Fraud can take many shapes and forms, but it’s particularly worrisome in worlds that depend on the consistent flow of significant amounts of money. Few industries have as many risks as commercial real estate (CRE), where projects depend on large networks of investors, construction companies, permitting processes, tenants, and more, all connected through email, project management software, and payment processing systems.
Each contact point opens up greater vulnerabilities, and soon a simple request for payment from a seemingly trustworthy source can become a headache or worse.
Contrary to popular belief, it’s the simple exploits and mistakes that create the most fraud opportunities rather than advanced schemes. "Most fraud losses we see aren't the result of highly advanced schemes. They're the result of someone bypassing a basic control or accepting information without proper verification," says Lisa Slattery, SVP and East Coast Sales Leader for Treasury Management-Real Estate at PNC.
Fraudsters understand how commercial real estate businesses operate. They know transactions move quickly, deadlines matter, and teams are often balancing multiple priorities at once. Rather than attempting to defeat security systems, they frequently exploit human behavior and operational weaknesses.
Understanding where those vulnerabilities exist can help organizations strengthen their defenses and reduce risk.
Putting Too Much Trust in Digital Communications
Email is one of the most important communications methods in business, and it’s one of the most exploited vulnerabilities by scammers. This is because it isn’t that difficult for fraudsters to gain access to a legitimate email address, or spoof one that closely resembles a trusted contact.
In this way, cybercriminals can impersonate executives, vendors, property owners, contractors and business providers with illegitimate emails that, in some cases, are identical to legitimate ones.
This will frequently take the form of changing payment addresses, asking for the change in an email that looks as real as any.
"Fraudsters understand that payment instruction changes are often processed quickly," Slattery says. "That's why any request to change wire or ACH information should be verified through a trusted, independent channel before funds are sent."
As vendor networks grow and change, maintaining accurate account information becomes more challenging. Without strong onboarding procedures and ongoing account maintenance, one runs the risk of creating fraudulent vendor accounts or processing fraudulent charges.
To protect yourself in such scenarios, it’s important to verify any change of payment through additional validation requirements – a trusted phone number or video call – to confirm the request is legitimate. A secondary verification, along with good record keeping, are simple procedures to enact, but important to consistently maintain. In doing so, you establish a clear, easy-to-follow procedure to help protect current and future projects.
Letting Familiarity and Urgency Override Controls
Imagine this: you receive an email late in the day at the end of the week asking for an unusually large payment to be processed for a familiar vendor. The writing style is different from past emails, and the sender stresses that the payment must be sent before the weekend. While there are a few red flags, the email and company information all check out, so instead of risking the ire of your managers and vendors on Monday, you send the funds.
Unfortunately, the request turns out to be fraudulent, and come Monday, you now have much bigger problems.
This is because common red flags were overlooked for the sake of urgency, a common tactic for fraudsters.
"The most effective fraud prevention tool is often a simple question," says Slattery. "'Does this make sense?' If something looks unusual or inconsistent with past behavior, it's worth taking the time to verify."
Organizations that encourage employees to pause and investigate questionable requests can often identify potential fraud before funds leave the business. This can feel stressful at times, especially when one is trying to meet strict deadlines, but exploiting the trust that has been built with vendors, brokers, contractors, and business providers is easier than you think.
This is especially true in the developing world of artificial intelligence (AI). Now, it’s easier than ever for fraudsters to mimic voices and even faces of trusted colleagues and vendors, making additional verification of paramount importance.
"One of the biggest misconceptions is that trusted relationships eliminate fraud risk," Slattery says. "Controls should apply consistently regardless of who is making the request."
Weak Internal Controls and Oversight
When one person has the ability to initiate, approve and release a transaction, opportunities for fraud and error increase. Separating those responsibilities allows multiple individuals to review a transaction before funds are disbursed.
"Independent review can help organizations catch mistakes and detect suspicious activity before losses occur," Slattery says. "The more separation there is between key responsibilities, the stronger the control environment becomes."
While some organizations may not have the personnel to add redundancies in every area, adding some level of independent review can help catch a fraud attempt before it becomes an issue.
This is especially vital when those close to you are the ones committing fraud. It’s not impossible that a vendor, broker, or business provider you’re working with could be the ones to overbill, fake a charge, or syphon funds. In these cases, there may not be many red flags to warn you that you’re being taken advantage of, which is why you must rely on procedure to help protect you.
Solid documentation and accounting can be used to verify the accounts are balanced correctly, and that any outlying charges are scrutinized for legitimacy.
"Good documentation supports better decision-making and stronger fraud detection," Slattery says. "It creates visibility into the transaction process and can help organizations identify control weaknesses before they become larger problems."
How CRE Organizations Can Help Reduce Fraud Risk
While fraud tactics continue to evolve, the most effective defenses are tried-and-tested.
According to Slattery, organizations can reduce their exposure by focusing on a few core practices:
- Verify all wire and ACH instruction changes through a trusted, independent communication channel.
- Require additional authentication beyond email for transactions involving movement of funds.
- Establish strong vendor onboarding procedures and conduct regular reviews of vendor account information.
- Maintain clear segregation of duties so no single individual controls an entire payment process.
- Encourage employees to question requests that appear unusual, inconsistent or overly urgent.
- Keep complete documentation and audit trails for approvals, account changes and payment activity.
- Apply the same verification standards to trusted providers and long-standing relationships as to new ones.
Fraud prevention isn't about creating obstacles to doing business, it’s about creating consistent processes that can help protect your organization in the long run. In commercial real estate where significant amounts of money move quickly and multiple parties interact every day, disciplined execution of basic controls remains one of the most effective ways to prevent losses.
Most Fraud Losses Are Preventable
While the many forms of fraud may seem daunting, it’s vital to remember that protection doesn’t have to be.
Companies can help reduce risk by relying on established processes and controls that support day-to-day operations while providing safeguards behind the scenes. Organizations that verify payment changes, maintain vendor management controls, follow approval processes, and encourage employees to question unusual requests may be better positioned to identify and mitigate potential fraud and operational risks.
Once again, any successful fraud attempts occur not because criminals employ sophisticated tactics, but because basic safeguards are overlooked. Don’t be caught off guard. Plan for the worst while striving for the best every day.