Court caps a builder's email-fraud loss at the cyber policy's social-engineering sublimit
Archive story from the 2026-06-21 edition. This is the reporting as filed; source publication and event dates may differ. Check the dated storyline for subsequent developments.
In Perry & Perry Builders v. Cowbell Cyber / Obsidian Specialty Insurance, a builder that got tricked into wiring money on a fraudulent payment instruction found its recovery capped by the cyber policy's social-engineering / funds-transfer-fraud sublimit, not the full policy limit.
Why it matters
Restoration shops move real money on emailed instructions all the time: supplier payments, sub payouts, insurance proceeds. A business-email-compromise hit can run six figures, and most operators have no idea their cyber policy sublimits that exact loss to a fraction of the headline limit.
Our assessment
The reflex after a wire fraud story is to go buy more cyber coverage. Coverage is the backstop, not the control, and the sublimit for this exact loss is usually a fraction of the headline limit. Put in the rule that actually stops it: any change to banking details gets verified by phone, to a number you already had, by a second person, every time.
Saved stories and followed topics stay in this browser. No account sync or email alerts.
Advisory/Broker (law firm blog summarizing a court ruling) Medium confidence at publication
What changed
Storyline: coverage law
What changed coverage-law thread moves off RCV/notice traps onto cyber/wire-fraud sublimits as an operator exposure.