Click to toggle navigation menu.

Corporate Account Takeover: Who Bears the Loss When a Business Bank Account Is Drained

< BACK

By Ryan Windt | Head of Growth Marketing | Updated August 2026


A business logs in one morning to find several hundred thousand dollars gone, moved out through a series of transfers nobody at the company authorized. The credentials were stolen weeks earlier through a phishing email, and an attacker used them to initiate payments that looked, to the bank’s systems, entirely legitimate. This is corporate account takeover, and the first question everyone asks is the wrong one.

The wrong question is whether the bank will simply put the money back. Most business owners assume the protections they have as consumers carry over to their company accounts. They do not. A business that suffers account takeover is standing on completely different legal ground than an individual, and where the loss lands is decided by rules most companies have never read, long before any insurance policy is consulted.

Understanding who bears a corporate account takeover loss means understanding two things in order: the legal framework that allocates the loss between the bank and the business, and then the insurance that may respond once that allocation is settled. Getting the first part wrong is how businesses end up absorbing a loss they assumed someone else would cover.

This article explains a general framework. It is not legal advice, and the outcome of any specific loss depends on the facts, the account agreement, and applicable law. Businesses facing an actual loss should consult counsel.


What Corporate Account Takeover Looks Like

Corporate account takeover follows a consistent pattern. An attacker obtains a business’s online banking credentials, usually through phishing, a malicious link, or malware that captures keystrokes or session tokens. With those credentials, the attacker initiates outbound payments, typically ACH transfers or wires, routed to accounts they control or to money mules who move the funds quickly beyond recovery.

What makes these losses so hard to unwind is that the payment instructions are technically authenticated. The attacker used real credentials. To the bank’s systems, the transfer looked like it came from the customer. There was no forged signature and no obvious system breach on the bank’s side. That single fact, an authenticated but fraudulent instruction, is what drives the entire liability analysis.


The Consumer Protection a Business Does Not Have

The most important thing a business can understand about account takeover is that it is not a consumer. Individual consumers are protected by Regulation E, which sharply limits a consumer’s liability for unauthorized electronic transfers and puts the burden on the bank to make the customer whole in most circumstances. That is the protection people are thinking of when they assume the bank will simply reverse the fraud.

Regulation E does not apply to commercial accounts. Business banking relationships are governed instead by Article 4A of the Uniform Commercial Code and by the account agreement the business signed. The default assumption flips: instead of the bank generally bearing the loss, the loss can fall on the business depending on how the transfer was handled.

Regulation E protects consumers and puts most unauthorized-transfer losses on the bank. Business accounts are governed by UCC Article 4A, where the loss can shift to the customer. Assuming consumer-style protection is the single most expensive mistake a business makes here.


How UCC Article 4A Allocates the Loss

Article 4A builds its loss allocation around the concept of a commercially reasonable security procedure. The framework, in general terms, works like this. A bank and its business customer agree on a security procedure for verifying payment orders, things like multi-factor authentication, transaction limits, dual authorization, or out-of-band confirmation. If that procedure is commercially reasonable, and the bank accepts a payment order in good faith and in compliance with the agreed procedure, the bank can generally treat the order as authorized even if it turns out to be fraudulent. In that situation, the loss can shift to the customer.

If the security procedure was not commercially reasonable, or the bank did not actually follow it, or the bank did not act in good faith, the loss generally stays with the bank. So the entire question often turns on whether the security procedure met the standard and whether the bank honored it.

Commercially reasonable is a fact-specific standard rather than a fixed checklist. It considers the wishes of the customer expressed to the bank, the circumstances of the customer including the size, type, and frequency of its normal payment orders, and the alternative procedures the bank offered and the customer declined. A procedure a small business waved off as inconvenient can become the exact reason the loss lands on that business later.


The Role of the Account Agreement

Article 4A sets the default rules, but the treasury management or cash management agreement the business signed frequently modifies them. These agreements often require the customer to adopt specific controls, to review and report unauthorized activity within a defined window, and to accept responsibility if it declines offered security measures. Missing a reporting deadline in that agreement can forfeit rights the business would otherwise have had.

The practical takeaway is that a business cannot assess its exposure by reading Article 4A alone. The agreement it signed with its bank often shifts more of the risk onto the business than the default rules would, and it is usually the first document a bank points to when a loss is disputed.


Where Insurance Picks Up for the Business

Once the legal allocation is settled, insurance is what stands between the business and the portion of the loss it has to bear. This is where a business that assumed the bank would cover everything discovers whether it prepared for the alternative.

The relevant coverage usually lives in a cyber policy’s funds transfer fraud or computer fraud provisions, or in a commercial crime policy. The critical detail is that these coverages are frequently sublimited well below the full policy limit, and their triggers differ. Computer fraud coverage may require the fraud to involve a manipulation of the system, while the more common social engineering scenario, where a person is deceived into acting, may fall under a separate and smaller social engineering sublimit, if it is covered at all.

A corporate account takeover driven by stolen credentials can sit awkwardly across these definitions. Whether it reads as computer fraud, funds transfer fraud, or social engineering depends on exactly how the loss occurred and how the policy is worded, and the answer determines both whether it is covered and at what limit.


Where Insurance Picks Up for the Bank

Banks face their own version of this analysis. When Article 4A shifts the loss to the customer because a commercially reasonable procedure was followed, the bank may have no direct financial loss to insure. When the loss stays with the bank, its financial institution bond and any computer crime rider may respond, subject to the same trigger questions that make the bond and cyber coverage coordinate imperfectly.

The bank’s stronger protection is upstream. Documented, commercially reasonable security procedures that the bank consistently follows are both the thing that can shift a loss to the customer under Article 4A and the thing an underwriter and a court will scrutinize afterward. For a bank, the security procedure is not just a control; it is the pivot the entire loss allocation turns on.


A Realistic Loss Scenario

A business customer’s controller is phished, and the attacker uses the captured credentials to push a fraudulent ACH batch of $400,000 over two days. The bank had offered dual authorization and transaction alerts, which the customer declined as too cumbersome. Here is roughly how the pieces sort out:

QuestionLikely outcome
Does Regulation E require the bank to reimburse?No. It is a commercial account, outside Reg E.
Does Article 4A shift the loss to the customer?Possibly, if the offered procedure was commercially reasonable and the customer declined it.
Does the account agreement affect it?Often yes, frequently reinforcing the customer’s responsibility.
Does the business’s cyber or crime policy respond?Possibly, often within a funds transfer or social engineering sublimit below the full loss.
Does the bank have an insurable loss?Often no, if the loss shifted to the customer.

The business in this scenario can end up bearing most of a $400,000 loss: no Regulation E, a plausible Article 4A shift, an account agreement that reinforces its responsibility, and a cyber sublimit that covers only a fraction. The declined security procedure is what ties every one of those outcomes together.


What This Means for Both Sides

For a business, the lesson is that the bank is not a backstop for commercial account takeover. Accept the security procedures the bank offers rather than declining them for convenience, read the treasury management agreement for reporting deadlines and risk-shifting language, and confirm that the funds transfer and social engineering limits on the cyber or crime policy are sized to a realistic loss rather than left at a token sublimit.

For a bank, the lesson is that the security procedure is the whole ballgame. Offering commercially reasonable procedures, documenting what the customer accepted or declined, and consistently following them is what determines where a loss lands and how well the bank’s own position holds up under scrutiny.


Frequently Asked Questions

Does the bank have to reimburse a business for account takeover fraud?

Not the way it generally must for a consumer. Regulation E does not apply to commercial accounts. A business account is governed by UCC Article 4A and the account agreement, under which the loss can shift to the business depending on the security procedures in place.

What makes a security procedure commercially reasonable?

It is a fact-specific standard, not a fixed list. It considers the customer’s expressed wishes, the size and frequency of its typical payments, and the alternative procedures the bank offered. A procedure the customer declined as inconvenient can be exactly what shifts a later loss onto the customer.

Will a cyber insurance policy cover a corporate account takeover loss?

It may, usually through funds transfer fraud, computer fraud, or social engineering provisions. These are frequently sublimited below the full policy limit and have different triggers, so coverage and the amount depend on how the loss occurred and how the policy is worded.

Is corporate account takeover the same as business email compromise?

They overlap but differ. Account takeover involves an attacker using stolen credentials to move money directly from the account. Business email compromise typically involves deceiving an authorized person into sending a payment. Both can trigger the same coverage seams around social engineering and funds transfer fraud.

Does a credit union member business account work the same way?

Consumer members are protected by Regulation E, but business accounts at a credit union are generally treated like other commercial accounts under Article 4A and the account agreement, so the same loss-allocation analysis applies.



SeedPod Cyber is a specialized provider of cyber and Tech E&O coverage. If your business moves money electronically and wants its funds transfer and social engineering limits sized to a realistic account takeover loss, contact our team.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.