The FBI ranks contractors second on one of its lists.
Among ransomware complaints from businesses outside the sixteen critical infrastructure sectors in 2025, contracting services ranked second at 17 percent. The FBI's own example of that category was electricians and general contractors.
Ready for terms? Get a quote. Want to find the gaps first? Compare your coverage.
The FBI Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with reported losses of 3.05 billion dollars, and wire transfer or ACH was the reported transaction type in 86 percent of BEC complaints (FBI IC3 2025 Annual Report). Separately, among more than 1,400 ransomware complaints from businesses outside the sixteen critical infrastructure sectors, contracting services was the second most-reported industry at 17 percent, behind legal services at 18 percent.
Contractors are attractive targets for a reason that has nothing to do with technology. The work involves large payments moving on a schedule, between parties who mostly know each other, negotiated over email, and often approved by whoever is free rather than by a defined process. A fraudster does not need to break anything. They need to be reading the thread when the draw request goes out.
How the money actually leaves
The pattern is consistent. Someone gains access to a mailbox, or registers a domain one character off from a real one, and waits. When a payment conversation is underway they insert an updated banking instruction, usually with a plausible reason attached. On a construction job that arrives as a revised subcontractor invoice, a change to where a draw should be deposited, or a supplier explaining that their bank has changed. The request is expected, the amount is right, and the only thing wrong is the destination.
The federal government has looked directly at this sector. A Treasury analysis of business email compromise reporting found that manufacturing and construction together were the most targeted sector in both years it examined, at 20 percent of analyzed transactions in 2017 and 25 percent in 2018, with fraudulent vendor and client invoice impersonation becoming the most common method. That analysis was published in 2019 and remains the most recent Treasury cross-sector breakdown, so treat it as dated rather than current.
Speed decides whether the money comes back
A diverted payment is not always gone. The FBI operates a Recovery Asset Team that works with receiving banks to freeze funds before they are withdrawn, and in 2025 it acted on 3,900 incidents involving 1.16 billion dollars of attempted theft, freezing 679 million of it (IC3 2025 Annual Report, p. 18). That is a 58 percent success rate, and it depends almost entirely on how quickly the victim reports.
The other side of that number deserves equal weight. A Treasury analysis of real estate payment fraud covering 2020 and 2021 identified 2,013 incidents worth 710 million dollars and recorded no fund recovery at all in just over 20 percent of them. Recovery is real and it is not reliable. The practical consequence is that the first hour matters more than anything in the policy, which is why a cyber policy with a genuine incident response hotline is worth more than one with a slightly larger limit.
A local case, and it was not a small one
In 2025 the United States Attorney for the District of Oregon filed a forfeiture action to recover 6,748,680 dollars diverted from the City of Portland through a business impersonation scheme aimed at its payment system. The scheme began in February, the city notified law enforcement in March, and a federal seizure warrant was executed in April. The full amount was recovered.
The reason it belongs on a contractor page is that the mechanism is identical to a vendor payment diversion against a construction company. Someone impersonated a business the city already paid, and the payment system did what it was designed to do. A municipal finance department has more controls than most contractors, and it still happened.
The notification clock, state by state
Data obligations are separate from payment fraud and they bite even when no money moves. If you hold employee records you hold Social Security numbers, and every state in our core footprint has a notification statute triggered by them. The deadlines differ and one of them just changed.
California now requires notice to affected residents within 30 calendar days of discovery under Civil Code 1798.82 as amended by SB 446, and, where more than 500 California residents are affected, a sample copy of that notice to the Attorney General within 15 calendar days of notifying consumers, following an amendment effective January 1, 2026. Most published summaries still describe California as having no fixed deadline, which is now wrong. Washington requires notice within 30 days under RCW 19.255.010, with Attorney General notice above 500 residents. Oregon requires notice within 45 days under ORS 646A.604, with Attorney General notice above 250 consumers, and separately requires a vendor to tell the business it serves within 10 days. Idaho sets no fixed number of days for a business under Idaho Code 28-51-105, and its 24-hour Attorney General duty applies only to agencies, not to private companies, which is a point widely reported incorrectly. A contractor working across all four should design to the 30-day standard.
The exclusions and conditions that void a cyber claim
The one most likely to bite a contractor is not an exclusion at all, it is a condition. Cyber applications ask you to confirm your security controls, and the answers become warranties. If you said you had multi-factor authentication on email and you did not, the carrier can deny the claim on the basis that the risk it agreed to insure was not the risk it got. Answer the application accurately even where the accurate answer is worse, and fix the control rather than the answer.
The written exclusions follow a pattern. War and hostile-action wording has broadened considerably since 2022 and now reaches some state-backed attacks, which is worth reading rather than assuming. Prior known incidents are excluded, so anything you were already aware of when you bought the policy stays with you. Infrastructure failure, meaning an outage at your internet or utility provider rather than at your business, is commonly carved out. And a redirected payment authorized by an employee who was tricked is only covered if social engineering is specifically included, which is exactly why that sublimit is the number to check first.
What it costs, and what moves the number
Revenue is the usual exposure base, so a contractor doing eight figures pays more than one doing seven for the same limit. Beyond that the controls decide it. After the ransomware losses of the early 2020s carriers repriced this line around security posture rather than around industry alone, which is why two contractors of the same size can be quoted very differently. We price it from the market rather than publishing a range.
What moves it: revenue, the limit, the retention (the amount you pay before the policy responds), and the controls in the section above, with multi-factor authentication on email and offline backups doing most of the work. Records held matter, so a solar contractor holding consumer credit applications rates differently from a framing crew holding almost nothing. And ask for the social engineering sublimit priced separately, because raising it is often the single cheapest improvement available on the quote and it is the part that answers a diverted draw payment.
What the coverage should contain
Start with funds transfer fraud and social engineering, because that is where the loss is most likely to occur. These are frequently written at a sublimit well below the policy limit, sometimes a tenth of it, and a contractor who buys a one million dollar cyber policy can discover the coverage answering their actual loss stops at fifty thousand. Ask for the sublimit by name and compare it to your largest routine payment.
Then breach response, which pays for forensics, legal advice on the notification statutes above, notification itself and credit monitoring. Then business interruption, and note the FBI's own caution that its ransomware loss figures exclude lost business, time, wages, files and equipment, which it says produces an artificially low picture. Then third-party liability for claims by others. Also check what your existing policies exclude, because cyber exclusions on property and general liability forms have broadened considerably and the gap between them is where an uninsured loss lives.
What underwriters want to see now
Cyber underwriting tightened considerably after the ransomware losses of the early 2020s, and the application is now a short security audit. Multi-factor authentication on email is close to mandatory, and a contractor who cannot answer yes to that question will find the market narrow and the price high. Offline or immutable backups are the second question, meaning copies an intruder cannot reach or overwrite, because they decide whether a ransom has to be paid at all. Both are cheap relative to what they unlock in coverage terms and pricing.
The third question is the one contractors most often fail and most easily fix. Underwriters ask whether you verify changes to banking details by a means other than email, using a phone number you already had rather than one supplied in the message. That single control defeats most of the payment diversion described above. Putting it in writing before you apply improves the quote and, more to the point, materially reduces the chance you ever need the policy.
Trades that need cyber
How this coverage applies changes with the work. These are the trades where it does the most, each with the exposure spelled out for that trade.
General Contractors
Draw requests and subcontractor payment details moving by email, which is exactly the document a fraudster wants to intercept and alter.
General contractor insurance →Drywall Contractors
Progress billings and supplier account details in one inbox, usually with one bookkeeper and no second approval on outgoing payments.
Drywall contractor insurance →Flooring Contractors
Homeowner deposits, showroom card payments and a customer file holding addresses and financing paperwork.
Flooring contractor insurance →Concrete & Masonry Contractors
Large material deposits and progress payments arranged by email, where a single redirected payment is hard to claw back.
Concrete and masonry insurance →Electricians
Service billing and customer records held in one system, with payment instructions moving by email on commercial work.
Electrician insurance →Specialty Trade Contractors
Small offices with one bookkeeper, one email account and no separation of duties on outgoing payments.
Specialty trade insurance →Requirements change at the state line
Licensing, bonds, and workers comp rules vary by state, and so do the limits contracts ask for. Pick yours.
Go deeper in the Learning Center
Plain-language articles on how this coverage behaves in a real claim.
Contractor cyber insurance questions
Why would anyone target a contractor?
What is business email compromise?
Does my general liability or property policy cover this?
If money is wired away, can it be recovered?
How fast do I have to notify people after a breach, and is Idaho really 24 hours?
What should the policy actually include?
Reviewed for insurance accuracy by Richard Sweet, Vantage Point Risk. Last reviewed August 21, 2026. How we review this.
What is the sublimit on social engineering?
It is the number that decides whether a diverted draw payment is covered or not, and it is usually far below the policy limit. We will find it on your policy and tell you what it is.
The exposure is the payment, not the computer.
Tell us how you take payment, who can approve a change to banking details, and what records you hold, and we will tell you where the gap is.