Will Cyber Insurance Cover a Law Firm Wire Fraud Loss?

Law firms are prime targets for wire fraud. 

Attorneys regularly handle sensitive financial transactions involving trust accounts, retainers, settlements, real estate closings, vendor payments, and client funds. That makes law firms attractive to cyber criminals who know that one convincing email can lead to a very expensive mistake.

A typical wire fraud scenario:

It starts with an email that looks legitimate. It may appear to come from a client, a title company, opposing counsel, a vendor, or even someone inside the firm. The email may include a real matter name, familiar language, and wiring instructions that seem reasonable. In some cases, the fraudster has gained access to an actual email account. In other cases, the email address is simply spoofed or altered slightly.

The firm wires the money. Then, after the transfer is complete, someone realizes the instructions were fraudulent.

At that point, the firm has two immediate concerns. 

First, can the money be recovered? 

Second, will insurance cover the loss?

Many attorneys assume that if their firm has cyber liability insurance, a wire fraud loss will automatically be covered. Others assume the loss will fall under crime coverage or lawyers professional liability insurance. Unfortunately, the coverage answer is not always that simple.

Wire fraud can fall into a complicated area between different types of policies. A cyber policy may include coverage for social engineering fraud or funds transfer fraud, but that coverage may be limited by a sublimit. The policy may also include conditions that must be satisfied before coverage applies. For example, the firm may be required to follow specific verification procedures before transferring funds.

A crime policy may also provide coverage in certain situations, but not every fraud scenario fits neatly into the policy language. Lawyers professional liability insurance, meanwhile, is generally designed to respond to professional negligence claims. It should not be treated as a catch-all policy for every financial loss connected to a cyber event.

That is why law firms should not assume they are covered just because they have “cyber insurance” listed on a policy. The details matter.

Firms should review whether their policies address social engineering fraud, fraudulent instruction schemes, and funds transfer fraud. They should also pay close attention to sublimits, exclusions, deductibles, and any required internal controls. A policy may provide a $1 million cyber limit, but the amount available for social engineering fraud could be much lower.

Just as important, the firm’s internal procedures should match the risk.

Email alone should never be enough to change wiring instructions or authorize a transfer. 

If new or revised instructions are received, the firm should verify them using a trusted phone number already on file – not the phone number included in the suspicious email. Any last-minute change, unusual urgency, or request to bypass normal procedures should be treated as a red flag.

Wire fraud prevention is not just an IT issue. It is a law firm management issue, a risk management issue, and an insurance issue.

Before a loss occurs, attorneys should speak with their insurance advisor and review their coverage carefully. The goal is to understand what coverage may apply, what limits are available, and what procedures the firm must follow.

The worst time to discover a gap in coverage is after the money is gone. If your law firm handles wire transfers or client funds, make sure you know how your insurance would respond before a fraud attempt turns into a claim.