Inform | Influence | Empower

Website Search:

The “Interested Buyer” Zoom Scam: A Growing Cybersecurity Threat Targeting REALTORS® and Real Estate Brokerages

Posted on 08/05/2026

The real estate industry has become one of the most attractive targets for cybercriminals. With high-value transactions, frequent email communication, and sensitive financial information changing hands daily, REALTORS® and brokerages are increasingly finding themselves in the crosshairs of sophisticated scams.
One of the latest threats involves scammers posing as motivated home buyers who claim they’re ready to submit an offer—but instead attempt to install malware on your computer and gain access to your business.
This scam doesn’t rely on hacking software vulnerabilities. Instead, it relies on manipulating people.
Here’s how it works—and how you can protect yourself and your brokerage.

How the Scam Begins

The attack usually starts within hours or days of a new property being listed.
An agent receives a text message from an unfamiliar phone number, often from another state.
The sender claims they are interested in the property, have proof of funds, and are prepared to make an offer quickly.
For busy REALTORS®, this sounds like a promising lead.
That’s exactly what the scammer wants.

Step One: Establishing Trust

Once you begin responding, the individual introduces themselves by name and often sends what appears to be a personal photo.
The image is intended to make the conversation feel legitimate.
In reality, the name is frequently fictitious, and the photo has often been stolen from someone else’s social media profile or other online source.
This is a classic social engineering technique designed to lower your defenses.

Step Two: Avoiding an In-Person Showing

Eventually you’ll ask when they’d like to view the property.
That’s when the story changes.
The “buyer” explains that their spouse, business partner, or friend is out of town and needs to participate in the discussion.
They insist on scheduling a three-way Zoom meeting before moving forward with an offer.
While Zoom is the most common platform used in these scams, some criminals may request Google Meet or Microsoft Teams instead.

Step Three: They Insist You Use a Computer

This is where the scam becomes more obvious—if you know what to look for.
If you suggest joining from your phone, the scammer may claim:
  • Zoom doesn’t work on mobile devices.
  • Three-way meetings require a desktop or laptop.
  • Their meeting can only be joined from a computer.
None of these statements are true.
If you recommend a phone call, conference call, FaceTime, meeting at your office, or showing the property in person, they’ll continue insisting that a Zoom meeting on a computer is the only acceptable option.
At the same time, they’ll continue reminding you they’re ready to write an offer—creating a false sense of urgency.

Step Four: The Fake Zoom Invitation

Once you agree to the meeting, you’ll receive an email containing what appears to be a Zoom invitation.
At first glance, everything looks legitimate.
However, the link does not lead to Zoom’s official website.
Instead, it redirects you to a malicious website designed to look nearly identical to the real thing.

Step Five: The Fake Zoom Update

After clicking the link, you may see what appears to be a normal Zoom loading screen or video conference interface.
Moments later, a message appears claiming that Zoom must be updated before you can join the meeting.
Your operating system asks whether you’d like to allow the installation.
If you click Yes, you aren’t installing Zoom.
You’re installing malware.

What Happens After Malware Is Installed?

The malware installed during these attacks varies, but it may include:
  • Password stealers
  • Keyloggers
  • Remote access software
  • Browser credential theft
  • Screenshot capture software
  • Information-stealing malware
Once attackers gain access to your computer, they often attempt to harvest usernames, passwords, browser cookies, saved credentials, and email accounts.
For a real estate professional, that can become much more than a computer problem.
It can become a transaction problem.

Why This Is Especially Dangerous for REALTORS® and Brokerages

Real estate transactions involve large sums of money, confidential documents, and ongoing communication between agents, buyers, sellers, lenders, attorneys, and title companies.
If criminals gain access to your email account, they may:
  • Monitor active transactions.
  • Identify pending closings.
  • Learn buyer and seller names.
  • Read conversations with title companies.
  • Impersonate you or your clients.
  • Request fraudulent wire instructions.
This type of business email compromise (BEC) has resulted in millions of dollars in stolen real estate closing funds nationwide.
One compromised computer can put multiple transactions—and your reputation—at risk.

How to detect the scam early on

1. A reverse search of the phone number reveals that it is owned by someone other than the name they provided, or will show that number has never existed.
2. A Google image search of the photo they provided will reveal a different name associated with the photo. It’s usually someone who is deceased, but that is not always the case.
3. The constant insistence on using Zoom, Meet, or Teams rather than a phone call, meeting in the office, etc.
4. The false claim that the only way it will work is on a laptop or PC.
5. If they do send the so called Zoom link via email, usually, hovering over the link they want you to click will reveal the real website they are directing you to, even if the email looks legitimate.