came in and the screen showed a name from the address book, it tested nothing beyond the attacker's willingness to type a number into a web form. Direction is the whole control: a call your side places to a number held before the request existed is a different thing from a call you receive, because a spoofed caller ID cannot make your outbound call ring on a criminal's phone. Underneath sits a change most awareness training has not caught up with. A familiar live voice used to be reasonable evidence of identity, and the industry's own figures now describe voice fakery as routine rather than exotic. The FBI still files homebuyer wire fraud under business email compromise, which is accurate about where these schemes came from and an increasingly poor description of what the victim experiences.
Keep the sequence: an email, then a call that confirmed it, then the wire. That is not carelessness, it is the standard advice being followed and losing. The only part of the chain an attacker cannot reach into is a number you already had and a call you place yourself. Take it to your next review in the plainest form available: when somebody in your organisation verifies a payment by phone, who dialled?

