The Fraud is in the Closing: AI, Spoofed Emails and New Jersey Lawyers

This article was originally published in New Jersey Lawyer in August 2026.

When Fraud Moves Into the Closing Process

Transactional lawyers have long treated fraud as a problem of deal substance: misstatements in financial disclosures, omissions in disclosure schedules, inaccuracies in representations and warranties. The risk, conventionally understood, lives in the four corners of the agreement.  That framing is no longer enough.

A new category of risk has emerged, one that targets not what a deal says but how it closes. Spoofed emails redirect wire transfers at the moment of closing. AI-generated communications impersonate executives and counsel with alarming fidelity.  Manipulated diligence materials circulate through virtual data rooms looking entirely authentic. These are not hypothetical scenarios. They are recurring features of the modern transactional environment, and no amount of careful drafting fully addresses them.

The Anatomy of Modern Deal Fraud

The legal stakes are significant. Fraud claims still depend on familiar elements: misrepresentation, knowledge, intent, reliance and damages. In Banco Popular North America v. Gandi, the New Jersey Supreme Court reaffirmed that a plaintiff must demonstrate reasonable reliance on a misrepresentation to prevail. In a world of AI-generated communications and spoofed accounts, what constitutes reasonable reliance in a digital transaction has become the central question in deal fraud litigation. The answer turns less on what the contract says than on how the parties actually conducted themselves.

Business Email Compromise

Business email compromise is the most prevalent form of transactional fraud today. The mechanics are simple. A fraudster gains access to or convincingly imitates a party’s email account, monitors deal communications, and at a critical moment near closing sends revised wire instructions directing funds to a fraudulent account. The message looks legitimate, arriving from what appears to be a known address. By the time anyone recognizes the fraud, the money is gone.

Litigation following such a loss turns on reliance. New Jersey courts treat reliance as a fact-intensive inquiry, examining what steps the plaintiff took to verify what it received. In Walid v. Yolanda for Irene Couture, Inc., the Appellate Division held that whether reliance is justified depends on what the plaintiff reasonably could have done to confirm the truth. Applied to modern closings, that principle has teeth. A party that wires funds based solely on emailed instructions, without independent verification, may find a court characterizing its reliance as unreasonable, particularly when simple safeguards were available and unused.

AI-Driven Impersonation and Synthetic Authority

Business email compromise is now the floor, not the ceiling. Artificial intelligence has enabled a more sophisticated category of attack. Fraudsters can generate deepfake video calls that appear to show executives approving transactions, voice clones that confirm payment instructions, and AI-generated emails that replicate a counterparty’s tone, formatting and signature block with precision. Fabricated corporate records and altered diligence materials can be produced and uploaded to virtual data rooms in ways that are nearly impossible to detect. The result is what might be called synthetic authority: communications that look legally sufficient and contextually appropriate but are entirely fabricated.

This creates a doctrinal gap.In Kaufman v. i-Stat Corp., the New Jersey Supreme Court held that fraud requires proof the plaintiff actually received and relied on the misrepresentation. When the apparent speaker is an AI impersonation, the traditional assumptions about authorship, identity and communicative intent collapse. The law has not yet fully adapted, but the practical implication is clear: verification, not appearance, must become the standard for reasonable reliance.

Fraud Embedded in Deal Materials

Not all modern deal fraud targets payment instructions. AI-assisted fabrication of financial statements, altered PDFs and manipulated diligence files are all documented problems. These attacks resemble traditional fraudulent inducement but are amplified by the speed and accessibility of generative AI.

New Jersey law draws a distinction that matters here. Fraud claims tied to inducement, meaning misrepresentations that caused a party to enter a contract, are generally actionable even where the relationship is governed by a written agreement. Fraud claims arising from performance of the contract are typically barred by the economic loss doctrine. When manipulated diligence materials cause a party to close a deal it otherwise would not have entered, the claim sounds in fraudulent inducement and may survive. When the problem surfaces only during performance, contract remedies are likely the exclusive avenue. The timing and character of the fraud can therefore determine whether a tort claim is available at all.

Why Traditional Contract Protections are Not Enough

Transactional lawyers have long managed fraud risk through familiar tools: representations and warranties, indemnities, integration clauses and disclaimers. These remain essential, but they address a different problem. They allocate risk after a deal is struck. They do not protect against fraud in the mechanics of closing.

The economic loss doctrine compounds the limitation. New Jersey courts generally bar parties from recasting contract claims as tort claims where the alleged misconduct arises from performance of the contract itself. Even deliberate wrongdoing may be confined to contractual remedies if it relates to performance rather than inducement. Fraud claims that clear that barrier still face the reliance inquiry, which asks whether the plaintiff could have discovered the truth and failed to look.

The result is a structural gap. Contracts allocate risk on paper, but liability turns on what parties actually did during execution. A perfectly drafted purchase agreement offers no protection when a party wires closing funds based on a spoofed email it never thought to verify.

Adapting the Contract to Address Cyber-Fraud Risk

Contract alone cannot close this gap, but contracts can be made considerably more useful than they typically are. Several categories of provisions deserve attention.

Payment instruction clauses address the most immediate exposure. Agreements should expressly govern how wire instructions are transmitted and confirmed. Provisions that prohibit reliance on emailed instructions alone, require out-of-band telephone confirmation using independently verified contact information, and allocate loss based on compliance with or deviation from the specified protocol are now standard in sophisticated deals and should become routine across the market.

Defined communication channel provisions address the broader infrastructure problem. Contracts can designate approved email domains, require secure portals for sensitive transmissions, and restrict last-minute changes to closing instructions. These provisions establish a contractual baseline that gives meaning to the reliance inquiry: a party that followed the agreed protocol occupies a materially different legal position than one that did not.

Risk-shifting provisions make the allocation explicit. A party that follows the agreed verification procedures bears no loss; a party that deviates does. This aligns contractual allocation with how fraud actually occurs and removes ambiguity about responsibility after the fact.

Cyber-integrity representations round out the picture. Some sophisticated agreements now include representations that a party’s communication systems have not been compromised, that no impersonation or spoofing is known to have occurred, and that data room materials are accurate and unaltered as of closing. These provisions do not prevent fraud, but they create additional remedies and a clearer evidentiary record if fraud surfaces after closing.

Process Design as a Legal Function

The most consequential shift for transactional lawyers is conceptual. Fraud prevention in deal execution is no longer just a drafting problem—it is a process design problem.

New Jersey’s reasonable reliance standard makes this unavoidable. Courts examine whether the victim exercised ordinary diligence, and in a digital environment that inquiry focuses directly on procedure. Were wire instructions confirmed through a known phone number, not one provided in the suspect email?  Were last-minute changes treated with heightened skepticism? Was there a documented protocol, and was it followed?

Transactional lawyers should build verification procedures into their standard closing practice and document them. Pre-closing verification protocols should be circulated to all parties and counsel before closing day. No-change periods, during which revisions to wire instructions will not be honored regardless of how they arrive, reduce the window of exposure. Dual authorization for transfers above defined thresholds adds a layer of internal confirmation. Test wires for significant transactions confirm account details before the full transfer moves.

These measures do more than prevent fraud. They create a contemporaneous record showing that reliance on the verified instructions was reasonable, which may be decisive in any litigation that follows.

Liability Exposure for Transactional Lawyers

As fraud migrates into the closing process, lawyers face exposure the profession has been slow to recognize. Potential claims include negligence for failing to implement reasonable verification safeguards, malpractice tied to supervision of closing mechanics, and in serious cases, claims sounding in aiding and abetting fraud where a lawyer’s conduct facilitated the loss.

The exposure is sharpest for lawyers who serve as escrow agents, transmit wire instructions, or control the closing process. A court assessing liability may view the transactional lawyer as the party best positioned to prevent the loss and therefore the one whose failure to implement safeguards is most consequential. That framing shifts the negligence calculus considerably.

Insurance provides only partial relief. Coverage disputes in social engineering fraud cases are common, frequently turning on questions difficult to predict when a policy is written: whether the loss falls under cyber coverage or professional liability, whether fraud or intentional act exclusions apply, and whether the event is characterized as third-party deception or a failure of internal procedure. Transactional lawyers should understand these gaps and, where possible, align contractual risk allocation with what their policies actually cover.

Ethical Dimensions

The New Jersey Rules of Professional Conduct intersect with these developments in ways the profession has not yet fully worked out.  The duty of competence requires adequate preparation and thoroughness. In a transactional context, that now includes a working understanding of how fraud is perpetrated in modern deal execution, not as a specialty area but as a baseline requirement of practice.

Harder questions arise mid-transaction. What must a lawyer do when communications begin to look suspicious? When does the absence of verification procedures cross from an acceptable judgment call into a failure of competence? New Jersey disciplinary jurisprudence has not yet addressed these questions directly, but the framework is in place. Lawyers who have not thought through their procedures before a problem arises will find themselves poorly positioned when regulators and courts eventually do.

Conclusion: From Drafting Agreements to Designing Transactions

The evolution of deal fraud reflects a broader change in what transactional practice requires. The traditional model assumed that risk lives in the substance of agreements. It does not, not anymore.

Today’s fraud exploits the mechanics of transactions: their dependence on digital communication, their compressed timelines and the trust parties extend to familiar-looking messages. New Jersey law, with its emphasis on reasonable reliance and its careful line between tort and contract, means that liability often turns not on what the agreement says but on what the parties actually did.

For transactional lawyers, the message is direct. The role now extends beyond drafting agreements that allocate risk to designing the systems through which deals close. The most effective protection against modern deal fraud is not found in a representation, a warranty or an indemnity clause. It is found in a process that makes fraud harder to commit and reliance easier to defend. 


You may also enjoy:

and, if you like what you’ve read, please subscribe below or in the right hand column.