The email looks like it's from the owner. It's short, it's urgent, and it asks for a wire transfer today. Someone on your team, doing what they believe the business needs, sends the money. This is business email compromise (BEC), and it's expensive. The FBI's Internet Crime Complaint Center logged $3.05 billion in BEC losses across 24,768 complaints in 2025, up from $2.77 billion the year before. That works out to roughly $123,000 per complaint, and most of that money moves by wire or ACH, which makes it hard to pull back once it's gone. The question most owners ask is "do I have cyber coverage?" The better question is "what does my policy actually pay when an employee is tricked into sending the money?" Here are five myths worth checking against your own policy.
First, the Vocabulary
Social engineering fraud is when an employee is tricked into voluntarily sending money or valuables based on fraudulent instructions, like a fake vendor or executive email. Funds transfer fraud and computer fraud usually describe a criminal getting into a system and moving money without anyone at the business authorizing it. Policies treat these differently, and the difference often decides the payout.
Myth 1: "My cyber policy pays its full limit."
Reality: Social engineering coverage is usually an optional add-on or a sublimit, meaning a lower cap inside the larger policy. Broker guidance commonly cites sublimits of $100,000 to $250,000, even on policies with $1 million or more in total limits. A $1 million cyber policy can pay $100,000 for a fake-boss wire and still be working exactly as written.
Myth 2: "If it's fraud, some part of my policy will cover the whole loss."
Reality: Which coverage responds depends on how the loss happened. In a 2021 Fifth Circuit case, a Mississippi manufacturer lost more than $1 million after an email posing as a regular vendor changed its payment instructions. Its crime policy carried $1 million limits for computer and funds transfer fraud, but only $100,000 for social engineering. Because employees had authorized the transfers, the courts held the smaller limit applied. (The Fifth Circuit's opinion was unpublished and isn't binding precedent, and every policy is worded differently, but it shows how much the fine print matters.)
Myth 3: "My BOP or general liability covers it."
Reality: A Business Owner's Policy typically bundles general liability, property, and business interruption coverage. Wire and social engineering fraud generally falls under commercial crime or cyber coverage instead. If neither is on your program, ask before assuming. Our guide to cyber insurance for North Shore small businesses covers the basics.
Myth 4: "Coverage applies no matter what procedures we follow."
Reality: Some policies make payment conditional on verification steps, such as confirming payment changes through a callback to a known number. Underwriters commonly ask about callback verification and dual authorization on applications, and losses that stem from ignoring your own documented procedures can be disputed or excluded. Good controls protect both the money and the claim.
Myth 5: "It only matters for wire transfers."
Reality: BEC can also mean fraudulent invoices, redirected vendor payments, payroll changes, and gift card purchases. Not every policy treats those the same way as a wire. Some social engineering coverage extends to invoices and gift cards, and some doesn't.
Five Questions to Ask Your Agent
- Do I have social engineering or funds transfer fraud coverage, and does it sit in my crime policy or my cyber policy? What is the sublimit, and is it separate from the rest of the policy? Does it cover fake invoices, payroll diversion, and gift cards, or only wires? Are there verification requirements, like callbacks or dual approval, that I have to follow? If my limit is $100,000, what would a $400,000 loss actually cost us?
If It Happens
Call your bank right away to ask about a recall, report the fraud to the FBI's Internet Crime Complaint Center at ic3.gov, and notify your insurer or agent promptly, since policies set reporting deadlines. Speed matters most in the first hours.
Why This Hits Small Teams Hardest
Scams like this target payment workflows that one or two people handle. That describes a lot of North Shore offices: medical and dental practices, law and financial firms, contractors, and family-run retailers. Not sure what your social engineering limit is? Call North Shore Insurance Associates at 847-315-0170 for a plain-English review. Better Coverage. Smarter Savings. This article is educational and general in nature. Coverage, limits, and terms vary by carrier and policy. Speak with a licensed agent for guidance specific to your business.
FAQ
Does cyber insurance cover a fake invoice or wire transfer scam? Sometimes. Coverage for social engineering fraud is often an optional add-on or a sublimit, commonly $100,000 to $250,000, so it's worth checking both the limit and the policy wording. What is social engineering fraud coverage? It covers losses when an employee is tricked into sending money or valuables based on fraudulent instructions, such as a fake vendor or executive email. It's typically an endorsement or sublimit on a commercial crime or cyber policy. Does a business owner's policy (BOP) cover wire fraud? Usually not. A BOP typically bundles general liability, property, and business interruption coverage. Wire and social engineering fraud generally requires commercial crime or cyber coverage, so check your policy wording.
