A fraudulent wire transfer can drain a business account in minutes. Getting that money back can take months, if it happens at all. Business email compromise, or BEC, is one of the costliest categories of cybercrime reported to the FBI’s Internet Crime Complaint Center each year. Losses run into the billions of dollars annually across U.S. businesses. That scale hasn’t made recovery easier. It has made the process more familiar, with clearer steps and more precedent than there used to be.
Recovering funds after a business email compromise almost always comes down to speed, documentation, and knowing which party is actually on the hook. This guide walks through what to do in the first hours after discovery, how liability gets assigned between banks, businesses, and vendors, and how to push a cyber insurance claim, or a lawsuit, across the finish line.
What Is Business Email Compromise and Why Reimbursement Is So Hard to Get
Business email compromise is a scam where criminals impersonate a trusted contact, a vendor, an executive, or a bank, to trick an employee into sending money to a fraudulent account. Unlike a straightforward hack, BEC doesn’t rely on breaking through firewalls. It relies on breaking trust.
That distinction matters for reimbursement. When someone hacks a system, liability often points at whoever failed to secure it. When someone fools an employee into authorizing a payment, the lines blur. Banks argue the business approved the transfer. Businesses argue the bank should have flagged it. Insurers argue someone should have verified the request first.
How BEC Scams Typically Unfold
Most BEC losses follow a similar script. A small manufacturing company wires a routine supplier payment after receiving what looks like an updated invoice from a longtime vendor. Days later, the real vendor calls asking why payment hasn’t arrived. By then, the funds have already moved through a fraudulent account overseas, often bounced through several accounts within hours.
The email that triggered the transfer usually looks legitimate. It might come from a spoofed domain that’s a single letter off, or from a genuinely compromised vendor inbox. Either way, the request feels routine enough that no one questions it.
Why Banks and Insurers Often Resist Paying Out
Banks process wire instructions that come with valid account credentials and an authorized sign-off. From their perspective, they did what the customer asked. Insurers write policies with specific conditions around verification and employee training. They scrutinize claims for any gap in those procedures.
None of this means recovery is hopeless. It means the business asserting a claim needs to move fast and build a paper trail that closes the gaps banks and insurers look for.
Immediate Steps to Take After a BEC Fraud Loss
The first 24 to 72 hours after discovering a fraudulent transfer matter most in the entire recovery process. Every hour that passes makes it more likely the funds have moved beyond reach.
- Stop further transfers immediately. Freeze any related accounts and halt pending payments tied to the same vendor or contact.
- Call your bank’s fraud department, not your regular branch line. Ask specifically for a wire recall.
- File a complaint with the FBI’s IC3. Do this the same day if at all possible.
- Preserve every email, header, and attachment tied to the fraudulent request. Don’t delete or forward in ways that alter metadata.
- Notify your cyber insurance carrier, even before you know the full loss amount.
- Alert any vendor or partner whose identity was impersonated, since they may be experiencing the same scam with other customers.
Contacting Your Bank and Requesting a Wire Recall
Call the bank the moment you suspect fraud. Ask for a wire recall or, for domestic transfers, a same-day ACH reversal request. Banks can sometimes freeze or claw back funds if the receiving bank hasn’t yet released them. That window closes fast, often within hours.
Ask the bank to also notify the FBI’s Financial Fraud Kill Chain, or FFKC. This process lets law enforcement request an international wire recall shortly after someone sends a fraudulent transfer. It has helped recover funds even after they’ve crossed borders, but only when reported quickly enough.
Reporting to the FBI IC3 and Local Law Enforcement
File a complaint at IC3.gov as soon as you confirm the loss. Include the wire amount, the receiving bank’s routing and account numbers, and copies of the fraudulent emails. IC3 doesn’t guarantee recovery, but a fast complaint feeds directly into the FFKC process banks and the FBI use to attempt recalls.
File a police report with local law enforcement too. Some banks and most insurers require one before they’ll process a reimbursement or claim.
Who Is Responsible for BEC Reimbursement
Liability for BEC losses depends on the type of account, the bank’s security procedures, and whether the business followed its own internal controls. There’s no single rule that applies to every case, but the legal framework does draw some clear lines.
Bank Liability Under UCC Article 4A and Regulation E
Article 4A of the Uniform Commercial Code generally governs business accounts, not Regulation E, which mainly protects consumer accounts. Under Article 4A, a bank isn’t automatically liable for a fraudulent wire if it followed a “commercially reasonable” security procedure, such as requiring a callback verification or dual authorization, and the business had agreed to that procedure.
That said, if the bank failed to follow its own agreed-upon security procedure, or if it ignored red flags that a reasonable institution would have caught, the bank can be held liable for the loss. This is where a detailed review of the bank’s own wire agreement and internal logs becomes critical.
When the Vendor or Employer Bears the Loss
If a vendor’s email account was compromised and that’s how the fraudulent invoice reached the business, responsibility can shift toward the vendor, especially if the vendor had lax security. Some vendor contracts include indemnification language addressing exactly this scenario.
More often, though, the loss lands on the business that authorized the transfer, particularly if it skipped internal payment verification steps. This is why documenting your company’s actual payment procedures, and whether the employee followed them, matters just as much as the bank’s conduct.
Filing a Business Email Compromise Reimbursement Claim With Cyber Insurance
Cyber insurance is often the most realistic path to recovering BEC losses, but only if the policy includes the right coverage and you file the claim correctly.
What Cyber Insurance Policies Typically Cover
Standard cyber policies frequently exclude social engineering fraud unless the business added a specific endorsement, sometimes called “funds transfer fraud” or “social engineering” coverage. Where that endorsement exists, it typically reimburses funds lost to a fraudulent instruction, subject to a sublimit that’s often far lower than the policy’s main cyber liability limit.
Before filing, pull your policy and confirm whether this endorsement is present, what the sublimit is, and what conditions apply. Insurers frequently require proof that the business followed a verification protocol before releasing funds. Even a basic callback to a known phone number can matter here.
Common Reasons BEC Claims Get Denied
Insurers deny BEC claims for a handful of recurring reasons: no social engineering endorsement on the policy, missing or inconsistent documentation, failure to report the loss within the policy’s notice deadline, or evidence that the business skipped its own stated verification procedures. Some carriers also argue the loss falls under a “voluntary parting” exclusion, claiming the business willingly sent the funds rather than having them stolen through a hack.
Understanding how insurers investigate a claim helps explain why documentation gaps get seized on so quickly. Adjusters are trained to look for any reason the loss might fall outside the policy’s exact wording.
How to Strengthen Your Case for Recovery
The strength of a BEC reimbursement claim usually comes down to paperwork. Banks and insurers reward businesses that can show exactly what happened, when, and what steps they took to prevent and then respond to the fraud.
Documentation Checklist for a BEC Claim
Gather the following as early as possible:
- The fraudulent email in full, including headers showing the originating domain and IP address
- Any prior legitimate correspondence with the impersonated vendor or executive, for comparison
- Wire transfer confirmations, including timestamps and receiving account details
- Internal payment approval records showing who authorized the transfer and when
- Your company’s written payment verification policy, if one exists
- The IC3 complaint confirmation number
- The police report number
- All correspondence with your bank’s fraud department, including recall request confirmations
- Your cyber insurance policy, including any social engineering or funds transfer fraud endorsement
Keep this file organized from day one. Insurers and banks will ask for pieces of it repeatedly. A business that can produce it instantly looks far more credible than one scrambling to reconstruct events weeks later.
When to Escalate With a Lawsuit or Regulatory Complaint
If a bank refuses a reasonable recall request, or an insurer denies a claim that should clearly fall within the policy’s social engineering endorsement, escalation is often warranted. Filing a complaint with your state’s banking regulator or insurance commissioner can prompt a faster review than waiting on the carrier’s internal appeals process.
When the dispute centers on whether coverage applies at all, filing a declaratory judgment action can force a court to resolve the coverage question directly. If the insurer is simply sitting on a valid claim without a good reason, suing an insurer for unreasonable claim delays is another route worth discussing with a business litigation attorney. And if you’re trying to figure out what a reasonable payout should even look like, understanding how commercial claims payouts are calculated can help you judge whether an offer is fair before you accept it.
Preventing Future Business Email Compromise Losses
Every BEC claim also becomes a lesson insurers and banks will expect you to have learned. A business that gets scammed twice by the same type of email has a much harder time getting reimbursed the second time.
Best Practices for Verifying Payment Requests
Require a callback to a known, previously verified phone number for any payment change request, never a number listed in the email itself. Put dual authorization in place for wires over a set dollar threshold. Train staff to slow down on urgency-driven requests, since BEC scams almost always create artificial time pressure.
Review your cyber insurance policy every year and confirm the social engineering endorsement keeps pace with how much money moves through your accounts. As you build out this coverage, it’s worth comparing it against your broader business insurance strategy, including small business liability insurance costs, since many carriers offer bundled discounts when cyber and liability coverage sit on the same policy.
If you’ve already been hit by a BEC scam, don’t wait to see whether the money reappears on its own. Document everything now. Push your bank for a wire recall. File your IC3 complaint today, and open a cyber insurance claim even if you’re still gathering details. And once a reimbursement or settlement does arrive, know the basics of verifying and cashing a fraud settlement check so the final step in your recovery goes as smoothly as the ones that got you there.