Christine Alifrangis

Deed Fraud Is Becoming a Technology Problem

· Christine Ali

Stealing a house sounds like it should be difficult. It’s a house. You can’t exactly put it in your pocket and walk away. What you can steal is the system’s belief about who owns it. That is a much more interesting security problem. Real estate ownership ultimately depends on records, documents, identities, signatures, and the processes used to establish that those things are legitimate. Attack those processes and you don’t need to physically steal anything.

You need to convince enough systems that a fraudulent transaction is real. This is why deed fraud isn’t merely a paperwork problem. It’s an identity-security problem. And increasingly, that makes it a technology problem. Think about the ingredients available to somebody attempting impersonation today. Personal information has been exposed through countless data breaches. Images of people are publicly available. Signatures can be copied. Documents can be manipulated convincingly.

close up shot of a person with handcuffs

Generative AI can create realistic images, text, audio and increasingly convincing video. Meanwhile, a real estate transaction naturally involves multiple organizations, systems and people. That gives an attacker boundaries to exploit. The dangerous assumption is that because each individual participant has a control, the transaction as a whole must be secure. That isn’t necessarily true. Security failures love boundaries. One organization assumes another verified something.

A system accepts data because it arrived through a trusted workflow. A person recognizes a familiar-looking document. A credential passes a superficial inspection. Nothing looks sufficiently wrong to stop the process. This is precisely why notarization matters. A notary doesn’t magically make fraud impossible. Nothing does. But a properly performed notarization creates another independent hurdle for an attacker. Identity has to survive another examination. The signer has to satisfy the requirements of the notarization.

A journal record may be created. For certain California real-property documents, the journal requirements include a thumbprint. That is defense in depth. The important phrase is in depth. I don’t want any single control protecting something as valuable as ownership of real property. Not a password. Not an ID card. Not facial recognition. Not a notary. Not an AI fraud detector. Not a database. Multiple independent controls are much harder to defeat than one supposedly perfect control.

Technology can improve this considerably. Systems can identify unusual transaction patterns. Credentials can receive additional validation. Events can be logged. Audit trails can become harder to alter. Notifications can alert property owners when records change. Information can move between organizations without relying entirely on humans copying it from one place to another. But technology can also make the attack better. That’s the uncomfortable part. Every tool that makes legitimate document processing easier can potentially make fraudulent document creation easier.

Every improvement in remote communication can potentially improve remote impersonation. Every AI system capable of understanding an identity document is operating in the same technological universe as AI systems capable of helping someone manufacture convincing false information. There is no point pretending otherwise. The answer isn’t to stop using technology. It’s to stop designing security as though attackers aren’t using it too. Real estate is particularly interesting because the assets involved are valuable enough to justify sophisticated fraud while many of the underlying processes evolved long before the current threat environment.

That gap deserves attention. The humble notary journal isn’t particularly futuristic. Neither is checking identification carefully. Neither is maintaining a clear chain of custody. Neither is making sure the human in front of you understands what they’re doing. Good. Security doesn’t receive extra points for being fashionable. It receives points for making attacks fail. The future of real-estate security will certainly involve better technology. But I suspect its strongest systems will combine that technology with something we’ve been using for a very long time:

Multiple independent humans and systems, each refusing to blindly trust the one before them. For California’s specific journal requirements, see the California Secretary of State’s Notary Public Handbook. Requirements differ by jurisdiction.


Discover more from Christine Alifrangis

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from Christine Alifrangis

Subscribe now to keep reading and get access to the full archive.

Continue reading