⚠ The Military Buyer Zoom Scam Is Targeting Agents Right Now
A two-stage scam designed to get inside your MLS, email, and financial accounts. Multiple Realtor® associations have confirmed this pattern across at least 7 states since October 2025.
If a “buyer” won’t get on the phone and pushes straight to Zoom, sending you the link themselves, don’t click. It’s an active phishing variant being reported by Realtor® associations in Wisconsin, Pennsylvania, Colorado, Idaho, Minnesota, New Mexico, and Alabama. The click can install malware, capture MLS/DocuSign/email credentials, or even record video for later use in deepfake fraud impersonating you.
This is not random spam. This is a targeted attack on listing agents, and it works because it looks organized, urgent, and qualified. Multiple state Realtor® associations have issued alerts on this specific pattern in the past 8 months, with variations in the fake-buyer profile (military, traveling executive, doctor on shift, etc.). The military buyer with VA certificate is one of the most convincing variants because it combines urgency, a believable reason not to call, and documents that look legitimate at first glance.
How the Scam Works
This is a two-stage attack designed to get you to trust the lead before you have time to verify the person behind it:
Build Credibility
The scammer sends a highly convincing email posing as a military buyer. The message includes a VA certificate, pre-approval, proof of funds, and urgency to move fast. The documents look professional. The story is coherent. Every detail is designed to lower your guard and create a sense of real opportunity.
The Zoom Link
The second message pushes for a Zoom call and the supposed buyer insists on sending the link themselves. That link is the real objective. It may route to silent malware, a fake Zoom page designed to capture credentials, or a fake “Zoom update” prompt that installs malicious software.
What the Zoom Link Can Do
This isn’t theoretical. Verified cases reported by state Realtor® associations:
- Install silent malware: A fake “Zoom update” can give the scammer full remote access to your computer — client files, email, saved passwords, everything.
- Steal credentials: A fake Zoom login page can capture your email and password, which are often the same credentials you use for MLS, DocuSign, or your bank.
- Take over accounts: One bad click can simultaneously compromise MLS, DocuSign, professional email, and financial accounts.
- Record video for deepfakes: In cases reported during 2025, scammers attempted to capture video recordings of the agent during the fake “meeting” for later use in deepfake fraud schemes — impersonating the agent to deceive future clients or facilitate wire fraud.
- Access in-flight transactions: With email access, the scammer can insert themselves into active deals to redirect wire transfers (wire fraud).
The 5 Specific Red Flags
Reports from Realtor® associations identify a consistent pattern. If you see 2 or more of these together, assume scam until proven otherwise:
Typical excuse: “I’m on duty,” “I’m traveling,” “working a long shift.” A real buyer, even busy, returns a 5-minute call to the agent selling their next home.
VA certificate, pre-approval, proof of funds, certifications — all included in the first email. Real buyers need time to gather these and typically deliver them progressively over days, not all at once before any conversation.
HOA fees, zoning, roof age, school zones, neighbors, history — real buyers ask. Scammers don’t, because they don’t care about the property; they care about the click.
This is the most important signal. A legitimate buyer will accept whatever format you offer (phone, your own Zoom, FaceTime, Google Meet) and let you send the link. The scammer needs it to be THEIR link.
Email from a free domain (Gmail, Outlook) when claiming to be a military officer. Sender name doesn’t match signature name. Double comma after the greeting. Perfect grammar but odd sentence structure. Email IP address doesn’t correspond to claimed location.
The Rule That Protects You
"If a buyer cannot pick up the phone for a 5-minute call, they are not ready to earn your trust. Verify first. Click later — if at all."
What To Do (Recommended Protocol)
- Never click Zoom (or any video conference) links you didn’t request. If a video meeting is needed, YOU send the link from YOUR verified account.
- Verify identity by phone before taking real action. Use the contact’s independently verified number — not the number the buyer provided in the email.
- Don’t trust “buyer” documents at face value. For VA certificates, call the lender listed as issuer to confirm authenticity. For pre-approvals, call the bank directly.
- Treat all unsolicited buyer/seller email with suspicion. Especially if it arrives with urgency, complete documents, and resistance to verification.
- Keep security software current. Professional antivirus, updated browser, two-factor authentication on ALL critical services (MLS, email, DocuSign, bank).
- When in doubt, talk to your broker or compliance office before responding to the suspicious buyer.
⚠ If You Already Clicked — Emergency Plan
If you already clicked a suspicious link, assume compromise and act fast. The first hours are critical:
- Disconnect the device from the internet immediately (Wi-Fi off, ethernet cable unplugged)
- From ANOTHER device (your phone using cellular data, NOT the office Wi-Fi), change passwords for: primary email, MLS, DocuSign, bank/financial accounts, anything sharing the same password
- Enable two-factor authentication on all critical accounts if you didn’t have it already
- Contact an IT/cybersecurity professional to scan and clean the device — don’t use the device for anything critical until confirmed clean
- Notify your broker and all currently active clients — if the attacker took control of your email, they could be sending fraudulent wire transfer instructions to your clients
- Report to the FBI Internet Crime Complaint Center (IC3.gov) and to your local Realtor® association
- Consider changing bank passwords by phone directly with the bank, not via web app until the device is confirmed clean
If you’re a buyer or seller working with an agent, this post explains why good agents verify identities carefully before taking digital actions. It also tells you something important to watch in your own communications: never approve a wire transfer based on instructions received only by email — always verify with your agent or closing agent BY PHONE to a known number. Wire fraud in real estate transactions is one of the most costly cybercrimes in the US, with the FBI reporting hundreds of millions in real estate-related wire fraud losses annually.
Frequently Asked Questions
Is it really specifically targeting agents, or is it general spam?+
What if the "military buyer" looks completely real with all the documents?+
How big is the deepfake risk if they captured my image?+
Is there legal protection or insurance against this?+
What other scam types are agents seeing right now?+
Final Take
The core rule is simple: if a buyer cannot pick up the phone for a 5-minute call, they are not ready to earn your trust. Verify first. Click later — if at all.
This scam works because it looks important and urgent — VA certificate, pre-approval, proof of funds, military member on duty. The details look legitimate, but the underlying tactic (refusing phone verification + insisting on Zoom + sending the link themselves) is the same across every variant. Once you recognize the pattern, you can spot it immediately.
Share this with your team and other agents. A strong culture of verification protects everyone.
See Also
Brian Wilder
The Wilder Real Estate Group at Keller Williams Wellington
In business since 1996 · 1,500+ homes sold across Palm Beach County
561-201-4717
Bilingual Spanish/English: Lucy Lopez · 561-285-8809
This post describes a phishing scam pattern targeting real estate agents verified by multiple state Realtor® associations between October 2025 and February 2026. Sources include official alerts from: Wisconsin Realtors® Association, Pennsylvania Association of Realtors®, Colorado Association of Realtors®, Boise Regional Realtors® (Idaho), Minnesota Realtors®, Greater Albuquerque Association of Realtors® (New Mexico), Huntsville Area Association of Realtors® (Alabama), and reporting by Frank on Fraud on the deepfake component. The protocol recommendations (phone verification, incident response plan, two-factor authentication) represent general cybersecurity best practices and do not constitute legal, technical, or insurance professional advice. Specific incident cases should involve qualified cybersecurity professionals, your brokerage, your cyber liability insurer if you have one, and relevant agencies (IC3.gov of the FBI, your local Realtor® association). This post does not represent endorsement or criticism of any video conference platform, government agency, or professional association mentioned. Information deemed reliable but not guaranteed. Equal Housing Opportunity.