Yes, a cyber or crime policy can cover money sent to a fraudster, but usually only up to a sublimit of $100,000 to $250,000 rather than your full cyber limit. Funds transfer fraud is the most frequent cyber loss for professional services firms, and it starts with one convincing email. Who this is for: Architecture firms that move client money or send payment instructions.
The short version
- Funds transfer fraud is the most common cyber loss for professional firms, ahead of ransomware.
- Social engineering coverage usually carries a sublimit far below the headline cyber limit.
- Ask whether the sublimit can be increased. It usually can, for modest premium.
- Multifactor authentication plus a mandatory callback to a known number stops most of these losses.
- Report to the bank and to law enforcement within hours, because recovery odds collapse after day one.
How the fraud actually works
- An attacker gets into an email account, often through a phishing page that captures a password and a session token.
- They watch quietly for days or weeks, learning who pays what and how instructions are worded.
- At the right moment they send an invoice or a change of banking details, sometimes from the real account, sometimes from a domain one character different.
- Money moves. By the time anyone notices, it has been split across accounts and, frequently, moved offshore.
For architecture firms, this is the most likely cyber loss you will ever face, and it does not require anyone to hack anything technical. It requires one person to believe a normal looking email.
Which policy pays, and how much
| Loss | Where it sits | Typical limit available |
|---|---|---|
| Your money sent on a fraudulent instruction | Cyber, funds transfer fraud, or a crime policy | $100K to $250K sublimit is common |
| A client's money you were holding | Crime policy or cyber social engineering | Often needs a specific extension |
| Your client sends money to a fraudster impersonating you | Third party liability under cyber, sometimes Errors and Omissions (E&O) | Full limit, but coverage varies widely |
| Forensics and legal costs after the email breach | Cyber incident response | Usually the full limit |
| Regulatory or notification costs if data was exposed | Cyber | Usually the full limit |
The headline cyber limit is rarely the number that matters here. Ask for the social engineering and funds transfer fraud sublimits specifically, and ask whether they can be increased. On many programs they can, for a modest premium.
The controls that stop it
- Multifactor authentication on every email account, without exception.
- A written rule that no change of payment details is actioned without a callback to a phone number already on file, never a number in the email.
- Dual authorization on any payment above a stated threshold.
- Alerts for mailbox rules that forward or delete messages, which is the fingerprint of an active intrusion.
- Training that shows staff a real example, since the abstract version does not stick.
These are cheap and they work. They are also what carriers now ask about before quoting, so the same controls that prevent the loss also lower your premium.
What this looks like in practice
Illustrative example. Numbers are typical of claims we see and are not a promise of how any specific claim would be handled.
The setup: A architecture firm whose email was compromised and used to send altered payment instructions to a client.
The claim: The matter started with a specified roofing assembly that failed an energy code review after permit. The owner claimed six weeks of delay damages and redesign fees.
The cost: $34,000 in defense costs and $96,000 in settlement, $130,000 in total, paid inside the policy limit after the retention.
The lesson: The incident response costs were covered in full, and the transferred funds were covered only to the social engineering sublimit. Raising that sublimit at renewal cost a small fraction of the shortfall.
Frequently asked questions
Q: Does insurance cover a fraudulent wire transfer?
Often, but usually under a sublimit rather than the full policy limit. Funds transfer fraud and social engineering sublimits of $100,000 to $250,000 are common on small business cyber policies.
Q: What is social engineering coverage?
It covers losses where an employee is deceived into sending money or data voluntarily. It is separate from computer fraud, which covers money taken by a direct system intrusion, and both are worth having.
Q: What if my client sends money to a fraudster impersonating my firm?
That is a third party claim and it can fall under cyber liability or professional liability depending on wording. It is one of the most contested claim types, so confirm your coverage rather than assuming.
Q: How do I stop this from happening?
Multifactor authentication on email and a mandatory callback to a known number before any change of payment details. Those two controls stop the overwhelming majority of these losses.
Q: Will my bank reverse the transfer?
Occasionally, if you report it within hours. Contact the bank and file with the Federal Bureau of Investigation's Internet Crime Complaint Center immediately, because recovery odds fall sharply after the first day.
Q: Can I increase the social engineering sublimit?
Usually yes, for a modest additional premium, especially if you can show multifactor authentication and a documented payment verification process.
How Morrow helps architecture firms
Morrow is a licensed independent commercial insurance brokerage that specializes in architecture firms. Sizing social engineering and funds transfer sublimits properly is exactly the kind of question we answer every week, and because we place this coverage every day we know which carriers write it well, which forms are broad, and which contract language actually needs an endorsement behind it.
- We read the contract clause and tell you what your current policy already does and does not do.
- We market your account to carriers that have real appetite for architecture firms rather than whoever answers first.
- We issue certificates the same day a client asks, with the endorsements listed correctly.
- We stay on the file at renewal so limits, retroactive dates, and contract requirements do not quietly drift.
Get in touch and we will see how we can help. Tell us what you do, send over any contract that is driving the requirement, and send us the question and we will tell you where you stand. Start at morrowinsure.com or reach the team through the contact options on that page.
One more thing. This article is general information for architecture firms and is not legal advice, tax advice, or a statement of coverage. Policy wording controls in every case, and forms vary by carrier and by state. Have a licensed advisor review your own policy and your own contract before you rely on any of it.
Last updated: Reviewed by the Morrow commercial lines team. Last updated August 2026.
