Cyber & technology risk

Business Email Compromise Insurance: What to Document Before You Assume Coverage

Respond to a compromised or spoofed business email account while preserving evidence needed for banking, incident response, and insurance review. Practical U.S. small-business guidance.

By Morgan Reyes · Source-checked · Updated Aug. 19, 2026 · U.S. focus · Educational information
Quick answer

Business email compromise covers a range of different events — account takeover, domain spoofing, fraudulent payment instructions, credential theft — and the applicable insurance depends on which one actually happened. A cyber policy may address incident-response and breach costs; crime or social-engineering coverage may be relevant if funds moved. Secure the account first, preserve the technical evidence, and describe the actual mechanism before guessing at a coverage label.

Search intentRespond to a compromised or spoofed business email account while preserving evidence needed for banking, incident response, and insurance review.
Primary topicbusiness email compromise insurance coverage

"Business email compromise" describes several different events

The phrase covers everything from an attacker fully taking over a mailbox, to a lookalike domain sending emails that were never actually inside the real account, to credentials being harvested and reused elsewhere without any visible activity in the mailbox itself. Each version leaves different evidence and triggers different parts of a policy.

Before deciding what kind of claim this is, establish which of those actually occurred — a question that usually needs the mail platform's sign-in logs and admin console, not just the appearance of the messages themselves.

No stolen money does not mean no loss

A marketing agency's owner account is taken over, and the attacker sends fake payment instructions to one of the agency's own clients. The agency's own bank account is never touched. But the agency still faces forensic costs to confirm the scope of the takeover, time spent on customer communications and reputational cleanup, and now a demand letter from the client who was targeted through the agency's compromised account.

Those are at least three different categories of cost — incident response, notification, and a possible third-party claim — sitting inside one event, which is exactly why a single generic "was this covered" question is hard for an insurer to answer without more detail.

Logs beat memory and screenshots

Preserve mailbox audit logs, sign-in records with IP addresses and timestamps, forwarding-rule changes, domain and DNS records if spoofing is suspected, MFA status at the time of the incident, and the actual payment records if any funds moved. Original exports from the platform hold up far better than screenshots taken after the fact.

  • Mailbox sign-in and audit logs, exported directly from the platform
  • Any forwarding-rule or mailbox-permission changes made during the window
  • Domain and DNS records if a lookalike domain was involved
  • MFA status and method for the affected account at the time
  • Payment records only if funds actually moved
  • Client and vendor communications sent during the incident

Reset the account without erasing the evidence

The instinct to immediately reset passwords and lock everything down is correct from a security standpoint, but doing it before exporting logs can destroy the record an insurer or forensic investigator needs. Where possible, export or preserve logs first, or work with an incident-response vendor who can do both at once.

Primary and regulator sources used

We use government, regulator, and other primary sources for insurance mechanics, state-authority routing, worker-classification, property, claims, and cyber-security guidance. Policy language and state rules still control your specific situation.

Frequently asked questions

Is business email compromise always a cyber insurance claim?

Not automatically. Depending on whether funds moved, whether the account was actually accessed, and whether a third party was harmed, the relevant coverage can be cyber, crime, or both.

What is the single most useful piece of evidence after a suspected compromise?

Mailbox sign-in and audit logs exported directly from the platform. They show what actually happened technically, in a way screenshots and memory cannot reliably reconstruct later.

Should we reset the compromised account immediately?

Security comes first, but if possible export or preserve the logs before or during the reset rather than after — a full lockdown can overwrite the evidence a claim later depends on.

Keep researching

Related guides and tools

Free tools

Turn this article into an action list

Use our downloadable checklists, worksheets, and fillable PDF forms to review a contract, compare quotes, track COIs, prepare for renewal, or document a loss.

Browse free templates