Doorify Real Estate Podcast
Welcome to the Doorify Real Estate podcast, brought to you by Doorify MLS. Join us every Wednesday to hear interviews with industry insiders, agents and brokers that are crushing their businesses, and updates from the Doorify MLS team.
Doorify Real Estate Podcast
Don't Take the Bait Cybersecurity Presentation with Matt Cohen
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Cybersecurity threats aren't just targeting systems anymore, they're targeting people. A few seconds of hesitation can be the difference between preventing an attack and dealing with weeks of recovery.
In this presentation, Matt Cohen, Principal of Advisory Services at Cotality and a cybersecurity expert with more than 30 years of experience protecting the real estate industry, explains why phishing, text scams, voice cloning, and social engineering have become some of the biggest risks facing MLSs, associations, and brokerages. He walks through the tactics attackers are using today, how staff members are being targeted, and why strong verification policies matter more than ever.
The presentation also covers practical steps organizations can take to reduce risk without sacrificing customer service. Anyone responsible for handling member accounts or sensitive information will find these recommendations immediately applicable.
Listen to the full presentation to learn practical habits and verification strategies that can help prevent costly cyber attacks.
Specifically, this episode highlights the following themes:
- Why attackers focus on people instead of technology
- Practical ways to recognize and stop phishing, smishing, vishing, and social engineering
- Building verification policies that protect member accounts and organizational trust
Links from this episode:
Know more about Matt Cohen: https://www.linkedin.com/in/mcohenmn
Learn more about Doorify: https://doorifymls.com
1ae5b43598204883b524f061d4880e6d10fca88c (for podfollow.com)
Matt Cohen [00:00:07]:
So, okay. I'm Matt Cohen. I've been helping maintain our industry security for over 30 years, working with technology companies and brokerages and franchises, MLSs, and local, state, and national associations here in this country and elsewhere. Lately, there's been an uptick in MLS and association staff being fooled by hackers, creating agent and broker account takeovers. It's not just the MLS at risk though. And obviously fake listings and trust in the system is important. You know, we want to prevent fake listings, but single sign-on into various systems and consumer— put consumer personal and financial data at risk. And with breach notifications, that could damage our industry's reputation.
Matt Cohen [00:00:59]:
And that is more difficult to recover than systems. So I'm endeavoring to help by providing these presentations. This is just the start. It's important to have regular training and testing. I myself, I'm on the receiving end of phishing tests constantly from my company. If I fail to detect a phishing test, there are consequences. So again, this is just a starting point in education. It's important that your companies have both regular training and testing for you ongoing.
Matt Cohen [00:01:34]:
So the big thing is, and it's been, it's been this way for a long time, but especially with how good things like antivirus and other technical things have become, attackers are not just hacking systems. They hack people. It's easier to break into someone's email by hacking an individual than guessing their password. To do so, they use phishing, which is email. They use smishing, they use text messages. They use vishing, which is voice phishing, and in-person social engineering. And social engineering is the art of manipulating people into handing over information, money, or access. The attacker poses as someone you could trust, like a vendor, a coworker, your bank, and uses urgency, fear, or curiosity to make you go past your better judgment.
Matt Cohen [00:02:31]:
So in your email, might get a message that looks like it's from a brand that you like, a vendor that you work with, a member, or a coworker. And this is designed to harvest your credentials, money, or to run a command on your computer, or to have you click on a malicious link. Examples of what to watch for are lookalike senders, things that look like it, but you could see in Microsoft, the 0 instead of an O, that tends to get past people. There are various things like that. Urgent language, like Act now, your account is suspended. You know, it can be a good urgency, like, hey, sign up to get this cool new t-shirt or to get access to this. So it's something you want to act on right now. It's an unexpected attachment or a link to a login page and a request to bypass policy, as in like, okay, this is— your CEO said this is okay, go ahead and do it.
Matt Cohen [00:03:31]:
Something that you normally would have a policy that says you don't do this. Again, you have the phishing texts that happened on the phone, called smishing. They're short, they're urgent, they're fake alerts, warnings, MFA codes that pushed you to tap a link or to reply. For example, it could be a delivery smishing rescheduling your package. It could be a fake MFA prompt asking you to confirm a code. It could be a boss asking you to send a quick gift card, or do me a quick favor, look this up and tell me this. It could be a shortened link. Whenever you see a shortened link from an unknown number, it's a big avoid.
Matt Cohen [00:04:12]:
Finally, there's vishing. AI voice cloning is very— makes very familiar voices very easy to fake. A caller poses as your IT, the bank, the IRS, a vendor, a member, and anyone that's ever put a video online Or a recording of voice, it's so easy to fake. So pressure to act now, requests for passwords or MFA codes or remote access to your computer, requests of arrests, fines, or account closure, and callbacks asking you to call back at a specific number that they give you or that they provide in an email. Those are all things to watch out for. And lastly, it can be in-person social engineering. Someone comes right through the door, someone doing maintenance on your building, delivering something, or with a clipboard, talks their way through the pass— past the badges and the front desks. And to watch out for is tailgating, someone slipping in behind you at a badged door, fake uniforms or vendor badges, like, I'm here to fix the printer, inspect the fire panel, et cetera.
Matt Cohen [00:05:22]:
Shoulder surfing, somebody coming up behind you, looking at what you're doing, and things like lost laptops, USBs, and pages on unattended workstations left unlocked. These people are very good at getting access to those kinds of things. So here are some examples of how they get in. Here are 4 examples. They use pretexting, such as inventing an unbelievable story. I'm from IT, your laptop is flagged. To extract information from you. They bait something.
Matt Cohen [00:05:55]:
They give you a free download, a USB drive in the parking lot. They have prize, something that gets you to click. Tailgating, following you through a badge door entrance with their hands full, smiling, no badge. Quid pro quo, offering to help you in exchange for access, such as a fake support fixing a problem that they created. So all manner of things that people do. So to all these things— phishing, smishing, phishing, social engineering— there are 6 things that you need to do. And you need to do this any time, day or night, they are accessing sensitive information. You know, I myself work at all hours.
Matt Cohen [00:06:41]:
In the early morning, that's the worst time to get a phishing test because I have to Sleepily pay attention to what's happening. So urgency. If you see 2 of these items on the screen, 2 of these 6 items, slow down immediately and stop and think about what's happening and test. And I'm going to go through the testing, but if there's urgency or authority or secrecy, something designed to get you emotional, either fear or panic or excitement or sympathy, slow down. If it's an unusual channel, like an unknown number or an unusual request, like wire transfer or MFA code or password reset, slow down. It's way better to slow down and think for a second and think, hey, this was an urgent request from my boss to do something unusual.
Wendy [00:07:40]:
Yeah.
Matt Cohen [00:07:41]:
Is it really my boss? Time to call a number I know and make sure before I do something. So you might get a fake SMS text message from US Postal Service. Your package couldn't be delivered. There's a link. You want to see what package is it that couldn't be delivered. You click the link. There's a Microsoft login, right, to access something on OneDrive. You read the email, you watch for an active vendor invoice.
Matt Cohen [00:08:12]:
The attacker reads finance from the inbox, new bank information, please update. And finance pays next invoice to the attacker's account. No alarms because you clicked in and gave them your login. You might see these things on these quizzes on Facebook, right? These are all familiar things you see. And I see people answering these every day. And these are all mechanisms for getting information about people and password information, information that might lead to a password. They find your public profile, employer, manager, coworker, vacation photos. They do a personality quiz to harvest your first pet, your street, your school, which are classic security answers.
Matt Cohen [00:08:59]:
A coworker sends you a message on LinkedIn, no, friendly, knows all about your project, asks for a quick favor. Quiz answers that are used to reset your password. And again, it's so easy for your account to become hijacked. So be careful what information you disclose online and how, again, they're going to use that information all the time. This is a new one. If ever you see a CAPTCHA, like verify you're a human, you know, in some way, and it gives you instructions like, if you're on Windows, press Windows+R and Ctrl+V and press Enter, that there is a way for the people to take over your computer. So be very watchful for that. That's going around.
Matt Cohen [00:09:51]:
A lot right now. And there are versions for Mac and the PC. So do's and don'ts. Do pause before clicking on any unexpected link. When you get an email, look over the URLs, look over who it's from, verify by a second channel. If it's something you didn't expect to get, call the person directly. If it's a member, Call the number, make sure they didn't change the number in your system recently. Hover over links to see the real URL.
Matt Cohen [00:10:26]:
Report suspicious messages to your IT department, even if you're unsure. Your IT department would much rather get a message from you than find out later that they have a mess to clean up. Using multi-factor authentication. And a password manager. Now, password managers are targets for hackers and they're always getting hacked, but it's way better to use one than to use a bad password. Don't share your passwords or MFA codes with anyone ever. Don't trust your caller ID. It can be spoofed.
Matt Cohen [00:11:03]:
Don't use links inside urgent emails. Go to the site directly. Don't reply to suspicious messages with personal information, and don't plug in unknown USB drives or scan random QR codes, because those are all things that people are using to hack these days. Again, stop, verify, report, contain. Reporting early is never a mistake. Even if you're wrong. There's lots of phishing online. I'm not going to play this, but there are lots of YouTube videos, there are phishing training, but ideally it's best to have your IT people sending regular phishing tests to make sure that you're taking the steps to catch bad phishing.
Matt Cohen [00:11:54]:
So a common MLS or association scenario. They'll call a help desk pretending to be a realtor or broker. Locked out of the MLS. They create a sense of urgency or crisis. A pending closing about to fall through. I'm late for a listing appointment. You know, this is going to cost me business. You know, I need it right away.
Matt Cohen [00:12:15]:
And I need you to reset a password or change account contact information or add a passkey or MFA or remove strong authentication. They can get in with just their password. Those are all things that people are doing all over the country to get into MLSs and take over accounts. They're targeting staff members with phishing emails containing malicious links or attachments. It can be something like association policy updates or invoice discrepancies or something, anything to make you think, wow, I really want to help that member. I really want to help. And that impulse is to help. And, but you have to be careful.
Matt Cohen [00:13:00]:
And once you click the link, attacker gets access to your staff's administrative account, allowing them to extract the database and remember passwords, hijack accounts, or alter MLS access permissions. Another thing that they're doing, and they're doing this today all over the country, is they're calling or emailing association staff Pretending to be one of your software vendors or a third-party marketing assistant, and staff might unwittingly grant them access, handing over member credentials or making other account changes required for them to control the account, especially when you change email address or phone number. Everything is lost from there. Attackers are monitoring staff activity. On platforms like LinkedIn, harvesting information about how things work internally at your organization, specific software vendors. They're getting the names of department heads. They're using this information to craft very convincing phishing messages, getting them to change account information in the association management system or the MLS. That's what's happening now.
Matt Cohen [00:14:14]:
Now, to protect member accounts, you've got to use a strict layered verification framework before resetting passwords, bypassing security controls, or changing contact information for anyone. The recommendation is to implement these layered verification frameworks as a policy. One example of that is to do an out-of-band callback. That means the staff hangs up politely on the caller and dials the number listed in the agent's official state licensing portal. If the hacker says the number is out of date or wants to use a new email address, make sure the information has not recently been changed. You should be able to see what's been changed and when, who changed it. You want to make sure that information is reliable. Another option is to call a known good contact who would know to confirm the changes, such as their broker, another contact.
Matt Cohen [00:15:20]:
Again, if you can't reliably have a place to do an out-of-band callback, you got to do another step. Another step might be secondary admin approval. If you're going to do a password reset or an MFA removal, or even a contact information change, you may require a second authorized staff member to review and approve the request. Make sure process is followed. Yeah, I know it's slow and right when you want to help the person because they have, they have a closing they have to get to, but it's important. You do something like a live video verification or do a brief call on your platform, your meeting platform, to match the agents based on the driver's license or real estate ID, just like pictured. Lastly, less good is have a pre-established PIN, a non-public security PIN established during their initial onboarding. If you have that kind of thing, That's another layer that you can add to the mix.
Matt Cohen [00:16:29]:
You should have zero trust help desk rules forbidding staff from accepting public information. That's license numbers, office addresses, other things like that as proof of identity. Again, these people all have access to the same public records that you have. So you can consider using dynamic knowledge-based authentication. That's like when you call a bank and they ask you, what's the first street you lived on? What's, uh, what did you, what car do you have in 1984, et cetera? And they do that to out what's called out-of-pocket, out-of-wallet questions to try to figure out if it's you or not. If you have access to that kind of system, that's another useful thing. Another possibility is to enforce a mandatory 24-hour hold. on high-risk changes to accounts.
Matt Cohen [00:17:24]:
Lastly, I mentioned this is done for me. There are social engineering, simulated social engineering, where management runs unannounced, realistic phishing and voice phishing tests on staff, and repeated failures must have consequences. If I fail a phishing test myself, I got to go— we go through phishing training. If I fail a few phishing tests, I'm out of there. They're firing me again. They have to keep people safe on the other end. So one more real-world example, and this is a real thing that's happening nowadays. Hacker calls the association pretending to be a member, requests that the email address be updated in the AMS.
Matt Cohen [00:18:12]:
Once the email is changed, the hacker requests a password reset. Reset link is sent to the new email address, giving the hacker access to the member's account. If the AMS is synchronized with NAR's M1 system, the compromised information can also affect the M1 record and be sent down to other MLSs. Or if an MLS uses M1 as its source of truth, the hacker could contact the MLS requests an email change. And if they— if the MLS employee updates M1 and sends a password reset link, the password— the hacker then gains access to the MLS account. So again, the important thing is to have identity verification procedures, and there are many kinds: out-of-band callback, video verification, pre-established PIN, cooling-off period, having zero trust help desk rule. And secondary admin approval before making account changes or processing password reset requests. So these things have consequences.
Matt Cohen [00:19:17]:
There's business disruption. That's what people usually think of when there's hacking and ransomware and all those things. They think, well, they're going to get in the way of me doing business. They get in the way of my clients doing business. There's the integrity, confidentiality, and availability of member data. Which is also important to have, because when people change it, it's a real pain to have to figure out what changed and to go back. There's the cost of recovery and breach, especially when there's single sign-on to systems with consumer data, personal data, financial data. And so again, if you have a breach and have to tell the public about it, It— there's reputational damage.
Matt Cohen [00:20:01]:
There's also the cost of notifications. It's a hassle. Again, SSO access into the showing systems, lockbox, transaction document systems that contain personal information and financial information. And you have to do breaches notification. It's very bad. They also are using compromised accounts to socially engineer other accounts. So once they're in the MLS as one user, they can then work on compromising other users. Lastly, they're putting fraudulent listings into the trusted MLS environment and there are potential reputational and financial results of doing that.
Matt Cohen [00:20:42]:
I know that you have a new tool, Property Shield, for looking for fraudulent listings, but the assumption is that what's in the MLS Is truth, real listings. So everything tests against that. And again, compromise, I keep getting hackers in the systems, terrible things. So there are 3 things I want you to remember when you leave this meeting, or at least my part of it. One is attackers are targeting people. They're not hitting firewalls anymore. Email, text, Phone. Every channel is in play.
Matt Cohen [00:21:21]:
Treat every unexpected ask as a test. Verify. Pause and verify before you act. 10 seconds of skepticism beats 10 days of incident response. Just pause. Report fast, even when you're unsure. Report it to IT and management. They'd rather see 10 false alarms and miss one real attack.
Matt Cohen [00:21:48]:
So there's a lot going on nowadays, and I hope that you take the time and take the care because our industry's reputation is depending on you.
Wendy [00:22:03]:
Thank you, Matt. That's really true because our Doorify MLS support team gets quite a few calls, very similar to those. Situations asking for, please update my email address.
Matt Cohen [00:22:15]:
You know, it's so hard because you always want to help them.
Wendy [00:22:19]:
Yep. And it's really important to have a system in place internally on how to handle those situations. So I appreciate your presentation and your time today. I wanted to open up the floor. Did anybody have any questions for Matt?
Matt Cohen [00:22:34]:
I have one quick question, Matt. You were talking about, you know, we're all recording videos out there, so our voices and And things are, you know, are public knowledge now. Have we had any infiltrations with voice recognition? Absolutely. There have been, there have been phishing, vishing, submission, text message, the voice, even video. It's spooky. And nowadays, when the customer wants you to go over to their platform for, you know, doing online meetings, always use your platform. Because they can have a fake video queued up on their platform and fool you guys any day of the week when showing, you know, a video with a fake, fake ID and them. It's like, gotta be super careful.
Matt Cohen [00:23:24]:
But it's just, just from a theoretical standpoint, it would be entirely possible for me to get a message from my BIC instructing me to do something that sounds exactly like my BIC calling me. Absolutely. And using a number that They spoof the caller ID that it looks like, looks like someone you trust. If it's really unusual, call them back at a known number and have all those other steps, whatever process your organization wants to put in place. I'm not telling you you have to, but you can figure out which of those steps make sense for you in different circumstances and just take care.
Wendy [00:24:01]:
Yeah.
Matt Cohen [00:24:02]:
Because, you know, again, it takes so little time to check. They try their best to get urgent, to say, oh, I'm going to— I'm going to closing right now. I need this information. You know, my client's waiting for that number to send the money to. You know, again, everything they do looks like it's on the up and up, but the more you do, The more you have policy that you have to check and verify things, especially high-risk things, the better it is. It's just the reality of working today. You just can't trust anything online the way you used to.
Wendy [00:24:46]:
They're very creative, unfortunately for us.
Matt Cohen [00:24:49]:
There are, there are new scams every day.
Wendy [00:24:54]:
Yep.
Kate [00:24:54]:
So I just want to say, first of all, I have not invited anybody to a special party because I've been getting those things from people constantly lately. But, um, the innocent things, the things that aren't questionable at all, are the ones that really seem to trip us up the most. So it's not that unusual request. It's something that's just very innocent looking. And I keep worrying about. everything these days, you know, that I get in an email, in a phone call. But the biggest problem is, is that if you don't respond to certain things that are legitimate, you're going to get penalized. So, you know, it's kind of like, oh, should I respond? Should I call back? Should I wait? Should I check? Or should I do it? And, you know, I think that the best thing is for all of us to be very vigilant and report not only to whoever our tech people are or whatever, but, but also just to the community at large.
Kate [00:26:01]:
Because every day there is a new scam, there is a new something going on, and I need to be aware of it as, as an individual as well as for our company.
Matt Cohen [00:26:13]:
Yeah. When, when I report phishing, If like 5 other report people report the phishing and it's real phishing, then IT team immediately knows they need to get this email out of everyone's account, out of everyone's inbox, or someone might click on it.
Wendy [00:26:30]:
Right.
Matt Cohen [00:26:30]:
Important to have a policy. Everyone is always consistently required to do these things before making these kinds of changes or this, uh, providing this information over the phone. What can be provided over the phone? What can be done via email? If you don't have a policy, you have tendency. And tendency is 90% of the— we do the right thing and 10% we get fooled.
Wendy [00:26:56]:
A couple weeks ago, I got an email from Matt Fowler asking for my cell phone number. I'm like, why is Matt asking for my cell phone number? He knows it. But so then I looked, I was like, oh, that's not his email address. So it is something. Very. And so then I, internally, we have a process. I've reported that to our IT department and then a couple few other people did the same. That's one instance we've gotten recently.
Wendy [00:27:21]:
Another one is people calling up saying, can you change my email address? I can't get in. So internally, we, we contact the BIC right away of that office. So there are things that we are doing internally on the DoriFi side.
Kate [00:27:36]:
Yeah.
Wendy [00:27:37]:
Because again, if they get in, you know, it's a lot of work to try to get them out and fix what they, you know, what they got access to.
Matt Cohen [00:27:47]:
Oh yeah. It's terrible. And it doesn't matter how technically sophisticated you are. It's, they're playing with people's brains and the brains aren't evolving fast. Yeah. Yeah. With technology and things, they're, they're attacking the head. They attack the head.
Kate [00:28:05]:
And see, if what Wendy's talking about, some, you know, somebody you know who's asking for your phone number, if you are busy, if you are distracted even for a minute, it's like, what could it hurt? You don't even think about it. That's the stuff that is really keeping me awake at night.
Matt Cohen [00:28:25]:
They're looking for your phone number to send a text message, send a virus, to send malware to your phone. And from there they get everything. It's a bad time, but again, just take the step, take the time to verify at the right time. So you get around this stuff.
Wendy [00:28:44]:
Any other questions for, for Matt? Well, okay.
Matt Cohen [00:28:47]:
Well, have a great morning and have a great meeting and, uh, hopefully all have a good 4th.
Wendy [00:28:52]:
Thank you so much, Matt.
Matt Cohen [00:28:53]:
Thank you, man.