I just had an experience that I want every commercial real estate professional to know about, and to understand the potential dangers from it.

Because until this just happened to me, I had never even considered that someone might approach me, pretending to be an interested prospect, with the real intention being to perpetrate a scam that would install malware on my computer.

So here’s what happened…

I received an email from a woman named “Angela.”

Her message was simple:

She said that she was familiar with my work, was interested in my real estate coaching services, and she wanted to discuss her needs, and learn more about how we might work together.

So there’s nothing unusual about that.

I receive inquiries from people who are interested in coaching all the time, and this just sounded like it could be another one.

But I wanted to first know a little more about her.

With this in mind, I asked Angela if she could send me links to some of her listings, or perhaps to a bio page, where I could learn more about both her, and what she was focused on within her commercial real estate career.

She told me that she didn’t have anything like that online, but that she was really interested in investing in and developing real estate.

We continued communicating, and we scheduled a Zoom meeting together for the following week.

Then things started getting interesting…

Angela sent me a link to join the online meeting with her.

At first glance, it looked like it was a link to join a Zoom meeting.

But when I went to the webpage, I was told that I needed to download an application, in order to join the meeting.

That immediately struck me as being strange.

I’ve participated in more Zoom meetings than I could possibly count, so why should I suddenly need to download an application from the website in order to participate in this meeting, when I’ve always just joined Zoom meetings directly through my own web browser?

Then my Norton security software gave me an even bigger reason to be concerned.

Norton warned me that the website contained a malicious threat.

That was enough for me, so I didn’t download anything.

Instead, I told Angela that we could simply meet in my own Zoom meeting room, and I sent her my private Zoom meeting link to do so.

She begrudgingly agreed to this, but not before encouraging me to try accessing her link one more time.

So that really concerned me.

With this in mind, think about this…

If you’re a prospective client who genuinely wants to speak with me, why would you even care whose Zoom meeting room we utilize?

You supposedly just want to have our online meeting together.

My Zoom meeting room will accomplish this, just as easily as another person’s Zoom meeting room would.

Unless, of course, having the conversation together, really wasn’t their objective.

So I began investigating deeper…

I decided to look more closely at the link that Angela had sent to me.

The link wasn’t actually hosted by Zoom, but it had the name Zoom in its URL.

So it was hosted on a different domain, that was utilizing Zoom-related wording, to make the link appear legitimate.

And when landing on the webpage from the link, the Zoom logo was there, making it REALLY look legitimate.

Then, upon investigating further, I discovered that this domain had already been identified by independent cybersecurity services, as being malicious.

So suddenly this began began making more sense to me.

I then realized that the original email that I received, may not have been about genuinely being interested in hiring me at all, and the scheduled meeting for the following week, may not have been about discussing Angela’s commercial real estate goals.

The entire purpose of the interaction appears to have really been, to convince me to download malicious software onto my computer!

Think about how clever this is…

Most of us have learned to be suspicious of the obvious phishing emails that we’ve received over the years.

Your bank supposedly needs you to verify your password.

A package supposedly can’t be delivered.

You’re told that a huge charge has been made on one of your credit cards, and they want you to contact them immediately, to verify that the charge is legitimate.

We now know enough about these situations, to be suspicious.

But what happens when you receive an email from someone who says:

“I’m interested in hiring you for your services. Can we schedule a Zoom meeting to talk about this in greater detail?”

That’s different!

For you as a commercial real estate broker, that could be a prospective tenant.

A property owner.

An investor.

A developer.

Someone who is looking to buy a building, or to list one for sale or lease.

That’s exactly the kind of email that you want to receive!

So then you respond to the email.

You schedule an online appointment with the person.

And the person then sends you a link to join the online meeting.

At that point, you might not be thinking that some stranger has just sent you a dangerous link.

You may be thinking:

“Here’s the Zoom link for the meeting that I just scheduled with this new prospect.”

That’s what makes this scam so potentially effective!

So I didn’t download the application that I was asked to, and fortunately nothing happened to me, or to my computer.

But installing an app with malicious software can potentially give cyber criminals access to information that’s stored on your computer, capture passwords and other credentials, get access to login to your bank and financial institutions, monitor activity, or even give the attacker remote access to your entire computer.

That’s one BIG reason why I never store the login and password information for my financial institutions on my computer, or on my phone!

I always enter them manually, every single time, instead.

Because if someone gets access to your devices with that information already being stored in there, things could get really bad for you, in a hurry.

With this in mind, think about what’s on the average commercial real estate professional’s computer…

Email from clients.

Contact databases.

Client information.

Contracts.

Financial information.

Access to banking information.

Saved passwords and login information.

And potentially, confidential information involving clients and their transactions, including information within an email, for the exact timing and instructions for when your clients are supposed to wire funds within transactions.

Suddenly, getting a commercial real estate professional to install one little “Zoom application”, could become very valuable to a cyber criminal.

Then something rather comical happened…

I received another email from “Angela”, that was the exact same introductory email that she had originally sent me!

Apparently, after already communicating with me and scheduling an online meeting time with me, I was solicited all over again, as though we had never even communicated.

That certainly didn’t increase my confidence that I was dealing with a real, legitimate, prospective client.

So this experience has now taught me something…

When an unfamiliar prospect wants to have an online video meeting with me, I’m going to provide the meeting link to them.

Then they can meet with me in my own private Zoom meeting room.

And if someone insists that I use their own meeting link, or tells me that I need to download some special app before we can talk, that conversation will end immediately.

So I recommend that you consider doing this, too.

In addition, whenever you’re contacted by an unfamiliar prospect, do some homework.

Who are they?

What company do they represent?

Can you locate both them and their company online?

What properties do they own or lease?

A legitimate prospect shouldn’t be offended, because you want to know who you’re really dealing with.

And Here’s One Final Thought From Me On This…

I’m glad that this happened to me.

Why?

Because I didn’t lose anything.

I didn’t download anything.

My computer wasn’t compromised.

But I learned about a new type of scam, that I hadn’t previously even considered:

Someone may pretend to be a legitimate CRE prospect for you, simply to get you to click on a link, and install malicious software on your computer!

That is a new one for me.

And now that I’ve experienced it, I’ll recognize it much quicker the next time.

And maybe even more importantly, if you hadn’t heard about this scam before, you now know about it, too.

So the next time an unfamiliar prospect wants to schedule an online meeting with you, remember:

The person on the other end may genuinely want to do business with you.

But make sure the opportunity that they’re offering you, isn’t really just an opportunity for them to get inside of your computer!

With this in mind, in putting all of this together, right here is an article published by the California Association of Realtors, putting agents on notice about this scam, and warning them to take the proper precautions, to make sure that you never get victimized by this scam yourself.

________________

If you’re interested in one-on-one coaching, having me do a one-hour strategy session with you, or in having me lead a webinar or a training for your organization, send me an Email or give me a call!

“Within just months after I began my coaching work with Jim, I’d made back 21 times what I had paid him, and more commissions are still coming, and are on the way to me in my pipeline!”

George Abro
Altitude Commercial Real Estate