The flooring supplier's invoice is expected. The materials were delivered. The amount is correct. Then an email in what appears to be the same conversation says the supplier has changed banks.
An accounts-payable employee updates the routing details and pays. Days later, the supplier asks why the balance remains open.
The bill was genuine; the destination was not. A criminal may have spoofed an address, entered a real email account, or watched an existing exchange long enough to send a credible payment change. The FBI calls this business email compromise, or BEC. Its examples include a familiar vendor apparently sending an updated address or payment request. [1]
The critical mistake is not necessarily believing a fake invoice. It can be accepting new payment instructions on an authentic one without checking them through a separate channel. That is a control a small contractor, professional practice, or growing agency can build before the next transfer. Insurance deserves a second, distinct conversation: whether a particular cyber or commercial crime form would respond if the control fails.
A real invoice does not authenticate a new bank account. And a policy labeled “cyber” does not, by its name alone, insure a redirected payment.
01Business protection · Payment integrity
The moment
the transaction changes
Business email compromise does not require a dramatic ransomware screen. A criminal may impersonate an owner, vendor, or customer and ask someone to change a payment destination. The FBI notes that criminals can use an altered address or gain access to legitimate email threads about billing and invoices. That makes the request feel familiar. [1]
The attack can take different forms. One message may use an address that differs from the genuine vendor's by a character. Another may come from a compromised real mailbox, where the address itself is correct. A third may impersonate the business to persuade a customer to pay the criminal instead. Checking spelling helps in the first case, but it cannot establish that a real account has not been taken over.
The safest decision point is simple: treat any new bank account, routing number, or payment method as a change requiring independent verification. The FBI recommends contacting the person through a known channel, not a number supplied by the suspicious message, and verifying changes to payment procedures. The FTC advises businesses to train staff to scrutinize invoices and set clear approval procedures. [1] [2]
02Business protection · Payment integrity
One event can create
three different insurance questions
The phrase cyber fraud describes a risk, not a guaranteed coverage grant. Ask what was lost, who lost it, how the transfer occurred, and whether another person's information or money was affected.
| What happened? | Starting insurance question | Why it matters |
|---|---|---|
| Your employee was deceived into sending the business's money to a new account | Does a commercial crime, social-engineering, or cyber-crime grant apply to a fraudulently induced transfer? | Some forms distinguish an employee-authorized transfer from an unauthorized instruction or system intrusion. |
| An intruder accessed your mailbox, data, or network | Does first-party cyber coverage address investigation, recovery, notification, or covered interruption costs? | Response expenses and the stolen payment are different kinds of loss. |
| A customer or vendor alleges that your compromised email caused their loss | Does third-party cyber liability address a qualifying claim and defense? | The claimant, insured, event definition, and loss must match the issued wording. |
The Federal Trade Commission describes first-party cyber insurance as potentially addressing the business's own costs, such as forensic investigation, data recovery, notification, and certain fraud or interruption expenses. It describes third-party cyber protection as potentially addressing claims brought by others. The FTC also advises reviewing which protections a business actually buys. Its overview is not a promise that a standard cyber policy reimburses a deceived payer's wire. [3]
A separate commercial crime policy may offer a social-engineering endorsement. Chubb, for example, describes an optional crime endorsement for vendor, executive, and client impersonation. That is an illustration of a market option, not an assertion that SmittyShield offers that form, that any particular business qualifies, or that all crime policies include it. [4]
03Business protection · Payment integrity
Read the transfer wording,
not just the declarations page
A useful insurance review starts with the exact payment story. Who owned the money? Who pressed Send? Was a genuine company account accessed? Did the criminal give a fraudulent instruction directly to a bank, or persuade an authorized employee to approve the transfer? Those differences can matter under a particular form.
Ask to see the policy's definitions of social engineering, computer fraud, funds-transfer fraud, and cyber crime, if present. Compare their triggers with a vendor-bank-change scenario and a customer-payment-diversion scenario. A grant aimed at an unauthorized electronic transfer may be different from one addressing a transfer that an employee intentionally initiated after being tricked. A voluntary parting exclusion or a specific carve-back may affect the result. Amwins discusses these differences and cautions that policy forms vary substantially. [5]
Next, find the separate limit or sublimit, deductible or retention, reporting window, and any requirement to verify a payment change. Confirm whether loss of client funds is addressed. Some contracts require a callback or authentication step; failing a policy condition can change the claim outcome even when the loss fits a broad description. Amwins identifies callback, client-funds, and lower-limit issues as key differences to review. [5]
Do not confuse three statements:
- “We have cyber insurance.” That identifies a policy category.
- “The policy includes fraud language.” That identifies a provision worth examining.
- “This vendor payment is covered.” That is a claim-specific conclusion requiring the issued policy, facts, and insurer's review.
No article can skip from the first statement to the third.
04Business protection · Payment integrity
A six-minute
change-of-payment test
The best time to find a weak approval process is before the bank screen is open. Use one ordinary vendor-payment change as a rehearsal.
Pause the change. Keep the existing bank details on file until the request is confirmed. Mark the new instructions as unverified, even if the email looks like a familiar thread or arrives on a busy deadline.
Call a known contact. Use a number already in an approved vendor record or independently obtained through a trusted channel. Do not use the number, link, or reply address in the payment-change email. Ask an authorized person to confirm the change and record whom you reached. This follows FBI advice to verify requests through an independently established contact. [1]
Separate approval from payment. Have someone other than the person entering the new bank details approve the change. Set a sensible second-approval threshold for new vendors, changed bank accounts, and unusual transfers. The FTC stresses clear purchase and invoice approval procedures; the particular threshold is a business decision, not an insurance rule. [2]
Keep a compact record. Record the original request, verified contact, call date, approver, vendor record, and final account details in a controlled system. Restrict who may change payment instructions. This log does not create coverage, but it can help reconstruct what happened if a transfer later proves fraudulent.
Add multifactor authentication on business email and payment systems, and train staff to question urgent requests. The FBI recommends MFA and independent verification of changes to account numbers or procedures. [1]
05Business protection · Payment integrity
If a payment already went out,
speed and evidence matter
Contact the sending bank immediately. Tell its fraud team the transfer may have been redirected and ask whether recall or reversal steps remain available. The FBI's Internet Crime Complaint Center (IC3) says to contact the originating financial institution as soon as fraud is recognized. A request is not a guarantee that the funds can be recovered. [6]
File a detailed complaint at IC3.gov. Include the payment and banking information requested by the official complaint process. The FBI also says to contact your financial institution and request that it reach the receiving institution. [1] [6]
Preserve the evidence. Save the original invoice, message headers, thread history, payment authorization, bank confirmation, vendor callback notes, and any available access logs. Tell the business's cyber or crime insurer promptly using the notice channel in its policy; ask about authorized forensic and legal assistance before incurring significant expenses when the form requires preapproval.
If an email account or personal information was actually exposed, there may be a separate incident-response problem. The FTC advises securing systems, preserving evidence, working with appropriate experts, and evaluating notice obligations with counsel based on the facts and applicable law. A diverted payment by itself does not establish that customer data was breached; a breached mailbox may require further investigation. [7]
06Business protection · Payment integrity
Payment-change
readiness check
Use these questions with the person who approves bills and the person who manages insurance. Each answer should point to a procedure or policy page, not an assumption.
Can your team verify the next change?
Check a question after reviewing its actual answer. A checked box does not mean the answer is yes or that insurance will respond.
A business does not need to wait for a loss to have this conversation. One verified callback protocol can prevent a transfer from leaving. A separate review of the issued policies can reveal what happens if an apparently routine invoice still slips through.
For a different kind of interruption, read The Building Is Back. The Business Is Still Closed. For the broader question of policy wording versus evidence of insurance, read The Certificate Says Insured. The Endorsement Decides What That Means. To review available business-protection options with SmittyShield, call (561) 606-0778 or email smithlaurent@smittyshield.org. A discussion is not a binder, guarantee, or claim determination.

