Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Operational Risk

$3 Billion in BEC Losses. 58% Recovery Rate. A Pending Federal Appeal That Could Change What Banks Pay Back.

The FBI IC3 2025 report shows $3.04 billion in business email compromise losses, with 86% moving by wire or ACH. A 2025 Fourth Circuit ruling narrowed bank liability under UCC Article 4A. The Second Circuit is now poised to decide whether the Electronic Fund Transfer Act gives consumers stronger recourse — a ruling that will reshape who absorbs the loss when a fraudulent wire clears.

By Rebecca Leung · August 18, 2026 ·
Table of Contents

TL;DR

  • The FBI IC3 2025 Annual Report: $3.04 billion in BEC losses from 24,768 complaints; 86% of funds moved by wire or ACH
  • The 58% “recovery rate” applies only to cases reported within hours — most victims recover nothing
  • Fourth Circuit (March 2025): banks protected by UCC 4A unless they had actual knowledge of a beneficiary name/account mismatch — negligence alone doesn’t create liability
  • Second Circuit (2026): pending ruling on whether EFTA gives fraud victims stronger recourse than UCC 4A — decision could fundamentally shift who absorbs wire fraud losses

Business email compromise is the second-largest cybercrime category in the United States by total dollar losses. The FBI’s 2025 IC3 Annual Report puts the 2025 total at $3.04 billion — up from $2.77 billion the year before. Eighty-six percent of those losses moved by wire transfer or ACH. The average incident: $123,000, gone in minutes.

What makes BEC different from most fraud categories is where the litigation risk falls. When a fraudulent wire clears, the bank that processed it may or may not be liable. The bank that received it may or may not be liable. The victim may or may not have any meaningful legal recourse at all — depending on which statute a court applies. Two federal circuit courts are now in the process of answering that question, and the answers are going in different directions.

The $3 Billion Problem and the 58% That’s Missing the Point

The FBI’s Recovery Asset Team (RAT) froze $679 million in BEC funds in 2025. Divided by the roughly $1.16 billion reported to them early enough to act, that’s a 58% freeze rate. Some coverage treats this as a success story.

It isn’t. Here is why:

The 58% figure applies only to cases where victims reported to the FBI within hours of discovering the fraud and where funds were still in transit. Most BEC victims don’t know they’ve been compromised until the expected payment fails to arrive or until someone calls to ask where the wire went. By then, the funds have been layered through multiple accounts — often moved offshore or converted to cryptocurrency within the first 24 hours.

The 24,768 BEC complaints in 2025 represent victims who reported to the FBI at all. Industry estimates of actual BEC incidence run far higher; many victims don’t report, both for reputational reasons and because they’ve been told recovery is unlikely.

What the $3 billion figure actually means for financial institutions: BEC is the primary mechanism through which fraudulent wires enter the banking system in volume. As the originating bank, the receiving bank, or — for fintechs — a payment service provider in the chain, your institution is involved in BEC incidents that don’t become visible until after the fraud is complete.

UCC Article 4A: The 1989 Framework That Governs Modern Wire Fraud

The legal framework most courts apply to wire transfer fraud disputes is UCC Article 4A, adopted in its original form in 1989. Article 4A was designed to create commercial certainty in wholesale wire transfers. Under the framework, a bank that follows commercially reasonable security procedures and accepts a payment order in good faith is generally protected from liability — even if the payment order turns out to be fraudulent.

Article 4A-207 is particularly important for BEC cases. Under 4A-207, a beneficiary bank — the institution that receives the fraudulent wire into the fraudster’s account — can rely on the account number provided in the payment order rather than the beneficiary name. If the account number is correct but the name is different (or if the name on the account doesn’t match the intended recipient), the beneficiary bank is not liable for the resulting loss — unless it had actual knowledge that the account number identified a different person.

This is a high bar. In most BEC cases, the receiving bank has no actual knowledge that anything is wrong. The fraudster has set up a legitimate-looking account, the wire arrives with a plausible business name, and the funds clear without triggering automated monitoring alerts. Under 4A-207, the receiving bank is protected even if, in retrospect, a more careful review might have identified the discrepancy.

The Fourth Circuit’s 2025 Decision: Actual Knowledge Required

On March 26, 2025, the U.S. Court of Appeals for the Fourth Circuit resolved a dispute that had drawn significant attention from compliance professionals and financial litigators. A district court had held a credit union liable for a BEC-related wire transfer loss. The Fourth Circuit reversed.

The Fourth Circuit’s reasoning was straightforward: UCC Article 4A-207 requires actual knowledge that the account number identifies a person different from the named beneficiary. A bank that did not flag the mismatch — even if it might have detected it with different monitoring — is not liable under the name/account number discrepancy provision if it lacked actual knowledge. Constructive knowledge (what the bank should have known) is insufficient; only actual knowledge creates liability.

For financial institutions, this ruling is protective. But the protection it provides is only as solid as the Article 4A framework itself — and that’s exactly what the Second Circuit case is now testing.

The Second Circuit: Is There a Stronger Framework for Victims?

The case before the Second Circuit asks a different question: does the Electronic Fund Transfer Act (EFTA) — which governs consumer electronic transactions and was codified into Regulation E — apply to wire transfers that were initiated fraudulently?

The stakes are significant. EFTA gives consumers more robust rights than UCC 4A in fraud scenarios. Under EFTA, an unauthorized electronic fund transfer requires the bank to reimburse the consumer — subject to notice requirements and liability caps based on how quickly the consumer reported. If EFTA applies to fraudulent wire transfers, victims of BEC that go through consumer accounts would have significantly stronger claims than Article 4A currently provides.

Banks and credit unions argue that UCC Article 4A — not EFTA — governs wire transfers, and that EFTA’s protections apply to debit card transactions, ACH transfers, and similar consumer payment products but not wholesale wire transfers. The Second Circuit must decide whether that distinction holds when the wire transfer is initiated fraudulently through access to a consumer account.

The result of this case will matter at scale. According to Mayer Brown’s analysis of the pending ruling, a Second Circuit holding that EFTA applies could create a circuit split with the Fourth Circuit’s Article 4A-first approach — and eventually require Supreme Court resolution. For every institution that processes consumer wire transfers, the applicable liability standard could shift meaningfully depending on which framework wins.

What This Means for Your Compliance and Fraud Program

The litigation is still developing, but the operational implications are clear now.

Callback verification needs to be more than a documented procedure. The most common gap in BEC investigations isn’t that institutions lack a callback policy — it’s that front-line staff skip the callback for familiar vendors, longstanding relationships, or urgent requests where a manager approves the exception. A callback verification procedure that isn’t followed creates evidence of what you should have done. Document your procedures, but also test whether they’re actually being executed.

“Commercially reasonable security procedures” is not static. Article 4A protects banks that follow commercially reasonable security procedures. What’s commercially reasonable has evolved: multi-factor authentication for wire initiators, dual control for wire releases above threshold, out-of-band confirmation for any payment order that includes a new or changed beneficiary account — these have become industry standard. If your procedures were last reviewed in 2021, they may no longer be commercially reasonable under current FFIEC guidance.

The 72-hour window is real. BEC incident response requires speed in a way that most incident types don’t. The FBI Recovery Asset Team’s freeze rate drops dramatically after the first 24-48 hours. Report to your bank and to IC3 immediately — not after the internal investigation is complete.

Monitor your AI-enhanced BEC threat landscape. The FBI’s 2025 report attributed more than $30 million in BEC losses specifically to incidents with a confirmed AI component — primarily voice cloning and synthetic email generation. The AI-enhanced BEC response playbook covers the detection signals that differ from traditional BEC. If your fraud detection is tuned for the 2022 BEC profile, it may be missing the AI-augmented version.

Understand your liability position for received wires. The Fourth Circuit has given receiving banks significant protection under UCC 4A-207. But that protection depends on your monitoring and actual knowledge — if your transaction monitoring flags a wire and an operator dismisses the alert without investigation, the “actual knowledge” question becomes more complicated. Document how flagged transactions are reviewed and resolved.

The BEC-Adjacent Issue: Authorized Push Payment Fraud

BEC often gets lumped with authorized push payment (APP) fraud — cases where a legitimate account holder is socially engineered into initiating a wire themselves, rather than having their credentials compromised. The Zelle ruling on authorized push payment fraud covers how courts have treated APP differently from BEC: when a customer authorized the payment (even under false pretenses), the bank’s liability exposure under EFTA is different than when the payment was unauthorized.

The distinction matters because BEC and APP fraud use similar social engineering techniques but create different legal profiles. A fraudster impersonating a vendor and sending a fake invoice that a controller pays — that’s APP fraud on the company side. A fraudster breaking into email and sending payment instructions from a compromised account — that’s BEC. Both result in a fraudulent wire. Only one falls cleanly within EFTA’s unauthorized transaction framework.

So What?

The legal landscape for BEC wire fraud liability is actively in flux. The Fourth Circuit has given banks clarity under UCC 4A — actual knowledge is the bar for liability, not constructive knowledge. The Second Circuit may add a layer that gives fraud victims access to EFTA’s stronger protections for consumer accounts. Neither ruling changes the operational reality: most BEC victims recover nothing, and the most effective control is stopping the fraudulent wire before it leaves.

The $3.04 billion in 2025 BEC losses are a compliance risk, an operational risk, and an emerging legal risk simultaneously. Institutions with documented, tested, current fraud controls are positioned better in all three dimensions — both for examiner scrutiny and for the litigation climate that’s developing around bank liability for fraud-related wire transfers.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How much did business email compromise losses total in 2025?
According to the FBI's 2025 Internet Crime Complaint Center (IC3) Annual Report, business email compromise generated $3,046,598,558 in losses from 24,768 complaints — an average of approximately $123,000 per incident. BEC was the second-largest cybercrime category by financial loss, behind investment fraud. Losses have risen steadily year over year: $2.77 billion in 2024, $3.04 billion in 2025.
What is the FBI's 58% recovery rate for BEC losses and why is it misleading?
The FBI's Recovery Asset Team (RAT) froze approximately 58% of funds in cases reported to them quickly enough to act — but that rate applies only to the subset of victims who reported the fraud within hours and where funds were still in transit. Most BEC victims don't realize the fraud occurred until days after the wire clears, by which point the funds have been moved multiple times. The 58% figure represents the best-case recovery scenario, not the average. Most BEC victims recover nothing.
What did the Fourth Circuit decide in 2025 about bank liability in BEC cases?
On March 26, 2025, the U.S. Court of Appeals for the Fourth Circuit reversed a district court that had held a credit union liable for a BEC loss. The Fourth Circuit ruled that under UCC Article 4A-207, a beneficiary bank that receives a wire transfer can rely on the account number rather than the beneficiary name, and is not liable for loss when there is a discrepancy between the name and account number — unless the bank had actual knowledge that the account number identifies a different person. This is a high bar: negligent failure to catch a discrepancy does not create liability; actual knowledge is required.
What is the Second Circuit BEC case and when will it be decided?
A case before the Second Circuit involves whether the Electronic Fund Transfer Act (EFTA) — and by extension Regulation E — provides consumers with stronger recourse than UCC Article 4A in wire fraud cases. The core question: does EFTA's unauthorized transaction framework apply when a consumer's account is accessed to initiate a fraudulent wire, even if UCC 4A ordinarily governs fund transfers? The Second Circuit was poised to rule in 2026. If the court holds that EFTA applies, consumers and businesses could have significantly stronger claims against banks that process fraudulent wires than UCC 4A currently allows.
What is UCC Article 4A and why does it matter for BEC liability?
UCC Article 4A is the Uniform Commercial Code article governing electronic fund transfers — wire transfers and similar payment orders. It was written in 1989, long before business email compromise was a defined threat category. Under 4A, a bank that follows commercially reasonable security procedures is generally not liable for authorized payment orders later discovered to be fraudulent. Article 4A was designed to give banks a clear liability framework; the question courts are now wrestling with is whether that framework leaves victims of sophisticated social engineering with no meaningful recourse.
What should my institution do now to manage BEC-related operational and legal risk?
Three immediate steps: First, confirm that your callback verification procedure for wire transfer requests is actually being followed — documented procedures that front-line staff skip are worse than no procedure (they create evidence of what you should have done). Second, document your commercially reasonable security procedures in writing, review them against current FFIEC guidance, and update them if they don't reflect the threat environment. Third, if you receive fraudulent funds, report to your institution's bank within hours and to the FBI's IC3 immediately — the Recovery Asset Team's 58% freeze rate is only achievable in the first window. Delays make recovery statistically near-impossible.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.