Law Firm Wire Fraud: Do Cyber and Crime Policies Cover Client Funds?
Quick answer: Cyber insurance, crime insurance and legal malpractice coverage are not interchangeable when client funds are diverted. Review whose money is insured, how the transfer was authorized, the social-engineering wording and any verification conditions. A policy that covers a hacked computer may still limit a voluntarily authorized payment to a fraudster.
Separate the loss scenarios
| Event | Coverage question |
|---|---|
| A staff member follows fraudulent changed bank instructions | Is social engineering included, and at what sublimit? |
| An intruder initiates a transfer without approval | How does the policy define funds-transfer or computer fraud? |
| A client sends money to an impostor | Is this a client loss, a firm loss or a liability allegation? |
| Funds in a trust account are diverted | Does the insured-property definition include that money? |
What does the limit really buy?
Compare the applicable sublimit and retention with the largest plausible transfer, not just annual firm revenue. Ask about aggregation when several payments arise from one fraudulent instruction. Review who must verify a payment, how that verification is documented and whether the policy contains an exclusion or condition affecting the scenario.
Professional liability may respond to an allegation about legal services under its own terms; it does not automatically reimburse stolen money. Have the broker examine how the policies interact without assuming one always fills the other's gaps.
Make verification independent of the message
The FBI recommends verifying payment requests using an independently obtained phone number. A reply to the same email thread is not independent confirmation. Design a documented approval process with a known contact, and avoid relying on contact details supplied with the changed instruction.
If funds have already moved
Contact the financial institution immediately, follow the firm's incident and professional-responsibility process, and notify relevant insurers through the required channels. Preserve payment instructions, timestamps and evidence without altering original messages. The FBI's BEC guidance identifies its IC3 reporting channel.
For renewal, provide a description of trust-account handling and payment approval controls through a secure channel. Do not send client identities or account numbers in a public quote request. Obtain answers on actual forms before deciding that a large cyber limit is sufficient.