Social Engineering Fraud and Wire Transfer Coverage, Explained (2026)

By Winfield Lee, Licensed Independent Insurance Agent · Serving Georgia & the Southeast · Updated 2026

Short answer

Here is the loss. Your bookkeeper gets an email from a supplier you've paid for six years. New remittance instructions, new account number, polite and unremarkable. She updates the vendor record and pays the next invoice. Three weeks later the real supplier calls asking where their money is.

Nobody hacked anything. Nobody forged a signature. A real employee with real authority made a real transfer. That is exactly why the two policies you'd expect to cover it may both deny it.

The coverage that responds is a specific, separately-elected insuring agreement — usually called social engineering fraud, deception fraud, or fraudulent instruction — and it carries its own sub-limit and its own conditions. If it isn't named on your declarations page, assume you're self-insuring the loss.

The one-line version: this is the most common six-figure loss a small business actually suffers, and it lands in the seam between two policies most owners think already cover it.

The four shapes it takes

The scheme is always the same underneath — convince a trusted person to move money — but it arrives in four recognizable forms:

Contractors get hit disproportionately on the first one, because construction payment chains involve many vendors, large progress payments, and email-based invoicing across parties who rarely meet in person.

Why the crime policy may not respond

A commercial crime policy is a stack of separate insuring agreements. The three people assume will catch this each contemplate something that didn't happen:

Insuring agreementWhat it contemplatesWhy the wire loss may fall outside
Computer fraudA criminal directly entering or altering your computer systems to cause a transferNobody entered your system — they sent an email
Funds transfer fraudA fraudulent instruction sent to your bank without your knowledgeThe instruction to the bank came from you, knowingly
Forgery or alterationA falsified signature or financial instrumentNo instrument was forged
Employee dishonestyTheft by your own employee for their own gainYour employee was deceived, not dishonest

Whether a given policy responds anyway has been litigated repeatedly, with results that differ by jurisdiction, by policy wording, and by fact pattern — which is a polite way of saying you do not want your recovery to depend on it. Carriers resolved the ambiguity in the only way carriers do: by writing an explicit endorsement, and by tightening the base wording so the ambiguity is gone in the other direction.

Why the cyber policy may not respond either

A cyber liability policy is built around the data-and-network event: breach response and notification, regulatory defense, liability to affected parties, network business interruption, ransomware and extortion. Those are real and valuable coverages, and none of them is "we sent money to a criminal."

Direct financial loss from a fraudulently induced transfer sits in an optional insuring agreement — funds transfer fraud, cybercrime, social engineering, fraudulent instruction, the naming is not standardized — and when it is included, it very often comes at a sub-limit well below the policy aggregate. A $1M cyber policy with a $25,000 social engineering sub-limit is a completely ordinary thing to be holding without knowing it.

Do this today: pull the declarations page and look for the insuring agreement by name, then look at the number next to it. Not the policy aggregate — the number next to that line.

The callback condition — where good coverage still pays nothing

This is the part that matters most and gets read least.

Most social engineering endorsements include a condition precedent requiring verification before you execute a transfer request or a change in payment instructions: someone must confirm the request through a different channel than the one it arrived on — typically a phone call to a number already on file for that vendor, not a number supplied in the request itself.

Skip that step and the carrier can deny the claim even though the endorsement is on the policy and the loss is precisely what it describes. This is the single most common reason a business with the right coverage collects nothing.

So treat it as an operating procedure, not policy boilerplate. Write it down. Post it at the AP desk. Make it the rule that nobody — including the owner — is allowed to override by saying it's urgent, because "it's urgent" is the fraud.

What it costs in 2026

CoverageTypical sub-limitIllustrative annual premium*
Social engineering endorsement on a crime policy$100,000–$250,000~$400–$2,000
Funds transfer fraud on a cyber policy$25,000–$250,000Often bundled; higher sub-limits cost extra
Standalone crime policy (small business, full form)$250,000–$1M~$800–$3,500

*Illustrative only — not filed rates. Pricing varies by revenue, transaction volume, industry, prior loss history, and the payment controls you can document.

Two things about that table are worth sitting with. First, the premium is small relative to a single event — a five-figure annual spend does not exist here, and a six-figure loss absolutely does. Second, controls buy limit. Carriers will offer meaningfully higher sub-limits and better pricing to a business that can demonstrate dual authorization and documented out-of-band verification, and some won't offer a serious limit at all without them. The underwriting question and the prevention question have the same answer.

Five controls that stop most of these

  1. Never change vendor banking details from an email. Call a number already on file. Not the number in the message — that number reaches the criminal, who will confirm cheerfully.
  2. Dual authorization above a threshold. Pick a dollar figure that matters to your business and require a second, independent approver above it.
  3. Train the three warning signs: urgency, secrecy, and a change in payment method. Any two together should stop a payment cold. Give staff explicit permission to slow down — most of these succeed because a junior employee didn't want to question the boss.
  4. Multi-factor authentication on every mailbox, plus email authentication (SPF, DKIM, DMARC) on your domain. Most of these schemes start with a spoofed or compromised mailbox, sometimes your vendor's rather than yours.
  5. If it happens, move in hours, not days. Notify the bank immediately and request a recall, and report it to law enforcement including the FBI's IC3. Funds are sometimes recoverable in the first hours and are usually gone by the next business day. Then notify your carrier — late notice is its own coverage problem.

How this fits the rest of your program

Social engineering coverage sits at the intersection of two policies and belongs to neither by default, which is exactly why it gets missed when a business buys insurance one line at a time from different sources. The clean structure for most Southeast small businesses is a crime policy carrying employee dishonesty plus a social engineering endorsement, alongside a cyber policy handling breach response and network interruption — with someone checking that the two don't leave a seam between them. Insider theft and outsider deception are genuinely different exposures and you need both covered; neither endorsement substitutes for the other.

Where Bettr Coverage fits

Bettr Coverage is an independent commercial insurance agency serving Georgia and the wider Southeast. Social engineering is the coverage most often missing from an otherwise well-built program, usually because the crime policy and the cyber policy came from two different places and nobody read them side by side. We pull both declarations pages, confirm whether the insuring agreement exists and at what sub-limit, read the verification condition out loud so your AP process actually matches it, and size the limit against the largest transfer your business realistically makes in a week. One agency, one relationship, the whole program reviewed together — which is how seams like this one get found before a claim rather than after.

Can you name your social engineering sub-limit right now?

Most owners can't — and the number is usually far below the wire they'd actually lose. Bettr Coverage reviews your crime and cyber policies side by side, free.

Get a free coverage review

Common questions about social engineering and wire transfer fraud coverage

What is social engineering fraud in insurance?

A loss where an employee is deceived into voluntarily transferring money — fake vendor bank changes, executive impersonation, compromised mailboxes, payroll diversion. Nothing is hacked and nothing is forged, which is precisely what creates the coverage gap.

Does my crime policy cover a fraudulent wire?

Often not without a specific endorsement. Computer fraud, funds transfer fraud, and forgery all contemplate unauthorized acts, and this transfer was authorized by your own employee. Look for a social engineering or deception fraud endorsement by name.

Does cyber liability cover wire transfer fraud?

Not automatically. Cyber is built around breach and network events. Direct financial loss from a fraudulent instruction is a separate optional insuring agreement, usually at a sub-limit well below the policy aggregate. Verify it's on your declarations page.

How much does the coverage cost in 2026?

Roughly a few hundred to about $2,000 a year for a $100,000–$250,000 sub-limit added to a crime policy, depending on revenue, transaction volume, and the payment controls you can document. Better controls get better limits and better pricing.

What is the callback condition and why do claims get denied over it?

Most endorsements require verifying a transfer or payment-change request through a channel other than the one it arrived on — a call to a number already on file. Skip it and the carrier can deny even though the endorsement is on the policy. It's the most common reason covered businesses collect nothing.

Isn't this the same as employee dishonesty coverage?

No. Employee dishonesty covers theft by your own staff for their own gain. Social engineering covers an outsider deceiving a loyal employee. Different insuring agreements, and neither substitutes for the other — most businesses need both.

What controls actually prevent these losses?

Never change vendor banking from an email; call a known number. Require dual authorization above a threshold. Train on urgency, secrecy, and payment-method changes. MFA and email authentication on all mailboxes. And if it happens, notify the bank and law enforcement within hours, not days.

For general information only. Not a quote, contract of insurance, or legal advice. Cost ranges and sub-limits are illustrative, not filed rates, and vary by revenue, transaction volume, industry, controls, and loss history. Insuring agreement names, definitions, sub-limits, exclusions, and verification conditions differ materially by carrier and policy form — read your own declarations page and endorsements. Coverage litigation outcomes referenced are general and jurisdiction-dependent. Coverage subject to policy terms and carrier appetite.