{"success":true,"data":{"id":"mortgage-refinance-closing-phish","label":"Fake lender claiming a pre-approved mortgage refinance requires identity or bank account verification via email link to lock in the rate — credential-harvest and bank-drain fraud; real mortgage refinance closings happen through authenticated lender portals, not cold email links.","description":"Fake mortgage lender or refinance company claiming a pre-approved mortgage refinance requires identity verification, income confirmation, or bank account details via email link to lock in a rate before it expires — credential-harvest and bank-drain fraud targeting homeowners. Real mortgage refinance origination is handled through authenticated lender portals, title companies, and closing attorneys; cold emails demanding identity and banking credentials to lock a refinance rate are not a legitimate lender workflow. Distinct from realestate-closing-wire-fraud (wire-transfer redirection during active closing) — this targets the refinance origination and rate-lock phase. Detection: mortgage refinance pre-approved/rate lock expiring + verify identity/provide bank/submit income vocabulary + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +4. Source: GC1-R24; CFPB mortgage refinance fraud advisory; FTC mortgage relief scam report 2025.","tier":"danger","category":"phishing","isThin":false}}