Think you know how to spot a fake? A familiar email, a trusted voice or even a building ID card—nowadays none of these necessarily proves you’re dealing with the real person.
AI is giving scammers new ways to impersonate clients, agents and parties in a transaction, and it’s making fraudulent messages harder to spot, cybersecurity experts said during a recent webinar, “Cybersecurity in the Age of AI,” hosted by the National Association of REALTORS®’ Tech & Innovation team.
Joshua Sklüt, CEO of SKLÜT, a biometric facial recognition company for buildings and a 2026 participant in NAR’s REACH accelerator program, put the challenge simply: “You just don’t know what’s real until you can prove it. In the age of AI, proof is key.”
An attacker can use AI to research a listing, build a profile of the agent and transaction, craft a convincing message, monitor an email thread and ultimately send fraudulent wire instructions timed to closing. A cloned voice or other manipulated media can add another layer of false credibility.
“Voice alone is no longer reliable proof of identity,” said Sebastian Drywa, NAR’s director of cybersecurity.
The Red Flags to Watch
AI didn’t create phishing, business email compromise or impersonation scams, but “AI has weaponized them”—making these scams much faster to replicate, more targeted and more convincing, Drywa said.
Related: What’s Real, What Isn’t? How to Spot Deepfakes, AI Real Estate Scams
Mike Woodward, NAR’s director of data science, also warned that even a small amount of publicly available audio and video—a mere three seconds of it—or imagery can be used to create a convincing deepfake or synthetic media used to dupe unsuspecting parties in a transaction. That makes traditional cues—like recognizing a voice, an email address or even seeing a familiar photo—less reliable as proof of identity.
The speakers highlighted several warning signs real estate professionals should watch for, including:
- A sudden change to wire instructions. Treat any new or change to payment information as a reason to stop and verify.
- A request that doesn’t fit the normal transaction pattern. An unusual request from a familiar looking contact can still be fraudulent.
- Unexpected urgency. Pressure to act quickly—especially around money—should trigger more verification, not less.
- A message or caller that seems unusually convincing. A familiar voice, email account or writing style is no longer enough to base identity or verification on.
Related: New NAR Fraud-Fighting Site Takes Aim at Real Estate Scams
How to Protect Your Next Transaction From AI-Enabled Fraud
It’s not as easy as just becoming better at spotting AI-generated fakes; the scams are constantly evolving and growing more sophisticated. It’s about building verification into the transaction so that no single email, phone call or credential is treated as sole proof of identity, the cybersecurity experts said. Drywa recommends:
Set a code word early. When a contract is signed, agree on a code word that can be used only with clients and the title or closing company. Ask for the code word to verify identity and before any money is moved.
Don’t trust new wire instructions. Tell clients upfront that wire instructions should never change by email, without being verified separately.
Verify through a known channel. If a request seems suspicious, call a phone number you already have—not the phone number included in a new message.
Slow down when there’s urgency. An urgent request to change payment information should trigger more verification, not faster action, Drywa said.
Related: Protecting Your Clients and Your Business From Fraud
Physical Security Has an AI Problem, Too
The same principles apply beyond the transaction itself. Sklüt said physical access to commercial and residential buildings or even events also needs to move beyond credentials that can be copied, stolen or spoofed. He called out picture badges, driver’s license numbers written in a booklet, a lockbox code and sign-in sheets—“that is not security. That is security theater,” he said.
AI-generated headshots and cloned voices could make it easier for an impersonator to appear legitimate, even when trying to gain physical access to a building. Sklüt gave examples of someone using a cloned voice to call a building and asked to be buzzed in.
His company uses multiple forms of verification, combining a phone-based identity check, government-issued identification and biometric matching before granting access. The approach can be used in commercial and residential buildings, as well as multifamily properties and short-term rentals, he said.
Don’t Feed Sensitive Information Into AI Tools
The threat isn’t only external. Woodward also warned that AI tools can create data-leakage risks when employees enter sensitive information in large language models, like ChatGPT, Claude and Gemini, among others. Brokerages should establish clear policies about what information can—and cannot—be entered into AI tools, he said.
Woodward also urged real estate professionals to keep operating systems, devices, modems and other connected equipment updated with the latest security patches.
“The likelihood of anyone encountering an attack because of fraud has increased significantly,” Woodward said. “It’s become much more important to maintain your defenses. Any slack you may have had on this before has to be gone.”
After all, as Sklüt notes, “when you let your guard down, that is when they strike. Be as diligent as you can and constantly verify.”









