When a real estate firm calls me about stolen money, the first thing they say is almost always “we had a wire fraud.” That phrase covers at least five different events. They feel identical when you're living through one. To an insurance policy they're five separate claims, handled by different coverage, with different limits and different conditions.

Two questions sort nearly all of them: whose money was it, and what did the criminal actually do to get it? Here's how each one works, and how the Arch NetSafe® 2.0 program we place for real estate firms responds.

How to read the graphics in this article: a green coin is the client's money, a navy coin is your firm's money, a solid line shows where the money went, a dotted red line shows the attack, and a red badge marks a system that was broken into.

1. Third-party wire fraud: your system was breached, your client's money was taken

Third-party wire fraud: the fraudster breaches your firm's email, and the client sends their own money directly to the fraudster.

A criminal gets into your email. They sit quietly, read the transaction file, and learn the closing date, the amount, and the names. Then they send your buyer wiring instructions that look like they came from you. The buyer wires the down payment straight to the criminal.

Notice what didn't happen: the money never touched your account. Your client sent their own funds, from their own bank. But the fraud worked because of information taken from your systems, and your client is going to look to you.

That's a liability claim, and it's handled under Network Security and Privacy Liability, at the full limit of that coverage part, with a duty to defend you. The trigger is unauthorized access to your systems, or a failure to protect private information in your care. If the criminal never got into your systems and simply spoofed a look-alike domain, there's no network security event to point to, and the claim becomes the very different one described further down. I covered that distinction in detail in our post on client funds and the callback.

One detail matters more than it looks. The standard form excludes theft of money from covered damages, and the damages in this lawsuit are stolen money. On the program we place, an endorsement removes that exclusion. Without it, this coverage would defend you and then decline to pay the thing you were sued for.

2. First-party social engineering: you were tricked into sending your own money

First-party social engineering: the client is not involved; the fraudster deceives your firm into sending its own money.

This time the target is you. An email arrives that appears to be from a vendor with new bank details, or from the broker-owner asking accounting to get a payment out before the end of the day. Someone on your team sends the firm's operating funds to the criminal.

Nobody broke into anything. A person was deceived into making a payment voluntarily, which is why this is called social engineering, and why we've been writing about it since 2016. PBI Group was even targeted by one ourselves.

This is Social Engineering coverage, one of the Cyber Crime coverages on the policy. It comes with a condition you need to know cold: the instructions have to be verified through a different channel than the one they arrived by, before the money moves. If the request came by email, replying to that email doesn't count. Call a number you already had on file.

3. Social engineering of client funds: same trick, but the money wasn't yours

Social engineering of client funds: the client entrusts funds to your firm, and your firm is deceived into sending the client's money to the fraudster.

Identical deception, with one change. The money that left your account belonged to someone else: an earnest money deposit, a security deposit, rent collected for an owner, or closing funds waiting on settlement.

This is where many cyber policies fail real estate firms. A lot of forms cover only direct loss of the insured's own money. The Arch Cyber Crime endorsement extends covered loss to a customer's funds in your “care, custody and control,” including funds held in your account. Client money in your trust account is treated like your own, with the same callback condition as scenario 2.

If your firm holds other people's money in any form, this is the most important sentence to find in your own policy.

4. Electronic transfer fraud: you never sent anything, and the money moved anyway

Electronic transfer fraud: your firm never authorized it; the fraudster sends fake instructions to your bank, which moves the money out.

In scenarios 2 and 3, the criminal fooled you. Here, the criminal fools your bank. Instructions reach your financial institution that appear to come from you, approved by someone with authority at your firm, directing money out of your account. Often that starts with stolen online banking credentials. You find out when you look at the balance.

No one at your firm authorized anything, and no one at your firm was deceived. This is Electronic Transfer Fraud, and like Social Engineering, it covers both your own money and client funds in your care, custody and control. It's also the best argument I know for the basics: multi-factor authentication on banking and email, and daily review of account activity.

5. Invoice manipulation: your invoice went out, and their payment went elsewhere

Invoice manipulation: a fraudster who breached your systems sends your client a fraudulent invoice, and the client's payment goes to the fraudster instead of you.

You've done the work and the bill is due: a management fee to a property owner, a commission statement, an invoice to a commercial client. A criminal who has gotten into your systems sends your client a fraudulent version with different payment details. Your client pays on time and in full, into the wrong account.

Your client believes they've paid you. You've received nothing. Both of you are right, and the firm is left unable to collect for services it already delivered. Invoice Manipulation coverage exists for exactly this, and it's often missing from commodity cyber policies altogether.

Two things to know. First, like scenario 1, it requires a breach of your systems or a privacy violation, so a pure look-alike-domain scam with no compromise on your side doesn't qualify. Second, the coverage reimburses what the uncollected work cost you, not the profit you would have made on it.

Sorting them out

ScenarioWhose moneyWhat the criminal didHow the Arch policy responds
Third-party wire fraudClient's, sent by the clientBreached your systemsNetwork Security and Privacy Liability, full limit, duty to defend
First-party social engineeringYoursDeceived your staffCyber Crime, shared $250,000 limit
Client funds in custodyClient's, held by youDeceived your staffCyber Crime, shared $250,000 limit
Electronic transfer fraudYours or a client's, in your accountDeceived your bankCyber Crime, shared $250,000 limit
Invoice manipulationPayment owed to youBreached your systems, sent a fraudulent invoiceCyber Crime, shared $250,000 limit

One of these five is a liability claim that carries the full limit. The other four are Cyber Crime losses that share a single $250,000 aggregate limit for the policy period. They are not four separate buckets of $250,000, and that limit sits inside the policy's overall limit, not on top of it. That's worth knowing before a loss, and worth a conversation with us if your firm routinely holds or moves more than that.

Cyber Crime coverage is also reimbursement, not litigation coverage. It doesn't pay legal costs or liability to third parties. If a client sues, that's scenario 1's coverage part, and only if a breach sits in the chain of events.

The one your cyber policy won't answer: wire fraud negligence

E&O wire fraud negligence: no breach of your systems; your firm forwards the fraudster's instructions unverified and the client wires their own money to the fraudster.

There's a sixth fact pattern, and I've kept it out of the count on purpose, because it isn't a cyber claim at all.

Go back to scenario 1 and take away the breach. Nobody got into your email. Nobody touched your bank account or your invoices. A criminal simply sent fraudulent wiring instructions that looked like they came from someone in the transaction, and one of your agents passed them along to the buyer without verifying them. The buyer wires the closing funds to the criminal, can't get them back, and makes a claim against the agent and the brokerage.

Run that through the cyber policy and nothing fits. There was no network security breach, so scenario 1's liability coverage has no trigger. It wasn't your money or money in your custody, so the Cyber Crime coverages don't apply. What the buyer is alleging is ordinary professional negligence: you were careless in providing real estate services, and it cost me my down payment.

That's an E&O claim, and it runs straight into a problem. Most real estate E&O policies broadly exclude claims involving the theft or mishandling of money. My colleague Jonathan Lugo walks through this in E&O Coverage for Wire Fraud Negligence, including a claim he saw where a top-producing agent forwarded fraudulent instructions and the matter settled in mediation for tens of thousands of dollars.

Only a handful of E&O policies carve this exposure back in. The PBI Group E&O endorsement does, for a client who was deceived into wiring funds that can't be fully recovered because of an insured's negligence in providing real estate professional services. The carveback currently carries a $35,000 sublimit covering both claim expenses and damages, and it sits within the policy aggregate. It's deliberately narrow. It isn't wire fraud coverage, and it isn't a substitute for scenario 1's coverage when your systems actually were breached.

The practical point is that the same stolen down payment can land on two different policies depending on one fact: did the criminal get into your systems, or not? If yes, it's a cyber liability claim at the full limit. If no, it's an E&O negligence claim, and whether anything responds depends on a carveback most firms have never checked for. You need both policies, and you need to know what each one says.

What to do with this

Pull your cyber policy and look for all five. Then pull your E&O policy and look for the wire fraud negligence carveback. In the policies we review for real estate firms, it's common to find “Social Engineering: Covered” on the declarations page and nothing behind it for client funds, invoice manipulation, or a client's lawsuit after a breach. The answer is usually in the endorsements, not the first page.

Then pick up the phone. A callback to a known number, every transfer, every time, defeats most of these schemes before insurance is ever needed, and it keeps the coverage intact when it is. Our 7 steps to protect your agency from social engineering and the comprehensive cyber guide for real estate firms go deeper.

If you're not sure what your policy says, send it to us, including declarations, the full form, and every endorsement. We'll walk through it with you, no pressure and no obligation.

Eric Mauriello is a Partner at PBI Group and leads the firm's cyber insurance coverage practice for residential real estate professionals. Reach him at 973-349-2194.

This article is educational and summarizes policy mechanics in general terms. It is not legal advice, and it does not modify any policy. Limits vary by policy. Coverage outcomes depend on the specific policy language, endorsements, and facts of each claim. Make all final coverage determinations from your actual policy documents, and involve your legal counsel in claim decisions.