Licensed Agency · NPN #22222940·Prefer a human? Call our Orlando team: +1 (689) 353-8505
Truscott Insurance SolutionsTruscott Insurance Solutions
FeaturesHow It WorksBlog
Truscott Insurance SolutionsTruscott Insurance Solutions

Your insurance ally. We simplify policies, coach you on claims, and monitor for gotchas, so you're never caught off guard.

Call us: +1 (689) 353-8505

Tools

  • Policy Simplified
  • Claims Coach
  • Blog

Products

  • Auto Insurance
  • Home Insurance
  • Business Insurance
  • Cyber Insurance

Legal

  • Privacy Policy
  • Do Not Sell My Personal Information
  • Terms of Service
  • Licenses

© 2026 Truscott Inc. All rights reserved.

Truscott provides insurance information tools. AI-generated analyses are for informational purposes only and do not constitute insurance advice, legal advice, or coverage guarantees.

Back to Blog
Cyber Insurance

Does Business Email Compromise Insurance Actually Cover Wire Fraud Losses?

Truscott Team
August 29, 2026
7 min read

Business email compromise is the single most frequent way small and mid-sized companies lose real money to cybercrime. Someone gets into an email account, watches the conversation, and redirects a payment. The frustrating part is that many owners discover their cyber policy responds to the breach but not to the missing funds.

What business email compromise actually looks like

BEC rarely involves dramatic hacking. A criminal obtains a password through phishing, credential stuffing, or a leaked database, then quietly logs into a mailbox and reads. They learn who approves payments, what a normal invoice looks like, and when big transactions happen. Sometimes they set inbox rules that hide their replies so the real account owner never sees the conversation.

When the moment arrives, they send a message that looks entirely normal. A vendor emails updated banking instructions. A title company sends closing wire details. The CEO asks the bookkeeper to push a payment through before a flight. The money leaves, and by the time anyone notices, it has been moved through several accounts.

Two variations matter for insurance purposes. In a true BEC, the criminal is inside your email system. In a spoofing or impersonation attack, they never touch your systems at all — they register a lookalike domain and simply pretend to be you or your vendor. Some policies treat these two scenarios very differently.

Which part of a cyber policy responds

A cyber policy is not one coverage. It is a bundle of separate insuring agreements, each with its own limit and sometimes its own deductible. A BEC event can trigger several at once, and understanding which does what is the key to knowing whether you are protected.

  • Incident response and forensics: pays specialists to determine what the attacker accessed, how they got in, and whether other accounts were touched.
  • Breach notification and privacy liability: responds if the compromised mailbox contained personal information about clients, patients, or employees.
  • Business interruption: may apply if you had to shut down systems or lost revenue during the response.
  • Social engineering or funds transfer fraud: the coverage that actually reimburses the money you sent to the criminal.

That last bullet is where businesses get caught. The forensic and legal side of a BEC is usually covered generously, often at the full policy limit. The stolen funds themselves fall under a separate, much smaller crime-style coverage part that many policies include only by endorsement.

Why business email compromise insurance often has a sublimit

Carriers price funds transfer losses differently than data breach losses because the exposure is direct and immediate. A wire goes out, the money is gone, and there is no lengthy claims process to reduce the number. To manage that, insurers cap social engineering coverage well below the aggregate limit.

A common pattern on small business policies is a $1 million aggregate cyber limit with a $50,000 or $100,000 sublimit for social engineering fraud. Some policies offer $250,000. A handful of carriers will match the full limit for well-controlled accounts, but you generally have to ask and often have to answer additional underwriting questions about your payment verification procedures.

The mismatch matters because average BEC losses have climbed steadily. A construction firm paying a subcontractor, a law firm handling escrow, or a real estate brokerage coordinating a closing can easily wire six figures in a single transaction. If your sublimit is $50,000 and the wire was $180,000, the policy pays $50,000 and you absorb the rest. That is the single most common surprise in cyber claims for small businesses.

The conditions that can void a social engineering claim

Even when the sublimit is adequate, social engineering coverage usually comes with conditions precedent — steps you must have taken for the coverage to apply. These are not fine print you can ignore, because adjusters check them.

The most common requirement is out-of-band verification. Before changing payment instructions or sending funds above a stated threshold, someone at your company must call the requester at a phone number already on file — not the number in the email. Some policies require dual authorization on transfers over a dollar amount. Others require that the request come from a known vendor with an existing relationship.

Policies also differ on whose deception is covered. A narrow form covers only impersonation of a company executive or employee. A broader form adds vendor and client impersonation, which is where the majority of real-world losses actually occur. If your policy only covers executive impersonation and your loss came from a spoofed supplier invoice, you may have no coverage for the funds at all. When you review the actual policy language, or run it through a policy checkup, this is one of the first clauses worth reading word for word.

What business email compromise insurance does not replace

Insurance is the backstop, not the control. Because the funds coverage is sublimited and conditional, the practical value of prevention is higher for BEC than for almost any other cyber risk. Three controls do most of the work.

Multi-factor authentication on every email account is the baseline. Most carriers now require it just to offer cyber coverage, and it stops the overwhelming majority of credential-based mailbox takeovers. Second, a written payment verification rule that applies to everyone, with no exception for urgent requests from the boss. Third, monitoring for suspicious inbox rules, which is often the first sign an account is compromised.

Also understand what happens after a wire goes out. Speed matters enormously. If you contact your bank within roughly 24 to 72 hours and file an IC3 complaint with the FBI, there is a genuine chance funds can be frozen or recalled. Recovery rates drop sharply after that window. Your cyber insurer's response hotline can often help coordinate this, which is another reason to call them before you call anyone else.

Who has the highest exposure

Any business that sends or receives payments by wire or ACH has BEC exposure, but some professions sit squarely in the crosshairs because criminals know large transfers are routine. Real estate brokerages and title agencies handle closing funds. Law firms manage trust and escrow accounts. CPA firms hold client banking details and often process payments on behalf of others.

Contractors and wholesalers are targeted too, because subcontractor and supplier payments are frequent and the invoice formats are easy to imitate. Medical and dental practices face a compounded version of the problem: a compromised mailbox may also contain protected health information, turning a funds loss into a HIPAA notification event with its own set of costs.

For these businesses, the question is not whether to carry cyber coverage but whether the social engineering sublimit is sized to the largest payment they might realistically send in a single day. That is a specific, answerable number, and it should drive the limit you buy.

Frequently asked questions

Does a general liability policy or a BOP cover a fraudulent wire transfer?

Almost never. General liability responds to bodily injury and property damage claims from third parties, and a standard business owners policy excludes most electronic funds losses. Some BOPs offer a small cyber endorsement with a token limit, often $10,000 to $25,000, which is rarely enough for a real BEC loss. Standalone cyber insurance with an explicit social engineering coverage part is the reliable answer.

What is the difference between funds transfer fraud and social engineering coverage?

Funds transfer fraud typically covers losses where a criminal directly instructs your bank to move money without your knowledge. Social engineering covers losses where your own employee was tricked into authorizing the transfer voluntarily. Most real BEC losses are the second type, so a policy with funds transfer fraud but no social engineering coverage may leave the exact scenario you are worried about uninsured.

Will my claim be denied if my employee ignored our verification policy?

It depends on how the policy is worded. If callback verification is written as a condition precedent to coverage, skipping it can defeat the claim. If it is simply an underwriting representation, a single lapse is less likely to void coverage, though the insurer may still investigate. This is a meaningful difference in language and worth confirming before you bind.

Does cyber insurance cover the money if a client was tricked into paying a criminal instead of us?

Sometimes, under what is often called client or third-party social engineering coverage, but it is not standard. Many policies only cover funds you lose from your own accounts. If a customer wires a payment to a fraudster impersonating your business, you may face a dispute over who bears the loss, and only a broadened endorsement will respond.

Do I need to report a BEC even if no money was lost?

Yes, report it to your carrier. A compromised mailbox is a data event regardless of whether a payment went out, and if it contained personal information you may have notification obligations. Reporting also preserves your right to coverage if related losses surface later.

What Truscott recommends

Pull your cyber policy and find two numbers: the social engineering sublimit and the largest single payment your business might send in a week. If the second number is bigger than the first, you have a gap worth closing, and it is usually inexpensive to raise. A Truscott coverage review will also flag the verification conditions and impersonation definitions that decide whether a BEC claim gets paid at all. Reach out for a review, or request a business quote to see what stronger business email compromise insurance limits would cost.

Free tools from Truscott

  • Cyber insurance
  • Florida cyber insurance

More from the blog

Cyber Insurance

What Changes at Your Cyber Insurance Renewal?

Cyber renewals move more than most lines of insurance. Learn what underwriters re-examine each year, which security controls drive pricing, and how to prepare your application before it goes back to market.

Cyber Insurance

What Happens After a HIPAA Breach: Notification, Penalties, and Coverage?

A HIPAA breach starts a federal notification clock, a penalty assessment, and a cascade of costs. Here is what happens at each stage and which parts of a cyber policy respond.