When a scammer hacks an email account and uses it to redirect a wire, the person who authorized the transfer is almost always the one who eats the loss. That is the practical answer to who is responsible for a hacked email wire transfer, and it holds even when the sender was deceived. Under Article 4A of the Uniform Commercial Code, adopted in every state, a payment order the customer told the bank to send is treated as authorized. The FBI logged $2.8 billion in business email compromise losses in 2024 alone, part of $16.6 billion in reported cybercrime losses that year.1Internet Crime Complaint Center (IC3). 2024 IC3 Annual Report Most of that money is never recovered, and most of the loss falls on the sender.
Why the Sender Is the Default Loser
Wire transfers between banks run under UCC Article 4A, which was written for speed and finality.2Legal Information Institute (LII) / Cornell Law School. Uniform Commercial Code Locator Your bank is treated as a messenger. If it followed commercially reasonable security procedures and acted in good faith, the payment binds you as the customer whether or not the underlying instructions were fraudulent.3Legal Information Institute (LII) / Cornell Law School. UCC 4A-202 – Authorized and Verified Payment Orders The logic is blunt: you told the bank to send the money. A criminal manipulating you into giving that instruction does not make the transfer “unauthorized” for Article 4A purposes.
People often assume federal consumer protections will step in. They don’t. The Electronic Fund Transfer Act, which caps consumer liability for unauthorized debit card and electronic transactions at $50 if reported within two business days, specifically excludes wire transfers.4Office of the Law Revision Counsel. 15 USC 1693a – Definitions Regulation E reinforces the exclusion for bank-to-bank wires sent through systems like Fedwire.5eCFR. 12 CFR 1005.3 – Coverage If a thief drains your debit card, federal law caps what you owe. If a thief hacks an email thread and convinces you to wire $80,000 to a fake account, Article 4A governs and there is no comparable cap. The distinction between “someone used your account without permission” and “you authorized a payment to the wrong person” decides the case.
When the Bank Can Be Held Responsible
Banks are rarely on the hook for a BEC wire loss, but the door isn’t shut. The pivotal question under Article 4A is whether the bank used a commercially reasonable security procedure and actually followed it. A “security procedure” can include callback verification, encryption, identifying codes, or other agreed methods for confirming a payment order came from you.6Legal Information Institute (LII) / Cornell Law School. UCC 4A-201 – Security Procedure Comparing a signature to a specimen on file doesn’t count on its own.
If your bank agreed to call you back to confirm a wire and skipped the callback, it cannot enforce the payment order against you.3Legal Information Institute (LII) / Cornell Law School. UCC 4A-202 – Authorized and Verified Payment Orders The burden sits on the bank to prove it complied in good faith. That said, banks pick the procedures they offer, and those procedures only need to be commercially reasonable, not foolproof. If your bank offered a callback and you opted out for something faster, the bank is likely protected even if a callback would have caught the fraud.
Name and Number Mismatches
A separate rule creates narrow bank exposure when a wire lists both a beneficiary name and an account number and they identify different people. Under UCC 4A-207, the receiving bank can generally rely on the account number alone and does not have to check whether the name matches.7Legal Information Institute (LII) / Cornell Law School. UCC 4A-207 – Misdescription of Beneficiary That rule only works, though, if the bank gave the sender advance notice that payments could be processed by number regardless of the name. A non-bank sender who can prove they were never warned, and whose money went to someone not entitled to it, may be able to recover. Most banks bury the disclosure in their wire agreements, so check yours before assuming this argument is available.
When the Party Whose Email Was Hacked Can Share the Loss
Sometimes the compromised inbox belongs to the other side of the deal. A vendor or business partner gets hacked, and the attacker uses that access to send fake payment instructions to the vendor’s customers. Whether the hacked party bears any of the loss is a developing area of law.
Courts have started allowing claims against the hacked party where they failed to secure their email systems. The reasoning tracks a “who could have prevented this most cheaply” logic. If a vendor’s email lacked basic protections like two-factor authentication, and that gap is what made the fraud possible, some courts have let the sender’s negligence claim proceed. The analysis turns on whether the hacked party was careless in protecting their communications and whether any contract between the parties addressed who carries the risk of payment fraud. This is not a reliable path to recovery, but it is a real one worth exploring with counsel when the facts fit.
What Pushes Blame Squarely Onto the Sender
When a dispute over a BEC wire lands in court, judges focus on warning signs the sender missed. A few patterns tend to end the argument quickly:
- Changed wire instructions delivered only by email, especially mid-transaction. A request to update banking details should trigger a phone call to a known number, not the one in the suspicious email.
- Subtle email address changes, such as a domain like @compeny.com instead of @company.com, or a reply-to address that differs from the sender line.
- Unusual urgency or secrecy, including pressure to pay immediately or requests not to call to confirm.
- A first-time international wire when every prior payment was domestic.
Organizations without internal controls on outgoing wires are especially exposed. If your company has no rule requiring a second approver on large transfers or a phone confirmation of new payment details, a court will likely treat that as a failure to exercise reasonable care. In most BEC cases, a single verification call to a known number would have stopped the fraud, and that fact tends to decide who pays.
What to Do in the First Few Hours
Speed changes outcomes. Once wired funds land in a fraudulent account, they typically move within hours, often overseas. In order:
- Call your bank’s fraud department and ask them to contact the receiving bank to freeze the funds. If the money has not been withdrawn, a freeze can hold it while things get sorted out.
- File a report with the FBI’s Internet Crime Complaint Center at ic3.gov, including the transaction date, amount, account numbers, and every communication with the fraudster. The IC3’s Recovery Asset Team coordinates freeze requests with banks and field offices.1Internet Crime Complaint Center (IC3). 2024 IC3 Annual Report
- Ask about the Financial Fraud Kill Chain. For domestic transfers above a set threshold, the FBI can trigger a coordinated freeze across financial institutions. In 2024, the process froze $469 million in domestic funds and $92.5 million internationally, with a 66% overall success rate.1Internet Crime Complaint Center (IC3). 2024 IC3 Annual Report
- Preserve everything. Save the fraudulent emails with full headers, wire confirmations, phone records, and every message with the scammer. This matters both for law enforcement and any later legal claim.
The One-Year Outer Deadline
Article 4A sets a hard stop even if you don’t spot the fraud right away. If your bank sent a statement or notification identifying the wire and you fail to object within one year, you lose the right to challenge the transaction at all.8Legal Information Institute (LII) / Cornell Law School. UCC 4A-505 – Preclusion of Objection to Debit of Customer’s Account That preclusion applies whether the bank made an error or the payment was unauthorized. Review statements regularly, because letting the year run kills whatever legal argument you might have had.
Whether Insurance or Taxes Soften an Unrecovered Loss
Standard business policies generally do not cover BEC losses. The trouble is that you voluntarily sent the wire, and many policies treat voluntary transfers as outside coverage even when deception was involved. Two products can close the gap, though neither is automatic.
A commercial crime policy covers direct financial losses from fraud, but social engineering losses, where an employee is tricked into sending money, are typically excluded unless you add a specific endorsement. Sub-limits on those endorsements tend to be lower than the overall policy limit. Cyber liability insurance focuses on breach response costs like forensic work, notification, and legal fees; coverage for the stolen funds themselves usually requires a separate funds transfer or social engineering rider. If your business wires money regularly, ask your broker directly whether the policy pays when an employee voluntarily follows fraudulent payment instructions. The answer is often no without the right endorsement, and businesses tend to learn that only after a loss.
Taxes are a smaller consolation. Businesses can generally deduct wire fraud losses as theft losses in the year the theft is discovered, reduced by any insurance recovery, reported on Form 4684 using Section B for business-use property.9Internal Revenue Service. Topic No. 515, Casualty, Disaster, and Theft Losses If an insurance claim is still open, you may need to wait for it to resolve before taking the deduction. For individuals, the rules are tighter. Personal theft losses have been deductible only for federally declared disasters since 2018, but if the loss came out of a transaction entered into for profit, such as a real estate purchase or investment, it may still qualify as a deductible theft loss.10Internal Revenue Service. 2025 Instructions for Form 4684 – Casualties and Thefts The loss must qualify as theft under state law, and you must have no reasonable prospect of recovering the funds. A tax professional can tell you whether your situation fits.