Carolina Risk Partners
Custom Homebuilder Insurance

Wire Fraud and Cybercrime in Custom Homebuilding

Business email compromise, or BEC, is fraud that uses a trusted email identity to redirect a real payment. For a custom homebuilder, the target may be a supplier invoice, subcontractor payment, homeowner draw, deposit, or closing wire. Cyber insurance does not automatically cover the loss. The specific cyber, crime, and social-engineering wording controls.

By Stephen Ellias, CLCS Commercial Lines Coverage Specialist (CLCS) NC Insurance Producer License #20374030 Published October 2, 2026 Last updated October 2, 2026

Quick Answer: How Does Wire Fraud Hit a Custom Homebuilder?

Wire fraud in custom homebuilding often begins with business email compromise. A criminal impersonates or takes over a trusted account and redirects a legitimate invoice, deposit, subcontractor payment, land transaction, or construction draw.

The fact that email, accounting software, or a computer was involved does not automatically make the loss covered. Social engineering fraud, fraudulent instruction, funds transfer fraud, computer fraud, commercial crime, or cybercrime provisions may respond differently.

Bottom line: verify the payment process and the insurance wording before money disappears.

Key Takeaways

  • A legitimate mailbox can be compromised, so a familiar email thread is not proof a payment change is legitimate.
  • Every change in banking instructions should be verified through a trusted contact method already on file.
  • Cyber liability, commercial crime, social engineering, computer fraud, and funds transfer fraud are different coverage concepts.
  • A fraud sublimit can be much smaller than the main cyber or crime policy limit.
  • After a fraudulent transfer, contacting the bank immediately can matter.

Established North Carolina custom homebuilders move money constantly. Material deposits, subcontractor invoices, cabinet packages, appliance orders, land transactions, construction draws, change orders, and final payments can all create opportunities for someone to insert fraudulent instructions into a legitimate business process.

What Is Business Email Compromise?

The FBI Internet Crime Complaint Center describes Business Email Compromise as a sophisticated scam targeting businesses and individuals who transfer funds. Criminals may compromise a legitimate email account through social engineering or computer intrusion and use it to cause an unauthorized transfer.

Sometimes the attacker creates a look-alike email address. In more sophisticated cases, the criminal gains access to a real mailbox, watches legitimate conversations, learns who approves payments, and waits for the right invoice or wire.

Business Email Compromise (BEC)
A fraud scheme using a trusted or impersonated business email identity to manipulate a legitimate transaction or payment.
Social Engineering Fraud
A person is deceived into voluntarily sending money, property, credentials, or information to a criminal.
Fraudulent Instruction
A deceptive communication that appears legitimate and directs someone to transfer money, change payment information, or take another financial action. The exact policy definition varies.
Funds Transfer Fraud
A fraudulent instruction causes a financial institution to move funds without proper authorization, subject to the policy’s definition.
Computer Fraud
Fraudulent use of a computer or system causes a transfer or loss, subject to the policy’s required connection between the computer event and the loss.
Cybercrime Coverage
A broad label sometimes used for insurance addressing specified digital theft or fraud events. It is not one standardized coverage form, so the actual insuring agreements matter.
Sublimit
A smaller maximum amount of insurance available for one specific category of loss inside the larger policy limit.
Retention
The amount the insured is responsible for before applicable coverage begins paying, similar to a deductible.
24,768 BEC complaints and $3.046 billion in reported losses in 2025

The FBI’s 2025 Internet Crime Complaint Center report recorded 24,768 Business Email Compromise complaints and $3,046,598,558 in reported BEC losses nationwide.

These are national IC3 complaint figures across industries. They are not construction-only statistics.

View the FBI 2025 IC3 Annual Report

How Can Wire Fraud Reach a Custom Homebuilder?

Supplier Bank Change

A supplier email says future invoices should be paid to a new account.

Subcontractor ACH Change

Accounting receives revised ACH information immediately before a large subcontractor payment.

Builder Impersonation

A homeowner receives fraudulent deposit or draw instructions that appear to come from the builder.

Executive Approval Fraud

An attacker impersonates an owner or executive and pressures accounting to release funds quickly.

Land or Closing Transaction

Fraudulent instructions appear during a lot purchase, closing, lender transaction, or other large transfer.

Compromised Email Thread

The attacker enters a real mailbox and waits for a legitimate invoice conversation before changing the banking details.

Plain-English version: the dangerous email may contain the correct project, invoice amount, supplier name, and conversation history. The payment instructions can still be fraudulent.

Has Business Email Compromise Hit Construction Payments?

Yes. The FBI has documented a case involving a Texas school district that was building a new elementary school. An employee received fraudulent wiring instructions from a scammer impersonating the construction company and nearly $2 million was sent to the criminals.

That case was not a custom-home project, but the payment mechanism is directly relevant to construction: a legitimate project, an expected construction payment, and an attacker impersonating a known project participant.

Read the FBI construction-payment BEC example .

What Can a Custom Homebuilder Wire Fraud Loss Look Like?

Illustrative Scenario: The $86,000 Supplier Payment

A builder is finishing a custom home and owes a supplier $86,000. Accounting receives a message inside an existing email conversation saying the supplier recently changed banks.

The project is correct. The invoice is correct. The signature block looks normal. Updated banking information is attached on the supplier’s letterhead.

The builder sends the payment. Two days later, the real supplier asks why the invoice is still outstanding.

In this illustration, the supplier’s mailbox had been compromised and the criminal waited for a real payment conversation before inserting new instructions.

The control that matters: verify every change in banking instructions with a known person using a phone number or contact method already in your records. Do not use the phone number supplied in the email requesting the change.

Which Insurance Policy May Respond to Wire Fraud?

How Common Builder Policies Differ When Money Is Stolen Electronically
Coverage What it may address Main issue to verify Limit or sublimit note
Social engineering fraud An employee is deceived into voluntarily sending money to an impostor. Separate insuring agreement or endorsement, verification requirements, and retention. Carrier-specific. Chubb’s published materials illustrate how available limits can vary materially by underwriting and product structure.
Fraudulent instruction A deceptive instruction appears legitimate and causes a payment or change in payment details. Who sent the instruction, who acted on it, and the policy definition. Policy-specific. Verify whether a separate sublimit applies.
Funds transfer fraud A fraudulent instruction causes a financial institution to transfer money without proper authorization. Whether the insured actually authorized the transfer and how the instruction reached the bank. Policy-specific. Do not assume it shares the social-engineering limit.
Computer fraud Fraudulent computer activity directly causes a covered transfer or loss. The required causal connection between system access and the transfer. Policy-specific. Coverage may sit in a crime or cyber form.
Cyber liability / cybercrime May include breach response, ransomware, network events, and specified financial-fraud coverages. Whether financial fraud is actually included rather than assumed from the word “cyber.” The core cyber limit may not be the limit available for fraudulent transfers.
Commercial crime May include employee theft, forgery, computer fraud, funds transfer fraud, and social engineering by endorsement. Which insuring agreements are actually included. Separate limits can apply to different crime coverages.
General liability Primarily certain third-party bodily injury, property damage, and personal and advertising injury liability claims. It is generally not designed to reimburse the builder’s own money lost in a fraudulent transfer. Not a substitute for cybercrime or commercial crime coverage.
Builders risk Covered physical loss to property under construction. Electronic theft of money is different from physical damage to the project. Not a substitute for financial-fraud coverage.

Does Cyber Insurance Automatically Cover Wire Fraud?

No.

A policy can say “cyber” on the declarations and still handle a fraudulent payment under a separate insuring agreement, endorsement, crime policy, or sublimit.

The important question is how the money actually left the account.

Example: an employee who is fooled into voluntarily approving a payment can present a different coverage issue from a criminal who directly sends an unauthorized transfer instruction to the bank.

How Much Social Engineering Coverage Can Be Available?

There is no universal social-engineering limit. Available limits depend on the insurer, policy form, company controls, underwriting, requested limits, and the structure of the cyber or crime program.

Published carrier example, not a market-wide range: as of October 2026, Chubb’s public social-engineering webpage states that coverage is available up to $250,000 per occurrence, with higher limits considered through additional underwriting. A newer Chubb social-engineering guide states that primary limits up to and beyond $1 million may be available subject to underwriting, with excess capacity also available.

Those published Chubb figures illustrate why it is risky to quote one “typical” social-engineering limit for every builder. The practical comparison is between the amount of fraud coverage actually offered and the size of payments the builder routinely sends.

Chubb social engineering fraud coverage · Chubb’s newer social engineering fraud guide

Stephen Ellias, founder of Carolina Risk Partners
Stephen Ellias, CLCS Founder · Commercial Lines Coverage Specialist · NC Producer #20374030
Check the Fraud Limit Before Someone Tests It

I can review the cyber and crime policies for social engineering, fraudulent instruction, computer fraud, funds transfer fraud, limits, retentions, and major gaps.

Start with the basics. I can tell you what policy pages I need after I review your request.

Prefer to send the policy now? Email the declarations or quote directly .

What Should a Custom Homebuilder Check in the Cyber or Crime Policy?

  • Is social engineering fraud or fraudulent instruction specifically covered?
  • What limit or sublimit applies?
  • What deductible or retention applies?
  • Is computer fraud included?
  • Is funds transfer fraud included?
  • Does coverage require a specific callback or verification procedure?
  • How does the policy treat voluntary transfers induced by deception?
  • Does the policy protect only the insured’s money, or can certain third-party funds qualify?
  • How do the cyber and commercial crime policies coordinate?
  • What notice requirements apply after a suspected loss?

What Payment Controls Should an Established Custom Builder Use?

For builders in Raleigh, Wake Forest, Durham, Cary, and elsewhere in North Carolina, the insurance policy should be the backstop. The stronger outcome is preventing the money from leaving in the first place.

The Cybersecurity and Infrastructure Security Agency recommends multifactor authentication for sensitive business systems. The FBI also recommends using secondary channels to verify changes in account information.

What Should You Check Before Approving New Wire Instructions?

Not ready for a policy review? Run through this process before approving a new or changed wire or ACH instruction.

  • Stop: treat every new or changed bank account as unverified.
  • Call: contact the vendor, subcontractor, client, attorney, or lender using a phone number already on file.
  • Confirm: verify the bank name, account information, payment amount, and reason for the change.
  • Separate duties: do not let one person both change banking information and release a large payment without another approval.
  • Document: record who verified the change, when it was verified, and which trusted contact method was used.
  • Escalate: if the request is urgent, unusual, secretive, or inconsistent with normal procedure, stop the payment until it is independently confirmed.

Simple company rule: banking instructions do not change by email alone.

Want to compare that process against the insurance policy? Start a wire-fraud coverage review.

What If the Criminal Impersonates the Builder and Steals the Homeowner’s Money?

Imagine an attacker compromises the builder’s mailbox and sends a homeowner fraudulent instructions for the next construction draw. The homeowner follows those instructions and sends the money to the criminal.

The builder may not have suffered the direct theft of its own funds, but the incident can still lead to a dispute about responsibility, forensic expenses, a compromised-email investigation, possible privacy issues, legal expenses, and damage to the customer relationship.

The coverage review therefore needs to separate direct financial-fraud protection from broader cyber liability and breach-response coverage.

Can AI Make Business Email Compromise More Convincing?

Yes.

The FBI’s 2025 IC3 report recorded 22,364 complaints containing AI-related information and approximately $893 million in reported losses associated with those complaints.

Most of that AI-related loss was not BEC. Investment fraud accounted for about $632 million. For BEC specifically, the FBI reported more than $30 million in losses from scams involving AI in 2025 and described the use of generated executive emails and cloned voices in fraudulent wire requests.

Operational lesson: recognizing a person’s writing style or even hearing a familiar voice should not override the company’s payment-verification procedure.

What Does the FBI Data Show for North Carolina?

North Carolina Reported $431.6 Million in Internet-Crime Losses in 2025

The FBI’s 2025 IC3 report recorded 25,940 North Carolina complaints and $431,561,716 in reported losses across all internet-crime categories.

The FBI’s published state tables do not provide a separate 2025 North Carolina BEC total, so those statewide figures should not be presented as BEC-specific data.

Read the FBI 2025 IC3 report .

There is also direct North Carolina BEC history. In a federal case handled by the Western District of North Carolina, prosecutors described a business email compromise scheme that defrauded a North Carolina university of more than $1.9 million.

That case was not a homebuilder loss, but it provides a concrete North Carolina example of the same payment-redirection mechanism. Read the Department of Justice case summary .

What Should a Builder Do Immediately After Discovering a Fraudulent Wire?

  1. Contact the sending financial institution immediately and ask it to attempt to recall, freeze, or stop the transfer.
  2. Provide the receiving-bank information and transaction details.
  3. Report the incident through FBI IC3.
  4. Notify the appropriate cyber or crime insurer promptly.
  5. Preserve emails, attachments, transaction records, message headers, and other evidence.
  6. Reset credentials for compromised accounts and revoke active sessions.
  7. Review mailbox rules, forwarding settings, and delegated access.
  8. Have the IT provider determine what systems or accounts were actually compromised.
  9. If personal information may have been accessed, involve the cyber carrier or appropriate legal counsel to evaluate notification obligations.
  10. Document the timeline while events are still fresh.

The FBI advises BEC victims to contact their financial institution immediately. Recovery can become harder once stolen funds move through additional accounts.

When Should a Custom Homebuilder Review Wire-Fraud Coverage?

  • The company regularly makes large wire or ACH payments.
  • Several employees can change vendor banking information.
  • The builder has grown from owner-controlled payments to a separate accounting department.
  • The company is managing several custom homes at the same time.
  • Average project values or supplier deposits have increased.
  • Homeowners receive electronic payment instructions from the builder.
  • A vendor, subcontractor, employee, or client recently experienced an email compromise.
  • The company has cyber insurance but has never checked its social-engineering limit.
  • The cyber and commercial crime policies are written separately.
  • Renewal is approaching and limits or endorsements can still be reviewed.

What Is the Real Insurance Question for a Custom Homebuilder?

It is not simply, “Do we have cyber insurance?”

The better question: if someone tricks our accounting team, a homeowner, or a project partner into sending money to the wrong account, which coverage applies, what is the available limit, what retention applies, and what verification procedures were we required to follow?

That question forces the insurance policy and the company’s actual payment process to be reviewed together.

What Other Insurance Resources Should North Carolina Builders Review?

Frequently Asked Questions About Wire Fraud in Custom Homebuilding

What is business email compromise?

Business email compromise is a fraud scheme where a criminal impersonates or compromises a trusted email identity and uses it to manipulate a legitimate payment or business transaction.

Does cyber insurance cover a fraudulent wire transfer?

It may, but the answer depends on the insuring agreements and facts of the loss. Social engineering, fraudulent instruction, computer fraud, funds transfer fraud, cybercrime, or commercial crime provisions may be relevant.

What is a social-engineering sublimit?

It is the maximum amount available for that specific type of fraud. The social-engineering limit can be lower than the overall cyber or crime policy limit.

What if a subcontractor’s real email account is hacked?

A compromised mailbox can make the fraud difficult to recognize. Coverage still depends on how the payment was authorized, which account was compromised, the policy definitions, and the applicable cyber or crime insuring agreement.

Does general liability cover the builder’s money lost through wire fraud?

General liability is generally not designed to reimburse the builder’s own stolen funds. Commercial crime, cybercrime, social-engineering, computer-fraud, or funds-transfer provisions are more relevant places to look.

What is the most important control for changed banking instructions?

Independently verify the change with a known contact through a trusted phone number or other contact method that existed before the request arrived.

What should a North Carolina custom homebuilder send for a wire-fraud coverage review?

Start with the cyber policy or quote, commercial crime policy if there is one, declarations pages, relevant fraud endorsements, and any current payment-verification requirements. The review should compare those documents against the size and type of electronic payments the builder actually makes.

Stephen Ellias, founder of Carolina Risk Partners

About Stephen Ellias, CLCS

Stephen Ellias is the founder of Carolina Risk Partners, an independent commercial insurance agency based in Wake Forest, North Carolina. CLCS stands for Commercial Lines Coverage Specialist.

Stephen works with North Carolina contractors and custom homebuilders on commercial insurance programs, coverage gaps, policy structure, renewals, carrier options, and construction-specific risk issues.

NC Insurance Producer License #20374030 · North Carolina Department of Insurance licensing resources

Carolina Risk Partners LLC
123 S White Street, Suite 203
Wake Forest, NC 27587
stephen@carolinariskpartners.com · (919) 910-4554

About Stephen · Client reviews · LinkedIn

Moving Large Payments for Custom Homes?

Check the cyber and crime coverage before a fraudulent payment request shows you what the policy actually does.

Stephen Ellias, founder of Carolina Risk Partners
Stephen Ellias, CLCS Founder · Independent commercial insurance agency · Wake Forest, NC

No paperwork is required to start. I will follow up within 1 business day.

Already have the cyber or crime policy? Email the PDF directly .

This article provides general insurance and risk-management information and is not a coverage determination, legal advice, banking advice, or cybersecurity consulting. Cyber, commercial crime, social-engineering, computer-fraud, fraudulent-instruction, and funds-transfer coverage vary by insurer, policy form, endorsement, limit, sublimit, retention, security controls, and the facts of a particular loss. Actual coverage is determined by the applicable policy language and circumstances of the claim.