Your $25K Sublimit Won’t Save You
I had a conversation this week that I’ve had too many times.
A business owner called me after discovering they’d been the victim of a misdirected payment scam. Someone had impersonated a vendor, swapped out the bank account details on an invoice, and walked away with an $89K wire transfer. It happens fast. It looked completely legitimate, and the company even owed the other company that exact amount.
The good news: they had a cyber policy.
The bad news: their sublimit for misdirected payment fraud was $25,000. Their deductible was $10,000, so the most they are getting is $15K.
They had insurance. It just wasn’t built for the size of the problem.
The gap nobody talks about
Most bundled cyber endorsements are the kind added onto a Business Owners’ Policy (BOP) or package policy that include social engineering or misdirected payment coverage as an afterthought. Sublimits of $10K or $25K are common.
The average business email compromise loss is over $137,000…
A standalone cyber policy with purpose-built fraud coverage is a different product. Sublimits of $100K to $250K are available. Many carriers include cyber awareness training in the premium. The coverage form is designed for how these attacks work, not just broadly referenced in an endorsement.
What to do right now
Pull out your cyber policy or your BOP if that’s where your cyber coverage lives, and look for these specific line items:
- Misdirected payment fraud or social engineering sublimit
- Funds transfer fraud coverage
- Invoice manipulation or reverse social engineering
- If coverage requires verification/call back provision, and what happens if they aren’t followed
If you don’t know where to look or what you’re reading, that’s what I’m here for.
One procedural change that costs nothing
Any time you receive a request to change a vendor’s bank account information, call the vendor at a number you already have on file (not the one in the email). That one step stops the majority of these attacks and takes 90 seconds. Unfortunately, social engineers know this and will convince you to make an exception. If you have a call back provision in your policy, then that exception will void your coverage when you need it the most.
TLDR
Check your sublimits. If your misdirected payment fraud coverage is under $100K and you move significant money, you have a gap worth closing before you need to use it. Many companies I work with have a $250K sublimit, but regularly make $1million+ wire transfers. Part of our intake is discovering how much you need and giving you the coverage options customized to your business.
If you’d like more info on payment fraud, please comment below $$$ or send an email to joe@c3insurance.com and I’ll send you our Fraud Prevention Guide and Checklist to make sure you aren’t the next victim.


