Commercial Crime and Social Engineering Fraud Coverage in 2026
A wire leaves on a Tuesday afternoon. The instructions looked routine — a familiar vendor, a plausible request, an email that read like every other email. Days later the money is gone, the vendor says it never asked for a thing, and the question becomes uncomfortably specific: does the insurance respond? For a growing number of mid-market businesses, the honest answer is it depends on language most buyers never read.
The scale is no longer abstract. The FBI's Internet Crime Complaint Center logged more than $16.6 billion in reported losses in 2024, a 33% jump over the prior year, with business email compromise alone accounting for $2.77 billion. These are not fringe events. They are the predictable output of criminals who have learned that deceiving a person is more reliable than defeating a firewall.
Two crimes that look identical and insure differently
Traditional commercial crime and fidelity coverage was crafted for a different threat: the dishonest employee who steals from within. Its core insuring agreements — employee theft, computer fraud, funds transfer fraud — assume either an internal thief or a direct technical breach of the bank. Social engineering fits neither mold. When a fraudster impersonates a CEO or a supplier and a trusted employee voluntarily sends the money, the loss surfaces a hidden gap. The employee was deceived, not dishonest. The bank followed legitimate instructions. The computer merely delivered an email.
That gap has been litigated hard. Funds transfer fraud coverage generally contemplates a criminal submitting false instructions directly to your financial institution, while social engineering turns on an employee authorizing the transfer themselves. Insurers have denied claims on the theory that the insured voluntarily parted with the funds — and some courts have agreed. Others have not. In the closely watched Medidata Solutions dispute, the insured recovered $4.8 million after the Second Circuit affirmed in 2018 that a spoofed-email scheme triggered the policy's computer fraud provision. The lesson is not that policyholders always win; it is that outcomes hinge on precise wording and facts you cannot control after the fact.
The sublimit most buyers overlook
Even where carriers offer social engineering coverage, they typically do so by endorsement — and with a sublimit far below the policy's headline number. Common ranges run from $25,000 to $250,000, a fraction of the limit protecting against employee theft or direct funds transfer fraud. That matters because the losses are rarely small. Coalition's 2026 Cyber Claims Report found funds transfer fraud made up 27% of cyber claims with an average loss near $141,000, and business email compromise remained a leading trigger. A six-figure loss against a $50,000 sublimit is not coverage — it is a partial reimbursement dressed up as protection.
The form matters as much as the limit. A financial institution bond is built around a bank's exposures and definitions; a commercial crime form is written for operating companies, and the two treat social engineering and funds transfer fraud through different language and triggers. Reading them as interchangeable is how organizations discover, mid-claim, that their coverage was assumed rather than confirmed.
Where the money actually leaks
The tactics are increasingly patient. Invoice manipulation — where a criminal intercepts or impersonates a legitimate vendor and quietly alters the banking details on an otherwise genuine invoice — exploits the trust inside long-standing relationships. Deceptive funds transfer instructions arrive mid-thread, in the right tone, referencing real projects. This is why controls and coverage must be designed together. Many endorsements now condition payment on verification steps: callback confirmation to a known number, dual authorization above a threshold, out-of-band approval. Skip the step, and the carrier may decline the loss it appears to insure.
Structuring limits, then, is an exercise in ownership rather than guesswork. Align the social engineering sublimit with your realistic single-transaction exposure — not an arbitrary default. Confirm whether funds transfer fraud sits at full limit. Coordinate the crime form with your cyber policy so the two do not each point at the other. And document the verification controls the endorsement requires, because those controls are both your first line of defense and a condition of the promise.
This is precisely the work our 4-Step Strategic Process is built to illuminate. Strategic Discovery surfaces how money actually moves through your business. Risk Assessment measures the exposure against real loss data. Solution Design crafts the limits, sublimits, and coordinated forms with intention. Ongoing Optimization keeps them aligned as your vendors, volumes, and threats evolve — so the coverage you believe you have is the coverage you can prove.
The threat is not going away, and neither is the fine print. The businesses that fare best are the ones that treat this as a matter of discipline and control — reading the language before the wire goes out, not after.
Sources: FBI (IC3) — 2024 Internet Crime Report; CertifID — 2024 FBI IC3 Cybercrime Report Breakdown; Ward and Smith — Social Engineering Fraud and Your Crime Policy; Higginbotham — Funds Transfer Fraud vs. Social Engineering; Coalition — 2026 Cyber Claims Report; Hunton Andrews Kurth — Chubb Owes $4.8M for Medidata Loss; Hunton Andrews Kurth — 2nd Cir. Affirms Medidata Spoofing Loss Covered; WTW — Social Engineering and Fraudulent Funds Transfer
— Ryan Mefford, President & Risk Advisor