Business Insurance

Wire Fraud and Business Email Compromise: A Cyber Warning for Small Businesses

By October 5, 2026No Comments

A small business recently came frighteningly close to a significant wire fraud loss.

Someone had gained access to its email environment and apparently had enough control to compromise the administrative side of the system. An email address was created that looked almost identical to a legitimate one.

And then, apparently, they waited.

We don’t yet know how long the activity had been going on. But when a legitimate wire transfer was being planned, an attempt was made to change the account information so the money would be wired to a different account.

Fortunately, something didn’t look right. The change was questioned and verified before the transfer was completed.

The money didn’t move. But it easily could have.

This Is Business Email Compromise

Business Email Compromise, often called BEC, is a form of cyber fraud that can lead to wire fraud and other financial losses.

Unlike a cyberattack that immediately shuts down a computer or announces itself with a ransom demand, this type of attack can be quiet.

Criminals may gain access to an email account or environment and monitor communications. They can learn who handles payments, who the business works with, how people communicate and when a transaction is expected.

Then they can use that information at exactly the right moment.

The threat is significant. The FBI’s Internet Crime Complaint Center reported more than $3 billion in Business Email Compromise losses in 2025 alone.

Multiple Parties Can Mean Multiple Points of Exposure

Wire transfers and significant business transactions often involve multiple people.

Communications may pass among customers, vendors, attorneys, accountants, lenders, banks, employees or other third parties.

That matters because your own email system doesn’t necessarily have to be the only point of compromise.

If criminals gain access somewhere in the communication chain, they may learn enough about a legitimate transaction to make a fraudulent request appear convincing.

The parties may be real.
The transaction may be real.
The amount and timing may be real.

Only the destination for the money has changed.

That’s why an unexpected change in wire or banking instructions deserves independent verification—regardless of how legitimate the email appears.

They Had Dual Authentication

There is another important part of this particular experience.

The business was using dual authentication.

Despite that safeguard, the criminals apparently gained sufficient control over the email environment that the authentication protections were also affected.

The exact nature and extent of the compromise are still being investigated, but it demonstrates an important point:

Cybersecurity is not a one-and-done task.

Technology and cyber threats are constantly changing. The security measures that were appropriate when your systems were installed may need to evolve as criminals develop new techniques and your business changes how it operates.

Multifactor authentication remains an important safeguard. So are strong passwords, carefully controlled administrative privileges, monitoring, software updates and good IT security practices.

Businesses should periodically revisit their cybersecurity with their IT professionals rather than assuming protections put in place several years ago are still enough.

When Money Is Moving, Add Another Layer

Technology isn’t the only defense.

Businesses should also have clear procedures for changes to wire transfers, bank accounts and payment instructions.

One simple rule can add another layer of protection:

A change in banking or wire instructions is never approved by email alone.

If banking information changes, call a contact you already know using a phone number you already have. Don’t rely on the telephone number or contact information contained in the email requesting the change.

That additional step may seem inconvenient when everyone is trying to complete a transaction.

It can also be the step that prevents the money from going to a criminal.

What About Cyber Insurance?

The business in this situation had cyber insurance.

That’s important. But having insurance doesn’t make an incident like this insignificant.

Once an email environment has been compromised, the business may need to determine:

  • How did the criminals gain access?

  • How long were they there?

  • What information could they see?

  • Were other accounts or systems affected?

  • Was customer, employee or financial information exposed?

  • What needs to change before the business can be confident its systems are secure?

There can be IT and forensic work, business disruption, communication with financial institutions and potentially legal, regulatory or notification considerations.

And if the wire had actually been transferred, there would have been another important question:

How would the insurance policy respond to the wire fraud itself?

Cyber policies aren’t all the same. Coverage involving Business Email Compromise, social engineering, fraudulent funds transfers and wire fraud can vary by policy, including limits, conditions and exclusions.

Simply knowing that your business “has cyber insurance” doesn’t necessarily tell you how the policy would respond to a particular incident.

Cyber Risk Should Be an Ongoing Business Conversation

You don’t need to be a large corporation to be a target. If your business uses email, online banking, electronic payments or wire transfers, cyber risk should be part of your ongoing risk-management process.

Periodically ask:

  • Are we using current security practices, including multifactor authentication?

  • Who has administrator access to our systems?

  • How would we recognize unusual activity?

  • How do we verify changes to wire or payment instructions?

  • Are employees receiving updated cybersecurity awareness training?

  • Have our vendors or financial processes changed?

  • When did we last review our cyber insurance?

  • Do we understand how our policy addresses Business Email Compromise, social engineering and wire fraud?

Cyber threats will continue to evolve. The way a business protects itself needs to evolve with them.

In this case, someone questioned the change before the money moved. That additional verification may have prevented a devastating financial loss.

Cyber insurance can be an important part of protecting a business, but insurance is only one layer. Technology, employee awareness, financial controls, insurance and good business procedures need to work together.

And sometimes the most important protection is simply having someone willing to stop a transaction and ask:

“Why did these instructions change?”

This example has been generalized to protect the privacy of the business involved. Insurance coverage, eligibility, limits, exclusions and policy terms vary by insurance company and individual risk. This resource provides general information and does not determine coverage for a specific business or cyber event.