Wire Fraud and Social Engineering Claims

Yes, a cyber or crime policy can cover money sent to a fraudster, but usually only up to a sublimit of $100,000 to $250,000 rather than your full cyber limit. Funds transfer fraud is the most frequent cyber loss for professional services firms, and it starts with one convincing email. Who this is for: Technology services firms and managed service providers that move client money or send payment instructions.


The short version

  • Funds transfer fraud is the most common cyber loss for professional firms, ahead of ransomware.
  • Social engineering coverage usually carries a sublimit far below the headline cyber limit.
  • Ask whether the sublimit can be increased. It usually can, for modest premium.
  • Multifactor authentication plus a mandatory callback to a known number stops most of these losses.
  • Report to the bank and to law enforcement within hours, because recovery odds collapse after day one.

How the fraud actually works

  1. An attacker gets into an email account, often through a phishing page that captures a password and a session token.
  2. They watch quietly for days or weeks, learning who pays what and how instructions are worded.
  3. At the right moment they send an invoice or a change of banking details, sometimes from the real account, sometimes from a domain one character different.
  4. Money moves. By the time anyone notices, it has been split across accounts and, frequently, moved offshore.

For technology services firms and managed service providers, this is the most likely cyber loss you will ever face, and it does not require anyone to hack anything technical. It requires one person to believe a normal looking email.

Which policy pays, and how much

LossWhere it sitsTypical limit available
Your money sent on a fraudulent instructionCyber, funds transfer fraud, or a crime policy$100K to $250K sublimit is common
A client's money you were holdingCrime policy or cyber social engineeringOften needs a specific extension
Your client sends money to a fraudster impersonating youThird party liability under cyber, sometimes Errors and Omissions (E&O)Full limit, but coverage varies widely
Forensics and legal costs after the email breachCyber incident responseUsually the full limit
Regulatory or notification costs if data was exposedCyberUsually the full limit

The headline cyber limit is rarely the number that matters here. Ask for the social engineering and funds transfer fraud sublimits specifically, and ask whether they can be increased. On many programs they can, for a modest premium.

The controls that stop it

  • Multifactor authentication on every email account, without exception.
  • A written rule that no change of payment details is actioned without a callback to a phone number already on file, never a number in the email.
  • Dual authorization on any payment above a stated threshold.
  • Alerts for mailbox rules that forward or delete messages, which is the fingerprint of an active intrusion.
  • Training that shows staff a real example, since the abstract version does not stick.

These are cheap and they work. They are also what carriers now ask about before quoting, so the same controls that prevent the loss also lower your premium.


What this looks like in practice

Illustrative example. Numbers are typical of claims we see and are not a promise of how any specific claim would be handled.

The setup: A technology services firm whose email was compromised and used to send altered payment instructions to a client.

The claim: The matter started with a firewall rule change during an after hours migration. Remote desktop access was exposed to the internet and the client's data was encrypted three days later.

The cost: $61,000 in defense costs and $275,000 in settlement, $336,000 in total, paid inside the policy limit after the retention.

The lesson: The incident response costs were covered in full, and the transferred funds were covered only to the social engineering sublimit. Raising that sublimit at renewal cost a small fraction of the shortfall.


Frequently asked questions

Q: Does insurance cover a fraudulent wire transfer?
Often, but usually under a sublimit rather than the full policy limit. Funds transfer fraud and social engineering sublimits of $100,000 to $250,000 are common on small business cyber policies.

Q: What is social engineering coverage?
It covers losses where an employee is deceived into sending money or data voluntarily. It is separate from computer fraud, which covers money taken by a direct system intrusion, and both are worth having.

Q: What if my client sends money to a fraudster impersonating my firm?
That is a third party claim and it can fall under cyber liability or professional liability depending on wording. It is one of the most contested claim types, so confirm your coverage rather than assuming.

Q: How do I stop this from happening?
Multifactor authentication on email and a mandatory callback to a known number before any change of payment details. Those two controls stop the overwhelming majority of these losses.

Q: Will my bank reverse the transfer?
Occasionally, if you report it within hours. Contact the bank and file with the Federal Bureau of Investigation's Internet Crime Complaint Center immediately, because recovery odds fall sharply after the first day.

Q: Can I increase the social engineering sublimit?
Usually yes, for a modest additional premium, especially if you can show multifactor authentication and a documented payment verification process.


How Morrow helps technology services firms and managed service providers

Morrow is a licensed independent commercial insurance brokerage that specializes in technology services & managed service providers. Sizing social engineering and funds transfer sublimits properly is exactly the kind of question we answer every week, and because we place this coverage every day we know which carriers write it well, which forms are broad, and which contract language actually needs an endorsement behind it.

  • We read the contract clause and tell you what your current policy already does and does not do.
  • We market your account to carriers that have real appetite for technology services firms and managed service providers rather than whoever answers first.
  • We issue certificates the same day a client asks, with the endorsements listed correctly.
  • We stay on the file at renewal so limits, retroactive dates, and contract requirements do not quietly drift.

Get in touch and we will see how we can help. Tell us what you do, send over any contract that is driving the requirement, and send us the question and we will tell you where you stand. Start at morrowinsure.com or reach the team through the contact options on that page.


One more thing. This article is general information for technology services firms and managed service providers and is not legal advice, tax advice, or a statement of coverage. Policy wording controls in every case, and forms vary by carrier and by state. Have a licensed advisor review your own policy and your own contract before you rely on any of it.

Last updated: Reviewed by the Morrow commercial lines team. Last updated August 2026.

Yes, a cyber or crime policy can cover money sent to a fraudster, but usually only up to a sublimit of $100,000 to $250,000 rather than your full cyber limit. Funds transfer fraud is the most frequent cyber loss for professional services firms, and it starts with one convincing email.