Business email compromise (BEC) is dangerous because the payment can look legitimate. An employee receives an apparently authentic instruction from a CEO, vendor, lawyer or customer and voluntarily sends money to the criminal’s account. That fact pattern can sit between traditional “computer fraud” and traditional “theft,” which is why insurance wording matters so much.
The FTC describes social engineering and phishing as scams that manipulate employees into sending money or sensitive information. The NAIC’s cybersecurity insurance reporting also identifies BEC and fraudulent wire transfers as significant cyber-loss drivers.
Why cyber and crime policies can overlap
| Coverage concept | Typical focus | Question for a deceptive-transfer claim |
|---|---|---|
| Cyber insurance | Network/security events, privacy incidents and cyber response | Does the form expressly cover BEC, phishing or fraudulent funds transfer? |
| Commercial crime | Employee dishonesty, forgery, computer/funds-transfer fraud and other crime perils | Does the insuring agreement require an unauthorized transfer rather than an employee-authorized payment? |
| Social-engineering endorsement | Impersonation-induced voluntary transfer | What sublimit, callback requirement or verification condition applies? |
| Funds-transfer fraud | Fraudulent electronic instructions to a financial institution | Who sent the instruction and whose system/account was compromised? |
Policy labels are not enough. Two products both marketed as “cyber insurance” can handle social-engineering losses differently, and a commercial crime form may have a separate endorsement specifically for deception-based payments.
Common social-engineering scenarios
- Vendor bank-change fraud. A criminal impersonates a supplier and asks Accounts Payable to change bank details.
- CEO fraud. An employee receives an urgent instruction that appears to come from senior management.
- Real-estate or transaction diversion. Closing funds are redirected using compromised or spoofed email.
- Payroll diversion. A criminal impersonates an employee and changes direct-deposit details.
- Invoice manipulation. A real invoice is altered so payment goes to the attacker’s account.
Why a “voluntary” payment can create a coverage dispute
In many social-engineering attacks, the employee intended to click “send” on the transfer—but was deceived about the recipient or reason. Some traditional crime clauses were drafted around money being taken without the insured’s authorization. Modern social-engineering endorsements are designed to address that gap, but they may carry lower sublimits and specific procedures.
Controls can affect underwriting and claims
Insurers increasingly ask how a company verifies payment changes and high-value wires. A policy can require dual authorization, out-of-band verification or a callback to a previously known contact number. Failure to follow a stated condition can complicate a claim.
The FTC recommends clear payment-approval procedures and independent verification of invoices and payment requests. For a vendor bank change, verify using trusted contact information already on file—not the phone number or link in the change request itself.
Coverage checklist for renewal
- Find the exact limit for social engineering/BEC, not just the overall cyber limit.
- Check whether the coverage is inside or outside another aggregate limit.
- Review computer fraud and funds-transfer fraud definitions.
- Identify any voluntary-parting or authorized-transfer exclusion.
- Read verification, callback and dual-control conditions.
- Check waiting periods or deductibles for business interruption triggered by a cyber event.
- Coordinate cyber and commercial crime policies to reduce gaps and disputes over which form responds.
What to do after discovering a fraudulent transfer
Act immediately. Contact the bank’s fraud department and request a recall or freeze, preserve email headers and transaction records, notify the insurer or broker under the policy’s notice requirements, and follow law-enforcement reporting instructions. Delay can reduce the chance of recovering transferred funds.
Do not destroy or alter evidence while investigating. Cyber insurers often have breach-response vendors, forensic firms and counsel available through the policy, but use of vendors can be subject to consent requirements.
Frequently asked questions
Does cyber insurance always cover business email compromise?
No. Some cyber forms provide a BEC or fraudulent-transfer benefit, while others may require an endorsement or leave the exposure primarily to a crime policy.
Is computer fraud the same as social-engineering fraud?
Not necessarily. Computer fraud can involve unauthorized use of a computer system; social engineering often involves an authorized employee making a payment because of deception. Definitions vary by policy.
Why can the social-engineering limit be lower?
Insurers may apply a separate sublimit to deception-based payment losses. Compare that amount with the company’s realistic maximum wire/invoice exposure.
Can better payment controls reduce risk?
Yes. Independent verification, dual approval, staff training and strong email security can reduce the chance that a fraudulent request results in a completed transfer.
Sources & further reading
Reviewed October 3, 2026. Coverage for deceptive transfers is highly wording-specific; compare cyber and crime contracts, endorsements, sublimits and conditions.
