Commercial real estate firms coordinate high-value payments, tenant and investor data, mobile teams, property systems, and many vendors. That combination makes identity and payment controls important, but public crime statistics do not prove that one threat is always the most common or costly for every CRE company.
Current as of 2026-08-15
The FBI’s 2025 IC3 Annual Report recorded 24,768 business-email-compromise complaints with about $3.05 billion in reported losses. The separate Real Estate descriptor recorded 12,368 complaints and about $275.1 million in losses. These categories do not establish a CRE-specific ranking.
Decision summary
- Require out-of-band verification for payment and bank-detail changes.
- Protect email, identity, endpoints, and property systems as one operating environment.
- Do not compare incomplete ransomware loss figures directly with BEC totals.
- Treat named-client case studies as reliable only when scope, outcomes, dates, and consent are documented.
Put payment controls ahead of urgency
The FBI’s BEC guidance recommends independently verifying account or payment changes through a known channel. A reply to the same email thread is not independent verification.
- Use dual approval for wires and changes to beneficiary data.
- Call a known contact using a verified number.
- Separate vendor-master administration from payment release.
- Alert banking partners immediately when fraud is suspected.
Treat identity as the control plane
Enforce phishing-resistant MFA where supported, remove stale accounts quickly, restrict administrator roles, and log high-risk sign-ins. Protect shared mailboxes and executive assistants because transaction workflows often pass through them.
Include buildings and vendors in the scope
Inventory property-management platforms, access control, cameras, HVAC interfaces, networks, tenant portals, and vendor remote access. Segment operational systems, require named vendor accounts, expire access, and preserve logs. A property technology device should not become an unmanaged bridge into corporate systems.
Plan recovery around business processes
Back up critical documents and configurations, test restoration, and maintain manual alternatives for tenant communications, payment approvals, and property operations. Ransomware loss reports exclude many indirect costs and are underreported, so plan from business impact rather than a single public average.
For related guidance from ITECS, see ITECS IT services for commercial real estate.
Sources and update trigger
Review trigger: Refresh after the next IC3 annual report or a material change to CRE payment, property-system, or vendor-access risk.
