Business email compromise, commonly known as BEC, is a category of cyber crime in which attackers compromise or impersonate a business email account and use it to deceive employees into wiring money to fraudulent accounts or disclosing sensitive information. Unlike ransomware, BEC involves no malware, no encrypted systems, and no system intrusion in the traditional sense. The attack is entirely social — it relies on deception, manipulation, and the exploitation of business processes that most companies have never designed with fraud in mind.

Despite this seemingly low-tech character, BEC is responsible for more financial losses to US businesses than any other category of cyber crime. According to FBI data, BEC causes over $2.7 billion in annual losses to American businesses, outpacing ransomware by a substantial margin. The attacks are sophisticated, targeted, and frequently designed around knowledge of a specific company’s payment processes, personnel, and vendor relationships that attackers have gathered over weeks of reconnaissance.

The coverage problem that makes BEC uniquely dangerous from a risk management perspective is that it frequently falls into a gap between two types of insurance that businesses commonly carry: cyber insurance and commercial crime insurance. Because BEC involves neither a traditional cybersecurity attack nor a traditional forgery or theft, claims arising from BEC losses regularly fall into territory that neither policy clearly covers. Understanding this gap — and how to close it before a loss occurs — is essential for any business that wires money, makes electronic payments, or operates in an environment where vendor or executive communications are trusted as a basis for financial transfers.

How Business Email Compromise Works

BEC attacks take several well-documented forms, each designed to exploit a different vulnerability in how businesses process payments and communicate. Understanding the attack patterns makes it easier to understand both why the attacks succeed and why the insurance coverage questions are so difficult.

In CEO fraud, the most common BEC variant, an attacker either compromises the email account of a senior executive or creates a domain name nearly identical to the company’s domain and sends email from it. The fraudulent email instructs an accounts payable employee or a financial officer to make an urgent wire transfer, typically referencing a confidential deal, an acquisition, a tax obligation, or another business purpose that explains why the transfer must happen quickly and why normal approval processes should be bypassed. The urgency is manufactured — it exists to prevent the employee from taking the time to verify the request through normal channels.

In vendor impersonation fraud, the attacker monitors ongoing email communications between the target company and one of its vendors — often through a compromised email account on either side. At a strategically chosen moment, typically when a legitimate payment is expected, the attacker inserts fraudulent wire transfer instructions. The victim company believes it is paying its vendor; the money goes to the attacker’s account. By the time the legitimate vendor follows up about the missing payment, the funds have been transferred multiple times and are effectively gone. In real estate and legal matter impersonation, attackers target the high-value wire transfers involved in real estate closings and business acquisitions by impersonating the attorneys or title companies involved and substituting fraudulent wire instructions at the moment of closing.

The Coverage Gap — Why Your Cyber Policy May Not Cover BEC

The central coverage problem with BEC is definitional. Cyber insurance policies are designed to cover events triggered by unauthorized access to computer systems, security breaches, or malicious code. The coverage language typically refers to a “computer attack,” “security failure,” “unauthorized access or use,” or similar trigger. In a classic BEC attack, none of these things occurred. The attacker did not break into your systems. Your employee voluntarily sent the money based on an email they believed was legitimate. The insurer’s position is often straightforward: there was no covered triggering event.

Some cyber policies have evolved to address this problem by including “social engineering fraud” as a separate and explicitly defined coverage grant. This grant specifically covers losses caused by an employee being deceived into transferring funds through a fraudulent communication. If your cyber policy includes social engineering fraud coverage, a BEC loss may be covered under it. But this coverage is not universal — many cyber policies do not include it, some offer it only as an optional endorsement, and many that do include it cap it at a sublimit far below the policy’s overall limit. A cyber policy with a two-million-dollar aggregate limit might offer social engineering coverage of only $100,000 to $250,000.

If your cyber policy does not specifically include social engineering fraud coverage, and if the BEC attack did not involve any unauthorized access to your systems, the cyber insurer’s likely position is that the loss is simply not covered under the policy. Business owners who assume that anything cyber-related is covered by their cyber policy may be unpleasantly surprised by this outcome.

The Coverage Gap — Why Your Crime Policy May Not Cover BEC Either

Commercial crime insurance policies are designed to cover losses caused by employee dishonesty, forgery, robbery, and — relevant here — computer fraud. The “computer fraud” insuring agreement in a typical crime policy covers losses caused directly by the use of a computer to fraudulently cause a transfer of money. This sounds like it should cover BEC. The problem lies in how courts have interpreted the requirement that the loss be caused “directly” by computer fraud.

Courts applying a strict causation analysis have held that in a BEC event, the direct cause of the loss was the employee’s voluntary decision to authorize the wire transfer based on a fraudulent email, not the computer system being used to perpetrate the fraud. The computer — specifically, the email system — was merely the medium through which the deception was communicated. On this reasoning, the loss was caused by human error induced by fraud, not by a computer being used to directly cause a transfer. The crime policy’s computer fraud insuring agreement, as interpreted by these courts, does not respond.

The result is the coverage gap: the cyber policy does not cover BEC because there was no unauthorized system access; the crime policy does not cover BEC because the direct cause of the loss was human action, not computer fraud. The business that wired $400,000 to a fraudster based on a fake email from what appeared to be its CEO finds itself holding a loss that neither of its insurers will pay.

How Courts Have Ruled on BEC Coverage Disputes

The coverage disputes arising from BEC losses have generated substantial and inconsistent litigation across federal circuits and state courts. The outcomes depend heavily on the specific policy language at issue and the court’s approach to causation analysis, which means that the same fact pattern can produce opposite results depending on jurisdiction.

In Medidata Solutions v. Federal Insurance Company, decided by the Second Circuit Court of Appeals in 2018, the court held that losses from a BEC attack were covered under the crime policy’s computer fraud insuring agreement. The attackers had spoofed email addresses from within the company’s own email system by manipulating email headers — in the court’s analysis, the fraudulent emails were “injected” into the company’s computer network, making the computer system itself the instrument of the fraud. This was sufficient to bring the loss within the policy’s computer fraud coverage.

In Apache Corporation v. Great American Insurance Company, decided by the Fifth Circuit Court of Appeals in 2016, the court reached the opposite conclusion on similar facts. An employee received a fraudulent email purportedly from a vendor asking for updated wire transfer instructions, and the company updated its records and paid the fraudulent account. The Fifth Circuit held that the computer fraud insuring agreement was not triggered because the loss was caused by the employee’s voluntary action in response to a fraudulent email — not directly by the use of a computer to cause the transfer. The causal chain was broken by the employee’s intervening decision.

These two decisions illustrate the fundamental ambiguity in crime policy language as applied to BEC and explain why dozens of similar cases continue to be litigated at the state and federal level. The takeaway for business owners is that you cannot assume you are covered based on a general understanding of what your policies cover. The analysis requires careful reading of the specific policy language by an attorney familiar with how courts in your jurisdiction have interpreted it.

How to Close the BEC Coverage Gap

The coverage gap described above is not inevitable — it can be addressed through careful policy construction before a loss occurs. The most effective solutions require working with your broker and attorney to review and modify your existing policies or add specific endorsements that clearly address BEC.

The cleanest solution is a social engineering fraud endorsement, available from many insurers on either the cyber or the crime policy. This endorsement explicitly defines “social engineering fraud” to include BEC attacks — scenarios where an employee is deceived by a fraudulent communication into authorizing a fund transfer — and provides coverage up to a specified limit. If your policies do not currently include this endorsement, ask your broker to obtain it. Be aware that this coverage often comes with a sublimit, and you should negotiate that sublimit to reflect your actual exposure.

A funds transfer fraud endorsement, available on some crime policies, specifically covers losses arising from fraudulent instructions to transfer funds, which directly addresses the BEC scenario. This may be preferable to or combined with social engineering coverage depending on your policy structure. If your existing crime policy already contains computer fraud language that is broad enough to cover BEC under your jurisdiction’s case law, your attorney may be able to obtain written confirmation from the insurer — via endorsement or other formal acknowledgment — that BEC losses are covered. Finally, verify the sublimits that apply to any social engineering or BEC coverage you obtain and ensure they are adequate given the size of transfers your business regularly makes.

Internal Controls That Reduce Risk and Preserve Coverage

Many insurers that offer social engineering fraud coverage require documented internal controls as a condition of that coverage. These requirements reflect the reality that BEC attacks succeed because of process failures, not purely technological ones. Businesses that implement robust controls are both less likely to suffer a BEC loss and better positioned if a claim dispute arises.

Callback verification is the single most effective BEC control: a written policy requiring any employee who receives a request to make or change a wire transfer — regardless of who appears to be making the request — to independently verify that request by calling the requestor at a known phone number from internal records, not from any phone number provided in the suspicious communication. This one control defeats the vast majority of BEC attacks because it requires out-of-band verification that the attacker cannot intercept. Dual approval policies that require two employees or two levels of management approval before any wire transfer above a threshold amount can be released add a second layer of defense.

Executive impersonation training teaches employees to recognize the hallmarks of CEO fraud emails: urgency, secrecy, requests to bypass normal approval processes, and instructions not to discuss the transfer with others. Email security controls — specifically DMARC, DKIM, and SPF records that authenticate outbound email and prevent spoofing of your domain — make it harder for attackers to impersonate your executives in emails to your vendors and partners. Implementing these controls serves a dual purpose: they reduce the risk of a successful attack, and they demonstrate the kind of reasonable security posture that supports a stronger insurance claim and may satisfy underwriter requirements for social engineering coverage.