Data security incidents come in all shapes and sizes and can have wide-ranging consequences.  One such consequence is a “business email compromise” (BEC), which the FBI describes as “a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments.”  BEC scams involve “compromising email accounts and other forms of communication . . . through social engineering or computer intrusion techniques to conduct unauthorized transfer of funds.”  In 2025 alone, the FBI received reports of more than $3 billion in losses due to BEC scams.

BEC scams can happen in any number of ways, with common variants including these:

  • Spoofed email accounts with slight variations to legitimate addresses to make them appear authentic;
  • Spear phishing emails that trick the recipient into revealing confidential information (e.g., access credentials, bank account information); and
  • Infiltration of computer networks (e.g., via malware) in order to access email threads regarding billing and payment.

Consider this scenario:  “GC” is a general contractor that has retained a subcontractor, “SUB,” for a construction project.  Throughout the course of the project, SUB would email invoices to GC along with wiring instructions specifying SUB’s legitimate bank account, and GC would pay the invoice per those instructions.  On Monday, SUB emails invoice #23 to GC as usual.  On Tuesday, and unbeknownst to SUB or GC, SUB is the victim of a BEC whereby a fraudster is able to access SUB’s email account and set up a rule to divert any emails from GC so that SUB cannot see them.  On Wednesday, the fraudster (posing as SUB) sends a follow-up email regarding invoice #23 to GC using SUB’s email account, and in that email the fraudster provides new wiring instructions to GC.  On Thursday, GC responds to the fraudster—believing him to be SUB—to confirm receipt of the new instructions, and then proceeds to make payment for invoice #23 to the account specified in those instructions.  The wire transfer is successful.  Two weeks later, and having not received any payment for invoice #23, SUB contacts CG to inquire as to when the invoice will be paid.  GC responds that it paid the invoice weeks ago, and it is eventually determined that the funds sent by GC to the fraudster’s bank cannot be recovered and are therefore lost.  Who bears the loss here?

The answer, as it turns out, is not that straightforward.  Courts across the country have confronted similar fact patterns, but they have not taken a uniform approach in addressing them.  Some courts have held that liability rests on the party that was “most greatly at fault” in causing the payment to be misdirected.  Other courts apply the “imposter rule” from Uniform Commercial Code (UCC) Article 3, section 3-404 (which governs negotiable instruments) by analogy, which places liability on the party who was in the best position to prevent the fraud by exercising reasonable care (e.g., by calling a known number to verify changed instructions).  Other courts have ruled that a party failing to exercise reasonable care in preventing unauthorized access to its email account should be liable for the subsequent loss.  Along similar lines, some courts have looked to agency law to find that, in the eyes of the party making payment, the fraudster posing as the party to be paid had apparent authority to change the wiring instructions.  Finally, some courts have addressed the issue from a pure breach of contract perspective—i.e., if GC owes SUB money under a contract and GC’s payment never reaches SUB, then GC is still liable under the contract for not paying SUB.

Another common fact pattern that emerges from BEC scams is a fraudster communicating with a business’s bank in order to transfer funds from the business’s bank account to an account controlled by the fraudster.  The issue in these scenarios is whether the business or the bank suffers the loss for the diverted funds. 

The answer to that question lies primarily in Article 4A of the UCC, which governs funds transfers.  Under Article 4A, the default rule is that the bank bears the loss for any unauthorized funds transfers.  An exception to that rule is where a payment order to the bank is deemed to be “effective.”  That occurs when (a) the bank and the customer have agreed to a “commercially reasonable” security procedure for purposes of verifying the authenticity of payment orders and (b) the bank accepted the payment order in question in good faith and in compliance with the agreed-upon security procedure. 

But even if a payment order is deemed “effective,” the customer will not bear the loss if either (a) the bank has agreed in writing that the bank will bear the loss, or (b) the customer can prove that the payment order was not caused by either (i) a person entrusted by the customer to act on its behalf regarding payment orders or the security procedure or (ii) a person who—without authority from the bank—obtained information from the customer (via any means, including a data security incident) that allowed that person to breach the security procedure.

The Bottom Line

Needless to say, wire fraud situations can be very thorny and complicated.  Recognizing and thwarting  security incidents that lead to BEC scams is a good way to avoid wire fraud.  But as we all know, data security incidents are inevitable and a part of doing business today.  That reality underscores the importance of being vigilant at every step of the way.  Indeed, even if your business is hit with a BEC scam, exercising vigilance—such as by verifying altered wiring instructions by calling a known contact at a known number—can stop trouble before it starts.


Disclaimer: This article provides general information about data privacy and is not a substitute for professional legal advice. Privacy requirements may vary by organization, jurisdiction, and industry. Always consult with a qualified data privacy attorney to develop strategies tailored to your specific needs.