Business Email Compromise Insurance in Florida: Why the Wire-Fraud Loss Lands Between Your Cyber and Crime Policies (2026)

By Ricardo Alonso, Founder, Atesa Risk Advisors · August 13, 2026

Key Takeaways

  • Coalition's 2026 Cyber Claims Report, released March 5, 2026, found business email compromise (BEC) and funds transfer fraud (FTF) drove 58% of all cyber claims in 2025 — more than ransomware and every other incident type combined [1].
  • The FBI's 2025 Internet Crime Report (April 2026) put reported BEC losses at $3.04 billion, with Florida perennially among the top states for complaints and dollar losses [2] [3].
  • A theft by faked email or spoofed invoice can land under a cyber policy, a crime policy, a social engineering endorsement — or none of them. Which one responds depends on how the money left, not how much.
  • The most common coverage failure is the sublimit: a business carrying $1 million in cyber coverage discovers its social engineering or FTF coverage is capped far lower — commonly $100,000 to $250,000.
  • Carriers in 2026 condition wire-fraud coverage on callback verification: if your team didn't confirm payment instructions by phone at a known number, some forms reduce or deny the claim.
  • Recovery is a race measured in hours — a same-day bank recall request, FBI IC3 report, and carrier notice is the difference between clawing a wire back and writing it off.
  • If personal information sat in the compromised mailbox, the Florida Information Protection Act (§ 501.171, F.S.) adds a 30-day notification clock on top of the theft.

If someone tricks your Florida business into wiring money — a spoofed vendor invoice, a fake "updated bank details" email — the loss is covered only if the right policy, endorsement, and limit were in place before it happened. General liability and property policies pay nothing for stolen funds. A cyber policy covers funds transfer fraud only if that coverage part was purchased; a commercial crime policy covers it only with a social engineering endorsement. Both are routinely sublimited far below the headline number, and both can require verification procedures your team must actually follow. This guide maps who pays, for what, and what underwriters demand in 2026.

The Numbers Behind the 2026 Wire-Fraud Problem

Ransomware gets the headlines. The claims data says your money is more likely to leave through your own email.

Coalition — one of the largest cyber managing general agents in the U.S., with more than 100,000 policyholders — released its 2026 Cyber Claims Report on March 5, 2026. Business email compromise and funds transfer fraud together drove 58% of all cyber incidents Coalition handled in 2025. FTF alone was the second-most-common claim type at 27%, and 52% of those claims started with a compromised or spoofed email account [1].

The FBI's numbers point the same direction: the 2025 Internet Crime Report, released in April 2026, put reported BEC losses at $3.04 billion — second only to investment fraud among loss categories [2] [3]. Florida has for years ranked near the top of the state tables for both complaints and losses [3], and an economy built on real estate closings, tourism deposits, construction draws, and healthcare billing generates exactly the payment traffic these schemes feed on.

Two definitions, because the coverage analysis turns on them. Business email compromise is unauthorized access to, or convincing impersonation of, a business email account — a criminal reading your controller's inbox for weeks, or mailing from a lookalike domain one letter off from your vendor's. Funds transfer fraud is the money actually moving: a wire or ACH payment your bank executes on instructions that turn out to be fraudulent. BEC is the burglar in the house; FTF is the valuables leaving — and policies treat them as different events.

Which Policy Pays When the Money Is Gone

There is no single "wire fraud insurance." The loss lands in one of four places.

Your cyber policy — if it includes funds transfer fraud coverage

Modern cyber forms from the specialty markets (Coalition, At-Bay, Beazley, Chubb Cyber, Corvus and others) offer FTF as a coverage part. It reimburses funds your business is tricked into transferring, and often funds a third party is tricked into transferring on your behalf — your customer wiring their deposit to a criminal who spoofed your email, then looking to you to make it good. The catch: FTF is an optional insuring agreement on many forms. Businesses that bought cyber coverage for ransomware sometimes declined it, or accepted a token limit, without registering what they gave up.

Your commercial crime policy — with the right endorsement

A commercial crime policy covers employee theft, forgery, and computer fraud — but computer fraud coverage was written for a hacker moving money directly. When an employee willingly sends the wire because a fraudster deceived them, carriers have argued the loss was "voluntary parting" with funds, not computer fraud. Federal appeals courts split on those disputes for years, which is exactly why the industry created a dedicated social engineering fraud endorsement. If your crime policy doesn't carry it, assume a deception-induced wire is contested at best.

Both policies — creating an order-of-payment question

If you carry both a cyber policy with FTF coverage and a crime policy with a social engineering endorsement, the two need coordinating: which is primary, which sublimit applies, and whether each policy's "other insurance" clause pushes the loss to the other form. This is placement work, not claims-day work.

Neither — the default for an unmanaged program

General liability covers bodily injury and property damage. Commercial property covers your building and contents. A Business Owner's Policy typically carries, at most, a small cyber endorsement that excludes or barely sublimits stolen funds. A business running on a BOP plus an unendorsed crime policy is, for practical purposes, self-insuring its wire-fraud exposure.

Where the loss lands: a quick reference

ScenarioPolicy that respondsWhat to check
An employee is tricked into wiring company fundsCyber FTF coverage part, or the crime policy's social engineering endorsementThe sublimit, and any callback-procedure condition
A hacker moves money directly, no employee involvedCrime policy computer fraud coverageWhether limits match your account balances
A criminal impersonating your company diverts a customer's paymentThird-party FTF coverage on the cyber formWhether the form includes it at all
Only a BOP and an unendorsed crime policy in placeNeither — the loss is effectively uninsuredAdd FTF coverage or the endorsement at renewal

The Sublimit Problem: Where Wire-Fraud Claims Actually Fail

The quiet failure mode in 2026 isn't a denied claim — it's a paid claim that covers a fraction of the loss.

Social engineering endorsements on crime policies are routinely capped at $100,000 or $250,000 regardless of the crime policy's full limit, and cyber FTF coverage parts carry similar caps on many small-business forms. Meanwhile, the wires leaving Florida businesses are not small: a construction draw, a real estate closing, or a quarter's inventory payment can each clear $500,000.

Three things a buyer — or their broker — should do about it:

  1. Read the declarations page for the sublimit, not the limit. The number that matters sits next to "social engineering," "fraudulent instruction," or "funds transfer fraud" — not the aggregate at the top.
  2. Size the sublimit to your largest routine payment. If you wire six-figure vendor payments monthly, a $100,000 cap is a decoration. Several specialty markets will offer full-limit FTF for well-controlled risks — but only if asked, and only with documentation.
  3. Ask about third-party FTF. If a criminal spoofs your domain and redirects your customer's money, the demand letter comes to you. Forms differ meaningfully on whether that's covered.

On the Florida accounts I review, the cyber limit got attention at the last renewal and the social engineering sublimit did not. A business wiring six figures a month against a $100,000 deception cap is the standard finding, not the exception.

— Ricardo Alonso, Founder, Atesa Risk Advisors

What Underwriters Require Before They'll Cover Wire Fraud in 2026

Wire-fraud coverage has followed the same path ransomware coverage took: from questionnaire checkbox to audited control set. On 2026 applications and renewals, Florida businesses should expect:

  • Callback verification, in writing. A documented procedure requiring voice verification of new or changed payment instructions at a phone number from your own records — never one supplied in the email requesting the change. Some forms make coverage contingent on the procedure being followed for the specific transfer, not merely existing in a binder.
  • Dual authorization. Two people approve any wire or ACH batch above a set dollar threshold.
  • Multi-factor authentication on email. MFA on all email accounts has been a baseline bind condition across major cyber carriers since well before 2026 — a compromised mailbox is the on-ramp for half of funds transfer fraud [1].
  • Email authentication records. SPF, DKIM, and DMARC — the DNS settings that make your domain hard to spoof. Carriers' scanning tools check your domain for them automatically.
  • Truthful attestations. Application answers about these controls function as warranties. A claim investigation that finds the attested callback procedure was never actually used is a rescission argument handed to the carrier. Never let an application overstate your controls; fix the control or disclose the gap.

The broker's role here is concrete: we see which carriers treat a missing control as a declination, which price around it, and which will bind with a 90-day remediation commitment — and we make sure what's attested matches what's true.

Four Florida Scenarios, and Where Each Lands

The title and escrow wire. Real estate is Florida's signature BEC hunting ground: closing dates and dollar amounts sit in multiple inboxes for weeks. A buyer wired to a fraudulent account after criminals spoofed the closing agent looks to the agent, the law firm, and sometimes the referring parties — for any business touching closings, third-party FTF coverage and a documented callback procedure carry the file. (Financing through an SBA loan? The same wire discipline applies at your closing — see our Florida SBA loan closing insurance guide.)

The contractor's vendor payment. A subcontractor's email is compromised; the GC receives "updated banking details" on a legitimate-looking invoice for a real project. The progress payment disappears — and the sub still expects payment. A first-party FTF claim if the coverage was bought; a five-minute callback would have prevented it. Contractors should treat crime/cyber as the fourth leg of the bundle — our Florida contractor insurance guide covers the other three.

The restaurant group's payroll diversion. An "employee" emails HR to update direct-deposit details before payday, and it runs a few cycles before anyone notices. Small individually, these losses aggregate — and they frequently fall under social engineering coverage on the crime form, not the cyber policy.

The medical practice's double exposure. A compromised office-manager mailbox is used to redirect a refund batch — and the same mailbox held patient information. Now there's a funds loss and a potential breach triggering FIPA's 30-day notification clock, with civil penalties that can reach $500,000 per breach under § 501.171, F.S. [4]. One incident, two coverage parts, two response tracks — which is why FTF coverage should live alongside real breach-response coverage; our Florida small-business cyber insurance guide covers that side in depth.

When the Wire Is Already Gone: The First 72 Hours

Recovery odds decay by the hour. Run this sequence the same day the loss is discovered.

  1. Call your bank immediately. Request a recall of the wire and a freeze on pending transfers, and ask the bank to contact the receiving institution's fraud department directly.
  2. File with the FBI at IC3.gov the same day. The FBI's Recovery Asset Team works with domestic banks to freeze funds before they're layered offshore — but it works when reporting is measured in hours, not days [3].
  3. Notice your carriers — both of them. Report to the cyber carrier and the crime carrier in parallel; let coverage counsel sort primacy later. Late notice is its own denial ground.
  4. Preserve the evidence. Original emails with full headers, invoice versions, bank confirmations. Forensics must establish how the instructions were altered — that fact pattern determines which insuring agreement responds.
  5. Check for data exposure. If a mailbox was compromised, assume the FIPA analysis is live and get breach counsel engaged within days, not weeks [4].

A broker who has run this sequence before coordinates it while you run your business.

Why This Is Broker Work

Wire-fraud coverage resists comparison shopping for three reasons. The forms genuinely differ — FTF insuring agreements, social engineering endorsements, and "fraudulent instruction" definitions vary carrier to carrier in ways that decide six-figure claims. The market is relationship-driven — full-limit FTF, third-party FTF, and control-based credits are negotiated, not listed. And the claim is adversarial enough that you want an advocate who packaged the risk honestly on the front end, so the application can't be turned against you on the back end. An AI quote engine can price a checkbox; it can't negotiate a sublimit against your actual payment sizes or sit on the phone with your bank's fraud desk at 4 p.m. on a Friday.

Frequently Asked Questions

Does cyber insurance cover wire transfer fraud? Only if the policy includes a funds transfer fraud insuring agreement — it's an optional coverage part on many forms. Check the declarations page for "funds transfer fraud" or "fraudulent instruction" and its specific sublimit; don't assume the headline cyber limit applies.

What's the difference between BEC coverage and funds transfer fraud coverage? BEC is the email compromise itself — the intrusion and response costs typically fall under a cyber policy's breach coverage. Funds transfer fraud covers money actually stolen through fraudulent payment instructions. Many incidents involve both, hitting different coverage parts with different limits.

Will my crime policy cover an employee tricked into wiring money? Usually only with a social engineering fraud endorsement. Base computer-fraud coverage was written for direct hacker theft, and carriers have contested "voluntary" transfers an employee was deceived into making. If the endorsement isn't on your policy, add it — and check its sublimit.

How much social engineering coverage can a Florida small business buy? Endorsement sublimits of $100,000–$250,000 are common, but several specialty markets offer higher or full-policy limits for businesses with documented callback and dual-authorization controls. Size the sublimit to your largest routine payment, not to the carrier's default.

What is callback verification and is it really required? Verifying any new or changed payment instructions by phone, using a number from your own records rather than one in the requesting email. Many 2026 forms either require the procedure as a condition of coverage or reduce the payout when it wasn't followed for the fraudulent transfer.

If my customer wires money to a criminal impersonating my company, am I liable? You may face the demand regardless of technical fault, and defense costs are real even when liability is arguable. Third-party funds transfer fraud coverage addresses exactly this — and forms differ on it more than almost any other provision.

Can stolen wire funds be recovered? Sometimes — if you move within hours. A same-day bank recall request plus an FBI IC3 report gives the Recovery Asset Team a chance to freeze funds at the receiving bank before they move again; after a few days, odds drop sharply.

Does a fraudulent wire trigger Florida's breach notification law? The wire itself doesn't — but the compromised mailbox behind it often does. If personal information of Florida residents was accessible in the account, FIPA's 30-day notice requirement can apply, with Attorney General enforcement and civil penalties for missed deadlines [4].

Related Reading

How Atesa Risk Advisors Can Help

We place cyber and crime programs for Florida businesses whose payments are worth stealing — contractors, medical and dental practices, title-adjacent businesses, restaurants, and growing companies that wire real money every month. The work starts with your payment flows, not a quote form: we map your largest routine transfers, match sublimits to them, document the controls underwriters credit, and make sure the application says exactly what's true. If the worst happens, we run the recovery sequence with you the same day. Request a review or call (904) 900-5063 — the sublimit conversation takes fifteen minutes, and it's usually the most valuable fifteen minutes in the file.

Sources

[1] Coalition 2026 Cyber Claims Report — Coalition, Inc. (released March 5, 2026) [2] FBI National Press Office — 2025 Internet Crime Report Release (April 2026) [3] FBI 2025 Internet Crime Report — IC3 Annual Report (PDF) [4] Section 501.171, Florida Statutes — Security of Confidential Personal Information (Online Sunshine)

Educational disclaimer: This article is general educational information about insurance and is not insurance advice, a quote, or an offer of coverage. Rates, discounts, deadlines, and requirements change and vary by property; confirm current figures with primary sources and a licensed agent before relying on them. Coverage is subject to the terms of your policy. For a personalized review, contact Atesa Risk Advisors, an independent, RamseyTrusted brokerage licensed in Florida (2-20 General Lines).

Ricardo Alonso is the Founder of Atesa Risk Advisors, a Florida independent insurance agency. Licensed 2-20 General Lines Agent and 2-15 Health & Life Agent, with a Master of Liberal Arts in Finance from Harvard University. He places cyber, crime, and commercial packages for Florida businesses from single-location practices to multi-entity operations.