There was a day or two where we’d directed the previous lender to transfer title, and had already wired $100K’s to an unknown escrow service half a state away.
I didn’t sleep all that well until the previous lender said they’d received a wire for the amount due on the loan.
It’s not surprising that, among the paperwork we signed, there were multiple FBI notices about avoiding wire fraud.
Note that PKI didn’t help much with this transaction. All “secure” communications were delegated to entities that I had no reason to trust (e.g., subdomain.docusign.com).
I did check some license numbers here and there, and called the phone numbers the license holders registered with the government. So, the SSL cert on the .gov site helped (though even that is hit or miss, since it relies on domain registers confirming all the sites they allow are actually government entities.)
I also called the office number I found at $MEGABANK’s website to make sure they’d heard of me.
Beyond that, I had no reason to think $TOTALLY_LEGIT_ESCROW.com was not a phishing front.