Who is legally responsible when a company wires money to a fraudster after a spoofed email?
In the ordinary case, the company that issued the payment order. A business email compromise is a fraud on the sender’s judgment rather than on its banking credentials: someone inside the company, believing the new instructions are genuine, authorizes a real payment order through the bank’s real channel. Uniform Commercial Code Article 4A, which governs commercial funds transfers, is built around the premise that such orders are processed automatically and at volume, and it allocates the risk accordingly.
The Fourth Circuit put the design plainly in Studco Building Systems US, LLC v. 1st Advantage Federal Credit Union, No. 23-1148 (4th Cir. Mar. 26, 2025), quoting the Seventh Circuit: “At bottom, Article 4[A] provides a framework for facilitating complicated transactions between sophisticated parties with competing interests.” The chain runs from an originator, to a receiving bank, to a beneficiary’s bank, to a beneficiary, each link carrying defined rights and duties under Va. Code §§ 8.4A-103 to -104 rather than a general duty of care.
So the first thing to establish is which link is being blamed, and under which section. Article 4A is not a negligence statute, and the instinct to plead that a bank should have caught the fraud runs into provisions written to foreclose that argument. The technical work — who issued what order, from which mailbox, using which credentials, after what change to the banking instructions — is the same link-by-link exercise set out in breach causation.
What does Article 4A say about security procedures and unauthorized payment orders?
Section 4A-202 makes a payment order effective as the customer’s order, even if the customer did not issue it, where a security procedure was in place and two conditions are met. Virginia’s enactment, Va. Code § 8.4A-202(b), requires that “the security procedure is a commercially reasonable method of providing security against unauthorized payment orders” and that “the bank proves that it accepted the payment order in good faith and in compliance with the bank’s obligations under the security procedure.” Section 8.4A-202(c) makes commercial reasonableness “a question of law to be determined by considering the wishes of the customer expressed to the bank, the circumstances of the customer known to the bank, including the size, type, and frequency of payment orders normally issued by the customer to the bank, alternative security procedures offered to the customer, and security procedures in general use by customers and receiving banks similarly situated.”
Section 4A-203 supplies the customer’s counter-move. Under Va. Code § 8.4A-203(a)(2), the bank cannot enforce or retain payment if the customer proves that the order “was not caused, directly or indirectly, by a person (i) entrusted at any time with duties to act for the customer with respect to payment orders or the security procedure, or (ii) who obtained access to transmitting facilities of the customer or who obtained, from a source controlled by the customer and without authority of the receiving bank, information facilitating breach of the security procedure, regardless of how the information was obtained or whether the customer was at fault.”
The practical significance is easy to miss. These two sections do their work when the fraudster issues the order, through stolen banking credentials or a hijacked treasury session. In the classic business email compromise, where an employee of the customer issues the order believing forged instructions, the order is authorized within the meaning of Va. Code § 8.4A-202(a), and the commercially reasonable security procedure analysis does not reach it. Distinguishing those two fact patterns from the forensic record is a threshold question, and it depends on evidence discussed in what disappears first after a breach.
Can the receiving bank be held liable for depositing into an account whose name does not match?
Only where the beneficiary’s bank actually knew the name and number identified different people, which is a demanding standard. Va. Code § 8.4A-207(b)(1) provides that where a payment order identifies the beneficiary both by name and by an account number and the two identify different persons, if “the beneficiary’s bank does not know that the name and number refer to different persons,” the bank “may rely on the number as the proper identification of the beneficiary of the order,” and it “need not determine whether the name and number refer to the same person.”
Studco tested that provision on facts that recur constantly. Studco received a fraudulent email purporting to come from its steel supplier, changed its banking instructions, and sent a series of automated clearing house payments naming the supplier as beneficiary while carrying an account number belonging to an unrelated individual at 1st Advantage Federal Credit Union. On the trial evidence recited by the Fourth Circuit, each deposit automatically generated a report carrying a name-mismatch warning, no one at the credit union read those reports before Studco reported the scam, and the credit union did not review them as a matter of course. After a bench trial the district court found for Studco. The Fourth Circuit reversed, holding that “knowledge” under Va. Code § 8.1A-202(b) means actual knowledge, not what due diligence would have produced, and that “[t]he beneficiary’s bank therefore has no duty to adopt reasonable routines to check for conflicting names.”
The opinion also quotes the Official Commentary on where the loss then sits. Article 4A places the risk of loss on “the person who dealt with the thief,” whose remedy runs against the recipient of the funds, the fraudsters, or potentially the receiving bank, because “it is not unfair to assign the loss to . . . the person who dealt with the impostor and . . . supplied the wrong account number.” That allocation is written into the statute rather than into case law a court can distinguish.
Does the Uniform Commercial Code impostor rule apply to a business email compromise?
Not by the terms of the sections themselves, because the impostor rule sits in Article 3 and Article 3 states its own subject matter. Virginia’s enactment at Va. Code § 8.3A-102(a) provides that “[t]his title applies to negotiable instruments” and that “[i]t does not apply to money, to payment orders governed by Title 8.4A, or to securities governed by Title 8.8A.” The impostor rule sits in that title: Va. Code § 8.3A-404(a) provides that where “an impostor, by use of the mails or otherwise, induces the issuer of an instrument to issue the instrument to the impostor . . . by impersonating the payee of the instrument or a person authorized to act for the payee,” an endorsement in the payee’s name is effective in favor of a person who in good faith pays the instrument or takes it for value, and subsection (d) then allows the party bearing the loss to recover from a person who failed to exercise ordinary care in a way that substantially contributed to it. That is what these sections say about their own scope; no decision read for this piece states that the impostor rule does or does not reach a funds transfer, and the point is offered as statutory text rather than as a holding.
Courts have nonetheless reached for Article 3’s reasoning by analogy where two innocent businesses are fighting over a redirected payment. In Beau Townsend Ford Lincoln, Inc. v. Don Hinds Ford, Inc., No. 17-4177 (6th Cir. Nov. 27, 2018), an unpublished decision applying Ohio law, a hacker inside a seller’s email account sent the buyer fraudulent wiring instructions for a fleet purchase, and the buyer paid the fraudster. The district court granted summary judgment for the seller on the reasoning that it had not been paid. The Sixth Circuit reversed, holding that if Article 3 principles are applied “the court would have to determine whether either Beau Townsend’s or Don Hinds’ failure to exercise ordinary care contributed to the hacker’s success, and would then have to apportion the loss according to their comparative fault.”
The panel drew the same principle from two district court decisions it discussed, Arrow Truck Sales, Inc. v. Top Quality Truck & Equipment, Inc., 2015 WL 4936272 (M.D. Fla. Aug. 18, 2015), and Bile v. RREMC, LLC, 2016 WL 4487864 (E.D. Va. Aug. 24, 2016): “losses attributable to fraud should be borne by the party in the best position to prevent the fraud.” It also held the question cannot be resolved on summary judgment, because “to make findings of fact, the district court must hold a trial.” That is why these disputes turn on the contemporaneous record of who was warned, who verified, and when.
Do Regulation E consumer protections help a business that was defrauded?
Generally not, on two independent grounds in the text of the regulation. Regulation E, 12 C.F.R. Part 1005, implements the Electronic Fund Transfer Act, and § 1005.3(a) states that “[t]his part applies to any electronic fund transfer that authorizes a financial institution to debit or credit a consumer’s account.” Section 1005.2(b)(1) in turn defines an account as a “demand deposit (checking), savings, or other consumer asset account . . . established primarily for personal, family, or household purposes,” so a company’s operating account falls outside the definition and the error resolution and unauthorized transfer provisions that consumers rely on are not engaged at all.
The second ground is narrower and applies even to consumers. Section 1005.3(c)(3) excludes from the definition of electronic fund transfer “[a]ny transfer of funds through Fedwire or through a similar wire transfer system that is used primarily for transfers between financial institutions or between businesses.” A wire is outside Regulation E by its own terms. The exclusions are drawn by mechanism as well as by account type, which is one reason the same fraud pattern produces different answers depending on the rails it traveled on.
This confuses people in the first days of a matter, because the popular understanding of payment fraud is built on consumer card and account experience, where the loss commonly does move to the institution. Commercial funds transfers run on a different statute with a different allocation. Whether any consumer-facing statute or a state unfair practices act supplies a separate theory is a question of law for counsel on the specific facts.
What do the insurance coverage disputes over business email compromise turn on?
On which insuring agreement in a commercial crime policy the loss fits, and on how directly the computer use caused the loss, in the two decisions below. In American Tooling Center, Inc. v. Travelers Casualty & Surety Co. of America, 895 F.3d 455 (6th Cir. 2018), decided July 13, 2018, a manufacturer wired payments to an impersonator after intercepted correspondence with its vendor. The policy covered “the Insured’s direct loss of, or direct loss from damage to, Money, Securities and Other Property directly caused by Computer Fraud.” Applying Michigan law, the Sixth Circuit rejected each of the insurer’s three arguments — that there was no direct loss, that this was not computer fraud, and that any loss was not directly caused by computer fraud — and held “that ATC’s loss is covered by the Policy and none of the asserted Policy exclusions apply,” reversing the district court’s grant of summary judgment to the insurer and granting summary judgment to the insured.
Other courts have read similar wording the other way, usually through the sublimits. In Mississippi Silicon Holdings, LLC v. AXIS Insurance Co., No. 20-60215 (5th Cir. Feb. 4, 2021), an unpublished per curiam decision applying Mississippi law, a manufacturer’s chief financial officer acted on emailed instructions to reroute payments to a new account. The insurer paid the claim under the policy’s social engineering fraud provision, which carried a far lower limit, and denied that the computer transfer fraud and funds transfer fraud provisions applied, on the ground that the funds were transferred with the employees’ knowledge and the fraud was therefore not confined to the computer system as the policy required. The district court granted summary judgment to the insurer, and the Fifth Circuit affirmed, agreeing that the insured was not entitled to coverage under the computer transfer fraud provision.
Whether a business email compromise is treated as computer fraud or as social engineering is a question of policy wording and of state contract law, not of security posture, and the two characterizations can carry very different limits under the same policy. What the coverage analysis needs from the technical side is a precise account of how the instructions arrived, whether any system of the insured or of its counterparty was actually compromised, and who touched the payment — the same account that decides the Article 4A questions above. Establishing it depends on mailbox audit logs, mail flow rules and authentication records, which expire on their own schedules; the Institute sets out that work at evidence preservation.