Your Sub Got Hacked. Now You’re Out $45,000.
I spent the early part of my career in construction supply before I got into insurance, so this one hit close to home. It keeps landing in my inbox, and it’s one of the more frustrating fights that we see contractors get dragged into.
Nobody broke into your trailer. None of your guys clicked anything. Your sub’s email was taken over, and somehow, you’re the one holding an empty bank account while a subcontractor still expects to get paid.
Let me walk you through a real one. I changed the details, but the bones are exactly what happened, because it shows why these claims get shot down on both ends and what it takes to dig out.
How It Went Down
A GC (we’ll call them the Buyer) had a countertop sub they’d worked with for years. Nothing fancy. Invoices came in on the jobs, payments went out, everybody was happy.
Sometime over the winter, the sub’s email got compromised. The attacker didn’t do anything right away. They just sat inside the account and read. They learned how these two companies talked to each other, what the invoices looked like, who signed off on what. Then, when a real payment was coming due, they sent over new banking instructions that looked exactly like every other email from that contact.
And here’s the part that stings. The Buyer did try to verify. They weren’t careless.
They called the sub’s office.
They called the bank to check the account.
Both calls came back fine. So why did it still blow up?
Because the crook only controlled the email, and the questions the Buyer asked didn’t touch what actually mattered. When they called the sub, they basically asked, “Hey, we’ve got this invoice for such-and-such amount, good to pay?” And the sub said yes, because the work was real and the number was right. Nobody ever asked the one question that would have caught it: “Is the account number still the same one we’ve always used?”
And the bank call? All the bank confirmed was that the account existed and was open. They’re not going to tell you whether it actually belongs to your sub. That’s not their job.
So, both calls gave honest answers, just not to the questions that would have stopped it. The whole scam lived in the email thread.
Over about two months, roughly $45,000 walked out the door to an account that had nothing to do with the sub.
This is the exact kind of loss that standard property policies and a lot of basic cyber policies just miss. The coverages that respond to it go by names like misdirected funds, invoice manipulation, or reverse social engineering (some carriers call it vendor fraud). Those are built for the situation where you send money in good faith based on fake instructions coming out of somebody else’s hacked inbox.
One rule that would have saved this whole mess: never change banking info off an email, period. Pick up the phone, call a number you already had on file before any of this started, and confirm the actual account number out loud before a dollar moves.
Both Sides Filed. Both Got Denied.
The Buyer was sitting on a commercial property and inland marine form. That kind of policy covers physical damage to physical stuff, your equipment, your materials, the things you can drop or dent. Money is almost always carved right out unless somebody added specific crime or funds transfer fraud coverage, and nobody had. On top of that, there was a cyber exclusion that wiped out anything tied to a hacking event. Denied.
The sub hit a different wall. Their problem was really an accounts receivable one. Money they were owed got rerouted. That’s not the classic “our network got breached” cyber claim, and plenty of policies won’t touch a receivables shortfall caused by somebody else’s fraud. Denied too.
Same event. Two denials. The money vanished because of a hack, but neither policy was ever built to catch this exact play.
Why This Keeps Hitting Contractors
Construction runs on a payment chain. Owner pays GC, GC pays subs, subs pay suppliers, and there’s a draw schedule and progress billing threading through all of it. Every one of those handoffs is an email with dollar figures attached, which is exactly what these guys are fishing for. You’re a bigger target than most industries just because of how the money moves.
Most contractors think about insurance in buckets. “I’ve got my GL.” “I’ve got property and my equipment floater.” “I’ve got a cyber policy.” As if any one of them stretches over everything. It doesn’t.
Property and inland marine cover physical things. Money is carved out.
Crime policies usually kick in when your own people or systems get played. They get murky fast when the hack happened on your sub’s side, and you just followed instructions that looked legit.
Cyber policies often include social engineering or funds transfer coverage, but the sub-limit on it can be small, and some forms still want the breach to have hit your own systems.
In this case, the party who got hacked wasn’t the party who lost the money. And the party who lost the money never had a breach on their own systems at all. That gap in the middle is exactly where both policies came up empty.
This isn’t some freak occurrence, either. According to the FBI’s 2025 report, business email compromise caused $3.05 billion in losses from under 25,000 complaints, which works out to about $123,000 a hit. Total cybercrime losses cleared $20.9 billion that year. And on the insurance side, Coalition’s most recent Cyber Claims Report, covering full-year 2025 claims, put business email compromise as the most common type of cyber claim at 31%, with funds transfer fraud right behind at 27%. More than half of those funds transfer losses started with a compromised inbox.
And AI is pouring gas on it. That same FBI report tied more than $30 million in BEC losses to attacks with a confirmed AI component. The fake emails read cleaner now, the tone matches, the details line up. Harder than ever to eyeball the difference.
So Whose Fault Is It?
This is the question both companies threw at their brokers and their lawyers, and there’s no clean answer. But there is a legal framework courts lean on, and you should understand it before you assume the other side is just going to eat this.
It’s sometimes called the imposter rule, and it traces back to Article 3 of the Uniform Commercial Code, the body of law that governs how payments and negotiable instruments work in every state. The gist: when a fraudster impersonates somebody to trick a business into paying, the loss tends to land on whichever party was in the best position to stop it, not just whoever happened to catch the wire.
When it lands in front of a judge, they’re weighing things like:
Whose email or systems got compromised
Whether the party paying took reasonable steps to verify before sending
Whether the party that got hacked had basic protections in place, like multi-factor authentication on their email
Whether anybody blew past obvious red flags, like a sudden change in banking info or a weirdly urgent tone
Here’s the twist that catches a lot of owners off guard. The framework often points right back at the party whose email got hacked, even though they’re the one who never saw a dime of the fraudulent payment. The reasoning is that they left the door open. If your email account gets hijacked and that’s what let the crook send fake wiring instructions in the first place, a court can decide you were the one best positioned to prevent the whole thing, because it was your account and your security that failed.
But it swings the other way too. If the party paying ignored clear warning signs, fired money off to a brand new account with no real verification, or skipped a basic callback, a court can push the loss right back onto them no matter whose system got breached. Both sides are expected to use their heads.
None of this is black and white. It’s fact by fact, and outcomes swing depending on the state and the judge you draw. Which is exactly why most of these things get settled instead of fought all the way to a verdict. Both companies usually have enough exposure and enough uncertainty that splitting the difference beats rolling the dice in a courtroom.
What To Do If You’re In It
Check every policy, not just the cyber one. A crime form and a cyber form on the same account can respond in completely different ways to the same event. Somebody should read all of them before you accept a denial as final.
Push back on the denial in writing. Carriers deny fast. Sometimes they reconsider once you hand them a clean timeline and the forensic details.
If the number’s big enough, get a coverage attorney involved. These fights often turn on how the policy defines something like “direct loss” or “computer system.” That’s not a DIY read.
Sort out who should carry the loss between the two of you. Use the UCC imposter rule as your starting point: whoever was best positioned to prevent it is usually on the hook, which often means the party whose email got hacked. But it depends on the facts and where you are, so treat it as a way to frame the conversation, not a guaranteed outcome.
Expect to settle it between the companies. A lot of these land on a 50/50 split, or a repayment plan folded into future invoices. Both sides usually want to protect a relationship that’s been good for years.
What you need to know
This isn’t some exotic, one-in-a-million scam. Vendor payment fraud is one of the most common cyber losses out there, and the 2025 numbers say it’s still climbing. Construction is right in the crosshairs because of how much money moves by email across the GC, the subs, and the suppliers.
And the thing that gets me about this case is that everybody did a lot of things right. The Buyer picked up the phone to verify. The sub eventually caught the breach. Both of them filed claims. And they still fell straight into a coverage gap, because their policies were never written for a loss that starts on somebody else’s system and ends with money leaving yours.
If you’re cutting checks to subs and suppliers all day, have a real conversation with your broker. Don’t just ask whether you’ve got a cyber policy. Ask this:
“If one of my subs gets hacked and I send money to a fraudster off their instructions, does anything in my program actually pay?”
For a lot of contractors right now, the honest answer is no. And AI is only making the fake emails harder to spot.
That’s the conversation worth having before the next invoice shows up.
Want a copy of our fraudulent transfer prevention guide and checklist? Email joe@c3insurance.com and we’ll send it over.


