Funds Transfer Fraud
Also known as: Computer and Funds Transfer Fraud, Fraudulent Funds Transfer Coverage, Wire Transfer Fraud Coverage
Funds transfer fraud coverage responds when a criminal fraudulently instructs the insured's bank — impersonating the insured through forged, altered, or fraudulent instructions — to transfer money from the insured's account without its knowledge or consent. It is found in both crime policies and the crime module of cyber liability forms. The defining feature is that the bank is deceived directly: the fraudster sends what appears to be a legitimate transfer request, and the funds leave the account before anyone at the insured authorizes it.
For a small-business buyer, this coverage matters because business bank accounts do not carry the consumer protections individuals enjoy, so a successful fraudulent wire can permanently drain operating cash. As criminals increasingly compromise email and vendor communications, funds transfer fraud has become one of the most common and costly cyber-crime losses businesses face. The coverage restores the stolen funds up to its limit, letting a company survive an event that could otherwise be existential. Buyers should note how it differs from — and often pairs with — social engineering fraud, which covers losses where an employee is tricked into authorizing the transfer voluntarily.
A practical nuance: the two coverages hinge on who is deceived. Funds transfer fraud applies when the financial institution is fooled by fraudulent instructions purporting to come from the insured; social engineering fraud applies when the insured's own employee is manipulated into sending money to a fraudster's account. Because carriers frequently give social engineering a much lower sublimit, a claim can be denied under one agreement and only partly paid under the other. Buyers should confirm both are present, review the required callback-verification and controls conditions, and check whether third-party crime or client-funds exposures are addressed.
Real-world scenario
Meridian Cabinetworks, a 40-employee custom millwork shop in Grand Rapids, added a funds transfer fraud insuring agreement to its commercial crime insurance policy at renewal. The full crime policy ran $4,850 in annual premium, of which roughly $1,150 was attributable to the funds transfer fraud and social engineering fraud agreements. The company bought a $250,000 limit on funds transfer fraud with a $5,000 deductible, while the broader employee-theft agreement carried a $500,000 limit.
Eleven months later, a hacker compromised the controller's email and, posing as the bank, initiated two fraudulent wire transfers of $92,000 and $61,500 directly out of the operating account. The bank recovered $18,000 before the wires cleared, leaving a net theft of $135,500. Meridian spent $9,400 on a forensic accountant to trace the transactions and $6,200 in legal fees confirming the loss fell within the funds transfer fraud agreement rather than the excluded voluntary-parting scenario.
After the $5,000 deductible, the insurer paid $130,500 toward the stolen funds, but the $9,400 forensic cost exceeded the policy's $5,000 claims-expense sublimit, so Meridian absorbed $4,400 of that out of pocket. Total insured recovery came to about $135,500 against annual premium of $4,850 — a stark reminder that a single unverified wire can erase a year of margin on a $12 million revenue base.
How it affects your premium
Funds transfer fraud pricing is driven less by industry class and more by how a business moves money and controls its banking. Underwriters weigh:
- Wire and ACH volume: Companies that send frequent, high-dollar electronic transfers present a larger loss surface and pay more for the same limit.
- Dual-authorization controls: Requiring two people to approve any wire above a threshold is the single biggest premium lever — many insurers won't quote meaningful limits without it.
- Chosen limit and deductible: Moving from a $100,000 to a $500,000 limit raises premium, while accepting a higher deductible lowers it.
- Overlap with other agreements: Whether the coverage sits inside a crime insurance policy alongside money and securities coverage or is bundled with cyber liability affects both rate and how limits stack.
- Callback verification procedures: Documented out-of-band phone verification of payment-change requests earns credits.
- Prior loss history: A past wire-fraud or social engineering fraud claim sharply increases rate or triggers a sublimit.
- Employee training and phishing testing: Regular anti-phishing simulations signal lower frequency risk and support better terms.
Common misconceptions
Myth: My cyber liability policy already covers stolen wire transfers.
Reality: Many cyber liability policies exclude or heavily sublimit direct financial theft, treating it as a crime exposure instead. Funds transfer fraud and social engineering fraud agreements are often the only places the actual stolen dollars are covered.
Myth: Funds transfer fraud and social engineering fraud are the same coverage.
Reality: Funds transfer fraud covers a fraudulent instruction the business never authorized (a hacker impersonating the bank), while social engineering fraud covers a transfer an employee was tricked into sending voluntarily. Insurers frequently give them separate limits and deductibles.
Myth: The bank will always make me whole if I get defrauded.
Reality: When your own credentials or employees authorize or enable the transfer, banks typically bear no liability, leaving the loss entirely on the business unless a crime insurance policy responds.
Frequently asked questions
What exactly does funds transfer fraud coverage pay for?
How is it different from social engineering fraud coverage?
Where do I buy funds transfer fraud coverage?
What limit should a small business carry?
Will controls like dual authorization lower my premium?
Sources cited
Need funds transfer fraud coverage?
Compare quotes from 10+ commercial insurance carriers in 5 minutes. Free, no contact info required.
Get My Quotes →