NearSeal

2026-08-26

Buying a home means emailing your financial life to strangers. Should those documents be encrypted?

Buying a home is the one time most people email their entire financial life to strangers. A standard mortgage application asks for recent pay stubs, W-2s or two years of tax returns, months of bank statements, and a government photo ID — more if you're self-employed. Between offer and closing, copies of those files fan out to a loan officer, a real-estate agent, a title company, an escrow officer, sometimes an attorney — a chain of inboxes and back-office systems you will never see and can't audit. That concentration is worth taking seriously for two specific, well-documented reasons: the industry that ends up holding your closing file has one of the worst document-exposure records on record, and the email threads carrying that file are exactly where a distinct crime — closing wire fraud — gets its foothold. This post walks through both, and then is honest about which part of the problem encrypting your own files can actually address.

The industry holding your closing file has a track record

In May 2019, Krebs on Security revealed that First American Financial — one of the largest title insurance companies in the United States — had been exposing roughly 885 million documents from real-estate transactions dating back to 2003 on its public website: bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts, and driver's license images. The flaw was not an exotic hack. Anyone who had a link to one document could read other people's documents by changing a single digit in the URL — no password, no authentication of any kind. New York's financial regulator later charged the company over the leak, and the case ended with a $1 million settlement in late 2023; the SEC's separate action over the company's disclosure failures settled for what Krebs called a "farcical" penalty of under $500,000. Four years later it was the other title giant's turn: in November 2023, Fidelity National Financial was hit by ransomware attributed to the ALPHV/BlackCat group, disclosed that data on approximately 1.3 million customers was stolen, and had to block access to its own systems for about a week — disrupting title insurance, escrow, and mortgage transactions nationwide while closings stalled. None of this means your particular title company is careless. It means the destination of your document pile is a category of company that attackers demonstrably target and that has demonstrably leaked, at industrial scale, the exact document types a mortgage requires.

The email thread is where wire fraud starts

The second problem lives closer to you: the transaction's email threads themselves. Real-estate closing fraud is a specialty within what the FBI calls business email compromise (BEC): criminals get into an inbox belonging to someone in the deal — an agent, a title or escrow officer, sometimes the buyer — then quietly read along. The thread tells them everything: who the parties are, what stage the deal is at, when money is due. At the right moment they send wire instructions that look like they come from the title company, pointing at an account they control. The FBI's Internet Crime Complaint Center counted 21,442 BEC complaints totaling $2.77 billion in reported losses in 2024 alone — its 2024 annual report describes one victim who, while closing on a property, received an email from the compromised account of their "title company" with wire instructions for over $1.3 million to a fraudulent bank account — and the FBI's own September 2024 public service announcement puts cumulative BEC exposure at more than $55 billion over the preceding decade. This is not rare at the level of an individual closing, either: in CertifID's 2026 State of Wire Fraud report, 26% of surveyed home buyers and sellers said they received suspicious or fraudulent communications during their closing, 4.7% reported actually becoming wire-fraud victims, and buyer cash-to-close fraud — the fake-instructions scenario above — was the most common variant, with a median loss of $239,850. The firm's previous year's report found first-time buyers were three times more likely to be victimized than experienced ones — the people least familiar with what a normal closing looks like.

One closing, many copies of your documents Sent in the clear Loan officer, agent, title, escrow — every inbox holds a readable copy of your pay stubs, statements, and ID An intruder in any one mailbox harvests all of it — and learns when to send fake wire instructions Encrypted before sending Every copy in every inbox is ciphertext; the passphrase travels by phone, never in the thread A mailbox intruder gets no readable documents — though wire amounts still need phone verification regardless
The same closing, two ways: encrypting the attachments doesn't shrink the number of copies, it changes what each copy is — from a readable document into ciphertext whose key never entered the thread.

What encrypting your documents actually changes

You can't shorten the chain of parties, and you can't patch the title industry. What you do control is the form your documents are in when they enter that chain, and what remains readable in all the places copies accumulate. Encrypt a file before you attach it, and read the passphrase to your loan officer over the phone — a call you should be making anyway, as we'll get to — and the calculus of a compromised mailbox changes concretely. The intruder reading the thread still sees who is talking and when, but the attachments they harvest are ciphertext: the bank statements, tax returns, and ID scans that would otherwise be the identity-theft payload of the haul are unreadable without a passphrase that never appeared in any message. The same is true of the copies that outlive the transaction — the ones sitting in your own sent folder years later, in your Downloads folder, and in the closing-package archive you keep. Those long-lived copies are entirely yours to protect, no counterparty's cooperation required, and they are precisely the files a future compromise of your own email account or laptop would otherwise serve up whole. If your lender offers a genuine secure-upload portal, use it — that's the right tool for that hop. Client-side encryption earns its place for the hops where plain email is the only channel anyone will accept, and for every copy that stays behind afterward.

What it honestly can't do

Two limits, stated plainly. First, the parties in the deal need to read your documents to do their jobs — the title company decrypts what you send and stores it in its own systems, and from that moment your encryption no longer protects those copies. Nothing you do on your side would have changed what First American's website leaked. Encrypting what you send shrinks your exposure surface — every inbox, forward, and leftover copy along the way — but it cannot extend into the counterparty's infrastructure. Second, encryption does not by itself stop wire fraud, because wire fraud doesn't require reading your documents — it requires convincing you at the right moment. The defense for that is procedural, and it's the one the FBI's PSA spells out: verify wire instructions, and any change to them, by calling a number you obtained independently — from the first in-person meeting or the title company's verified website, never from the email that delivered the instructions. The pleasant coincidence is that encrypting your attachments gives that phone call a second job: the same call that verifies the account number is the channel that carries the passphrase.

Where NearSeal fits

NearSeal encrypts files entirely in your browser. The file and the passphrase never leave your device — there's no account, no upload, and you can watch the network tab confirm that nothing is transmitted. Encryption is AES-256-GCM with a key derived from your passphrase via PBKDF2-SHA256 at 220 iterations, and on decryption the file is recognized by its actual bytes, not its name or extension — so a title company employee on the receiving end just opens the same website, drops the file in, and types the passphrase you read them. Nothing to install matters here: you cannot ask an escrow officer to set up software, but you can ask them to open a web page. For the closing archive you'll keep for decades, consider the opt-in age-encryption.org format — age files open in the official age CLI, rage, and every other age-compatible tool, so the archive's future isn't tied to this website's. One caveat applies with full force: there is no recovery. Nobody, NearSeal included, stores your passphrase, so a forgotten passphrase means an unreadable file — write it in a password manager or somewhere equally durable before you send anything. Then the documents from the largest financial transaction of your life stop being the readable payload in a dozen strangers' inboxes, and become ciphertext everywhere except the two ends of a phone call.

Sponsored
← NearSeal

This page shows ads only if you consent.