The short version
- Business email compromise is big. The FBI's Internet Crime Complaint Center logged 21,442 business email compromise complaints in 2024, with reported losses of more than $2.77 billion.
- Three different losses, three different coverages: an employee tricked into paying (social engineering), a criminal moving money directly (funds transfer fraud), and your customers paying a criminal (invoice manipulation).
- They are usually sublimited, often far below the main policy limit, and sometimes only available by endorsement.
- Many policies require verification, such as a call-back to a known number before changing payment details. Skipping it can void the coverage.
- Speed recovers money. In 2024, the FBI's Recovery Asset Team froze about $561.6 million of the $848.4 million in attempted theft it worked on, a 66% success rate. Call your bank first.
How the scams work
| Scam | How it happens | Who loses the money |
|---|---|---|
| Vendor impersonation | An email that looks like a regular supplier says its bank account has changed | You pay the criminal; the real vendor is still owed |
| CEO or owner impersonation | A spoofed or hacked email from "the boss" asks for an urgent wire or gift cards | You |
| Hacked email, altered invoice | A criminal inside your email changes the bank details on invoices you send | Your customer pays the criminal; you are still owed |
| Payroll diversion | A fake request from an "employee" changes their direct deposit | You, and the employee's paycheck |
| Account takeover | A criminal logs into your bank or payment portal and sends money out | You |
| Closing or escrow fraud | Fake wiring instructions for a real estate closing or large purchase | The buyer, or whoever relied on the instructions |
Which coverage responds
| What happened | Coverage that usually applies | Where it lives |
|---|---|---|
| An employee was deceived into sending money | Social engineering fraud | Cyber endorsement or sublimit, or a crime policy endorsement |
| A criminal accessed your bank or systems and moved money without anyone's approval | Funds transfer fraud, or computer fraud | Cyber or crime |
| Your hacked email sent customers fake invoices, and you cannot collect from them | Invoice manipulation | Some cyber policies, as a sublimit |
| An employee stole money | Employee theft | Crime |
| A client lost money relying on instructions from your hacked email, and sues you | Possibly privacy or network security liability, or professional liability | Cyber or professional liability, depending on wording |
The difference between social engineering and funds transfer fraud matters. Many policies treat a transfer that your own employee authorized, even under false pretenses, as social engineering, not funds transfer fraud, which usually means a lower sublimit. See cyber vs tech E&O vs crime for how to coordinate the two policies.
The fine print that decides claims
| Term | What to check |
|---|---|
| Sublimit | How much the policy pays for this loss, separate from the main limit. Compare it with your largest regular payment. |
| Verification condition | Whether coverage requires a call-back to a known number, or another procedure, before changing payment instructions |
| Retention | Some policies apply a separate, higher deductible to fraud losses |
| Definition of "fraudulent instruction" | Whether it covers email, phone, text, and fake vendor portals |
| Your money vs others' | Whether it covers only your funds, or also client or escrow funds you hold |
| Invoice manipulation | Whether it pays the full invoice amount, or only your cost of providing the goods or services |
| Crime and cyber overlap | Which policy pays first, and whether either says the other must respond |
A verification procedure that works, and satisfies insurers
- Never act on payment changes received by email alone, even from a known address.
- Call back using a phone number already on file, not one in the request.
- Require a second person to approve new payees and bank changes above a set amount.
- Watch for urgency, secrecy, and last-minute changes. Those are the hallmarks of the scam.
- Turn on multifactor authentication for email and banking. Most invoice scams start with a hacked mailbox.
- Write the procedure down and train on it, so you can show the insurer it exists.
If it happens: the first hour
| Step | Why |
|---|---|
| 1. Call your bank's fraud line and ask for a recall of the wire | Recovery depends on stopping the money before it is moved again |
| 2. File a complaint at ic3.gov | The FBI's Recovery Asset Team works with banks to freeze funds through the Financial Fraud Kill Chain |
| 3. Call your insurer's claims or breach hotline, or your broker | Fraud and cyber coverage usually require prompt notice |
| 4. Secure the email account | Reset passwords, turn on MFA, and look for forwarding rules the attacker set up |
| 5. Warn customers and vendors | If your email was compromised, others may receive fake invoices from you |
| 6. Preserve the emails and records | Investigators and the insurer will need them |
If the attacker had access to your email, there may also be a data breach. Mailboxes often contain personal information that triggers Washington's breach notice rules.
How much coverage to buy
Set the social engineering and funds transfer sublimits from your real exposure:
- Your largest regular outgoing payment, such as a supplier invoice, payroll, or a property or equipment purchase
- Client or escrow funds you move
- The largest invoice a customer could pay to the wrong account
If the sublimit offered is well below those, ask for more, add or coordinate a crime policy, or tighten approvals so no single payment can exceed what is insured. More on sizing in how much cyber insurance a small business needs.
Businesses with the most exposure
- Accounting, bookkeeping, and law firms moving client funds or managing trust accounts. See the CPA firm story and the law firm story.
- Contractors and suppliers sending and receiving large progress payments.
- Real estate, property management, and escrow businesses handling deposits and closings.
- Any business paying many vendors by ACH or wire.