Cyber InsurancePosted by confused_homeowner_579

small business hit by a $187k BEC wire-fraud loss, our cyber carrier (Chubb) is applying a $50k "fraudulent instruction" sublimit instead of the $1M policy limit - is there a path to argue the computer-fraud or funds-transfer fraud coverage applies instead?

need input from cyber claims attorneys, brokers, or any business owner who has been through a BEC (business email compromise) wire-fraud claim, especially with Chubb or one of the AIG / Travelers / Hartford cyber carriers. we are a 38-employee architecture firm in the midwest. carry a Chubb cyber policy, $1M aggregate, with a number of sublimits inside it that we frankly did not fully understand at bind. the loss happened in march. carrier coverage position dropped last week and it is a $137k coverage gap. i am trying to understand if this is winnable or if we have to swallow the gap and move on.

quick facts. our office manager (28 years with the firm, very reliable, not someone who falls for the obvious phishing emails) received what appeared to be a legitimate email from one of our largest clients - a long-running commercial developer client - asking to redirect a $187,400 milestone payment from the previously-used ACH account to a new wire-transfer account. the email came from what LOOKED like the clients CFO email address (we later learned it was a spoofed display name plus a similar-looking domain - claient-corp dot com instead of client-corp dot com, with the L and I swapped). there had been a real prior email exchange about the milestone payment with the actual CFO 8 days earlier. the spoofed email referenced that prior exchange in detail. our office manager called the number in the email signature (which was a fraudster-controlled VoIP number) to "verbally confirm" the wire instructions and got a voice that confirmed the change. she then initiated the wire from our operating account to the new account. funds gone within 4 hours. the bank tried to recall, recovered $0.

we discovered the fraud 3 days later when the real client called asking where the milestone payment was. immediately reported to (a) FBI IC3, (b) our bank, (c) the receiving bank (which had already closed the mule account), (d) our cyber carrier, (e) an external IT forensics firm. the forensics work confirmed the spoofed domain attack vector with no compromise of our actual email system or accounts. our office manager did not click anything malicious, was not phished in the credential-harvesting sense, and our network was not compromised. she received a well-crafted social engineering email from a similar-looking domain and acted on it.

the policy structure is where it gets complicated. our Chubb cyber form has multiple coverage agreements within the $1M aggregate:

(1) "Computer Fraud" coverage - covers loss resulting directly from "fraudulent entry of Data into, or fraudulent change of Data within, a Computer System." $1M sublimit.

(2) "Funds Transfer Fraud" coverage - covers loss resulting directly from "a Fraudulent Instruction directing a Financial Institution to debit the Insureds Transfer Account and transfer funds." $1M sublimit.

(3) "Social Engineering / Fraudulent Instruction" coverage - covers loss resulting from "the Insured transferring, paying, or delivering Money or Securities in reliance upon a Fraudulent Instruction received by an Employee that purports to be from a Vendor, Client, or Authorized Person." $50,000 sublimit.

Chubb is saying this is squarely a (3) social engineering claim - the fraudulent instruction was received by our employee, she relied on it, she initiated the wire. they are paying the $50k sublimit and denying the rest.

our broker is now (belatedly) pushing back and saying the coverage analysis is more nuanced and there is established case law on similar BEC losses applying the higher-limit Computer Fraud or Funds Transfer Fraud coverages instead of the sublimit. broker name-checked Medidata Solutions v Federal Insurance Co (2d Cir 2018) and Am. Tooling Center v Travelers (6th Cir 2018) as cases where appellate courts applied Computer Fraud coverage to BEC losses despite carrier arguments that social engineering sublimits should apply. but he also acknowledged that more recent cases have gone the other way and that the specific policy form language matters enormously.

questions for the panel.

(a) is the Medidata / Am. Tooling line of authority still viable in 2026? i have seen later cases (e.g. Mississippi Silicon Holdings, RealPage, Interactive Communications) where carriers won by arguing the "directly resulting" language requires that the fraudulent computer activity ITSELF cause the transfer rather than an intervening human decision. is that the dominant view now or is the law still split by circuit?

(b) the specific policy language matters. our Computer Fraud agreement requires "fraudulent entry of Data into, or fraudulent change of Data within, a Computer System." can a spoofed email arguably constitute "fraudulent entry of Data"? our broker thinks yes (the email is data, entered into our email server, fraudulently); Chubb is saying no (the spoofed email is "communication" not "data entry" within the meaning of the form). how do courts typically read this?

(c) the Funds Transfer Fraud agreement requires that the Fraudulent Instruction direct the Financial Institution to make the transfer. in our case the fraudulent instruction directed OUR employee to instruct the bank. the bank acted on a legitimate instruction from our authorized signer. does this take us out of FTF coverage entirely or is there an argument that the chain of causation is still within the coverage grant?

(d) the social engineering sublimit on our form is $50k. our broker now says he should have recommended a $1M sub but did not. is there potentially a broker E&O claim here, and does pursuing that complicate the underlying coverage dispute (since the carrier might argue we cannot have both - either the sublimit applies and we go after the broker, or higher coverage applies and there is no broker exposure)?

(e) what is the typical attorney structure for fighting a coverage dispute of this size? we are looking at a $137k gap which is a real number to us but maybe not large enough to justify a full insurance coverage litigation budget. is there a class of policyholder coverage attorney who handles these on contingency or modified hourly? we have one quote at $475 per hour with a $25k retainer and an estimated 80-150 hour case if it goes to litigation.

(f) finally, is there a regulatory or "good faith" angle worth pursuing? we feel like the carriers coverage analysis ignores the structure of how BEC actually works (the social engineering element is INHERENT in nearly every BEC loss, so categorically applying the lowest sublimit to all BEC losses effectively means the carrier never has to pay more than $50k on a wire-fraud claim even if the policyholder bought $1M of cyber coverage). is there a bad-faith claim-handling argument or a state insurance department complaint angle worth exploring? we are domiciled in a "weak bad faith" state but the carriers position feels like a structural problem with how cyber policies are being marketed vs how they actually pay.

any input appreciated. this is the largest single loss event in our firms history and we are still digesting the financial impact.

5 comments
5 Comments
Log in or sign up to leave a comment

Loading comments...

small business hit by a $187k BEC wire-fraud loss, our cyber carrier (Chubb) is applying a $50k "fraudulent instruction" sublimit instead of the $1M policy limit - is there a path to argue the computer-fraud or funds-transfer fraud coverage applies instead? | ClaimCave