First American
Private wire fraud and impersonation briefing

How First American can detect & take impersonation in real time with Outtake

Outtake is an AI-native threat intelligence and Brand Protection platform. It finds the lookalike domains, spoofed escrow and closing emails, fake agent and branch identities, and fraudulent title and payoff instructions impersonating First American, investigates the infrastructure behind each one, and coordinates removal with the registrars, hosts, and mail providers keeping them running.

First American external surface Public context
$7.45B
FY2025 REVENUE
FY2025 Form 10-K / 2026-02-18
19,102
EMPLOYEES
FY2025 Form 10-K / 2026-02-18
#2
U.S. TITLE INSURER
ALTA market share data
531,900
2025 TITLE ORDERS CLOSED
FY2025 earnings / 2026-02-11
49 + DC
OPERATING REACH
FY2025 Form 10-K / 2026-02-18
8.6B
PROPERTY DOCUMENT IMAGES
First American / 2025-06-24
01 / First American signals

First American already teaches customers and agents to expect impersonation at the edge of a transaction.

The public record is consistent: fake email identities, altered wiring instructions, seller impersonation, notary fraud, and AI-generated personas all target trust before funds move.

First-party warning / Undated

A published homoglyph example targets the corporate email domain

First American documents a fraudster changing @firstam.com to @first-arn[.]com, substituting ‘rn’ for ‘m’.

First-party warning / Undated

Payment changes require direct verification

First American says it will not request passwords or personal financial information by email and directs recipients to verify changed payment or wire instructions with their representative.

First-party research / 2025-02-20

Deepfakes can impersonate transaction participants

First American research describes deepfake audio or video impersonating real estate professionals and home sellers.

First-party launch / 2025-09-08

Early identity verification is an essential safeguard

The Agency Division launched an identity verification capability against a growing real estate fraud threat.

First-party launch / 2026-01-21

Property title monitoring expanded to 25 states

First American launched free title monitoring and fraud alerts as an early warning system for property owners.

First-party guidance / 2026-04-14 and 2026-05-08

Impersonation attempts are increasingly polished

Agency guidance names seller impersonation, wire and email spoofing, payoff fraud, notary and ID fraud, and deepfake impersonation among recurring schemes.

02 / External trust surface

Customer trust moves through an external surface First American does not fully control.

A customer or agent trained to accept mail and logins across two root domains and a dozen subdomains has no reliable way to spot a thirteenth that is fake.

01

Closing and wire instruction channels

Escrow officer email, payoff letters, wiring instructions, and closing document delivery carry the transaction. First American’s own guidance warns that the instruction itself can be forged.

02

Agent, branch, and notary identity

Policy-issuing agents, local branch and escrow officer identities, notaries, and vendors all become identities a fraudster can imitate.

03

Homeowner and seller-facing surfaces

Title monitoring enrollment, home buying guidance, property-owner identity, and seller verification extend trust into consumer-facing journeys.

04

The First American domain family

Two root domains and a dozen subdomains train customers and agents to accept many legitimate destinations, while homoglyphs imitate the pattern.

firstam.com
myfirstam.com
agency.myfirstam.com
fams.myfirstam.com
agentnet.firstam.com
agency.firstam.com
ignitere.firstam.com
commercial.firstam.com
blog.firstam.com
local.firstam.com
careers.firstam.com
investors.firstam.com
endpoint.com
04 / Operating method

Outtake expands one suspicious finding to the infrastructure behind the operation.

Cross-surface detection, autonomous investigation, campaign correlation, and provider coordination stay in one workflow, so separate teams can work from the same evidence and response path.

01
Detect
Find the impersonation surface
Continuously find homoglyph and lookalike registrations against the firstam.com and myfirstam.com families, spoofed escrow and closing correspondence, cloned agent portal logins, fake branch and escrow officer identities, and fraudulent title monitoring signups.
02
Investigate
Turn a signal into an evidence file
Automatically collect the registration, hosting, mail configuration, and delivery paths behind each signal, so a reported lookalike becomes an evidence file rather than a ticket.
03
Correlate
See one operation across separate queues
Connect shared hosting, shared templates, and repeated delivery paths so a fake closing instruction and a cloned agent login that share infrastructure are handled as one operation rather than two tickets in two queues.
04
Dismantle
Act against the dependencies
Coordinate with registrars, hosting providers, and mail providers against the dependencies the operation needs, making it costly enough to run that the operators move on.
Lookalike signal
Domain, email, profile, or portal
Registration + DNS
Infrastructure
Mail configuration
Delivery path
Shared template
Artifact reuse
Related lure
Cross-surface correlation
Provider path
Registrar, host, or mail
Brand Protection / How it works

How Outtake works

Outtake combines entity definition, agentic search, threat-graph intelligence, and provider-level response coordination in one platform. The result is a continuous external-risk workflow that gets more context from every investigation.

Outtake Brand Protection platform investigation view
Entity definition
01

Define the identities that matter

Outtake models the First American names, domains, visual identities, portals, branches, agents, and transaction surfaces that legitimate customers and partners are expected to trust.

Agentic search
02

Search beyond exact matches

Autonomous agents look across domains, ads, social platforms, apps, messaging, and other external surfaces for copied identity, altered language, visual similarity, and suspicious transaction cues.

Threat-graph intelligence
03

Map the operation behind each fake

Registration, hosting, certificates, mail configuration, templates, and delivery paths are connected into a graph that helps teams see related activity instead of isolated alerts.

Response and learning
04

Automate takedowns and threat briefing

Provider-level response paths support coordinated action at the source dependencies. Each investigation adds evidence that can improve how related activity is detected, prioritized, and handled over time.

Organizations protected by Outtake
Point72
Pershing Square
Cyera
NVIDIA
OpenAI
Notion
Private working session

See how external fraud signals become one investigation and response path.

In 30 minutes, see how Outtake finds a lookalike of a First American closing domain, investigates the infrastructure behind it, connects it to related activity across agent, closing, and consumer channels, and coordinates action with the providers keeping it online.

Private briefing prepared by Outtake for First American.