SardineCon SF/2026

Learn More
Fraud types4 min de lectura

¿Qué es Escrow fraud?

Suscribite al newsletter

Escrow fraud uses a fake or compromised escrow service to intercept the money in a deal between a buyer and a seller. The victim believes a neutral third party is holding funds until the trade completes, when in reality the escrow is controlled by the fraudster.

What is escrow fraud?

Real escrow reduces risk in a deal: a trusted third party holds the buyer's money and releases it to the seller only when both sides meet the terms. Escrow fraud weaponizes that trust by inserting a fake or hijacked escrow service into the middle. Whatever the victim pays in never gets held safely; it goes straight to the fraudster.

There are two common shapes. In the first, the fraudster spins up a bogus escrow site, often a convincing clone of a known brand, and steers the deal to it. In the second, the fraudster impersonates a real escrow or title company, sending altered wire instructions so the buyer sends funds to an account the criminal controls. This overlaps heavily with business email compromise and payment diversion.

For a fraud or payments team, the key idea is that escrow fraud launders trust, not just money. The victim performs a wire transfer they believe is safe precisely because a neutral intermediary is supposedly involved, which is exactly what disarms their caution.

How an escrow scam unfolds

Most escrow scams follow the same arc, from steering the deal to draining the funds:

  1. SteerPropose the escrow The fraudster suggests using escrow to seem safe, and names a service they control or spoof.
  2. Dress upMake it look legitimate A cloned website, branded emails, and fake confirmation notices convince the victim the escrow is real.
  3. CollectTake the deposit The buyer wires funds to the fake escrow account, believing they are held safely until delivery.
  4. VanishMove the money and go dark Funds are pulled out through mule accounts, the site disappears, and no goods ever arrive.

Who is involved?

Who

Their role

The fraudster

Runs the fake escrow or spoofs a real one and controls the receiving account.

The victim

A buyer, or sometimes a seller, who wires funds trusting the escrow is neutral.

The mule or receiving bank

Holds the account the money lands in first, before it is layered away.

The real escrow or title firm

Impersonated in the wire-instruction variant; often finds out only after the loss.

What it looks like in practice

A buyer agrees to purchase a used vehicle from an online listing. The seller, who is the fraudster, insists on using an escrow service for safety and sends a link to a site that looks like a well-known escrow brand. The buyer receives a professional-looking email confirming the funds will be held until the car is delivered, and wires the full amount.

The escrow site is a clone. The money lands in an account that is emptied within hours through onward transfers, the seller stops replying, and the domain goes offline days later. The bank the buyer wired from sees an authorized push payment to a plausible business name, so nothing blocked it at the time.

Why it matters to operators

Escrow fraud produces authorized transfers, so the payment leaves with the customer's own approval and clears standard checks. That makes it hard to stop at the moment of sending and hard to recover afterward, since the funds are often gone before anyone realizes the escrow was fake. For banks under authorized push payment reimbursement rules, these losses can land on the sending institution.

It also puts legitimate escrow and title companies in the blast radius: their brand gets cloned, their wire instructions get spoofed, and their real customers get burned in deals the company never touched. The defensible signal usually lives in the destination, a newly seen beneficiary, a mismatched name, a just-registered domain, rather than in the sender's behavior, which looks entirely normal.

What to watch in the data

  • Brand-new beneficiaries. First-time payees named like an escrow, title, or holding company receiving a large one-off wire.
  • Fresh domains. Escrow instructions pointing to a website registered days or weeks ago, or a near-miss of a known brand.
  • Last-minute instruction changes. Updated account or routing details arriving by email just before a scheduled payment, a hallmark of the impersonation variant.
  • Fast layering. Funds that land, then move out quickly through several accounts, consistent with a mule network.
  • Deal steering. A counterparty who insists on a specific escrow service and resists using an established or buyer-chosen one.

Quick questions

How is escrow fraud different from a normal purchase scam?

A purchase scam simply takes payment for goods that never arrive. Escrow fraud adds a fake neutral middleman to lower the victim's guard, which makes larger, riskier deals feel safe enough to fund.

Does it always involve a fake website?

No. One major variant impersonates a genuine escrow or title company and changes the wire instructions, so the victim thinks they are paying the real firm while the money goes to the fraudster.

Can the money be recovered?

Rarely in full. Because the victim authorized the wire and the funds are layered away quickly, recovery depends on speed of reporting and cooperation from the receiving bank, and often only a fraction comes back.

Where does it overlap with BEC?

The wire-instruction variant is essentially business email compromise aimed at a specific closing or purchase. Spoofed or hijacked email is used to redirect an expected escrow payment to a criminal account.

What is the strongest control?

Independent verification of escrow details through a known, previously confirmed channel, never the contact information in the deal thread, plus destination-side checks for new beneficiaries and freshly registered domains.

Qué saber junto con Escrow fraud

Reporte

Informe de Fraude y ALD 2026

Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.

Descargar reporte