When your company sends a payment to an account that a hacked or spoofed email supplied, two questions follow: can the money come back, and if not, who absorbs the loss? Under Minnesota’s version of Article 4A of the Uniform Commercial Code, the answer between your business and its bank turns first on whether the payment order was “authorized” or “verified” under Minn. Stat. § 336.4A-202(a)-(b); between a buyer and a seller, the contract and general Minnesota law decide what the statute leaves open. In my Minnesota business compliance practice, I have advised companies on each side of these disputes: one whose account sent the money, and one whose mailbox the fraudster used.
How should a Minnesota business respond in the first 48 hours after a fraudulent wire?
I suggest four steps in the first 48 hours, in this order: a recall request through your own bank, a complaint to the FBI’s Internet Crime Complaint Center (“IC3”), preservation of the email and system records before the mailbox is cleaned up, and notice to your insurers. Under Minnesota’s Article 4A, a cancellation is “[a] communication of the sender of a payment order canceling or amending the order,” sent to the bank that received the order, Minn. Stat. § 336.4A-211(a), so the request comes from the business that sent the payment.
Victims reported $3,046,598,558 in business email compromise losses to the IC3 in 2025, according to the FBI’s 2025 IC3 Annual Report. The same report says the IC3’s Recovery Asset Team froze $679,013,183 of the $1,163,919,846 in attempted theft it worked that year, figures that include tech support and account takeover schemes as well as business email compromise.
- The recall request goes to the bank that sent the payment, and the same report advises making it “along with any necessary indemnification documents.”
- The IC3 complaint at www.ic3.gov follows, with “the full transaction details” the report asks for. I suggest stating the facts accurately and completely while leaving out conclusions about who is responsible, because a complaint that concedes who bore the loss can be used against your company in a later dispute with its trading partner.
- The records get preserved before the mailbox is cleaned up: original emails with full headers, forwarding rules, connected applications, sign-in logs, bank confirmations, and call notes. In one matter, a password reset alone did not end an intruder’s access, because applications had been connected to the mailbox.
- Notice goes to every insurer whose policy might respond, before any settlement, because notice and cooperation terms are part of the contract that decides coverage.
If the mailbox held personal information, Minnesota’s breach-notification requirements need their own review, and a counsel-directed incident response covers preservation and privilege in more depth.
How does Minnesota’s Article 4A decide whether the bank or the business bears a fraudulent wire?
Minnesota’s Article 4A asks who issued the payment order. If an employee with authority to send payments sent the wire, even to an account a fraudster supplied, the order is “the authorized order of the person identified as sender” because your company “authorized the order or is otherwise bound by it under the law of agency,” Minn. Stat. § 336.4A-202(a). If a criminal sent the order through your online banking credentials, the bank bears the loss unless it proves the order was verified under a commercially reasonable security procedure that it followed in good faith and in compliance with any timely recorded restrictions you gave it, Minn. Stat. § 336.4A-202(b).
The Minnesota Court of Appeals has described the bank’s burden the same way: a bank “must establish that a transfer is ‘authorized’ under Minn.Stat. § 336.4A-202(a) or ‘verified’ under section 336.4A-202(b).” Hedged Investment Partners, L.P. v. Norwest Bank Minnesota, N.A., 578 N.W.2d 765, 772 (Minn. Ct. App. 1998).
A business email compromise in which an employee with authority to send payments follows fake instructions fits § 336.4A-202(a). The order is your company’s own, and the refund duty for unauthorized orders in Minn. Stat. § 336.4A-204(a) does not apply. Recovery then runs through the recall, the IC3 freeze process, and claims against whoever received or enabled the payment. Because the authorized-order rule borrows the law of agency, how agency law ties a company to its employees’ acts and your written limits on who can approve a payment, especially limits your bank holds in a record, help decide whose orders bind your company.
What makes a bank’s security procedure commercially reasonable under Minnesota law?
Under Minn. Stat. § 336.4A-202(c), commercial reasonableness is “a question of law” decided from the customer’s wishes expressed to the bank, the customer’s circumstances known to the bank (including the size, type, and frequency of the payment orders it normally issues to the bank), the alternative procedures the bank offered, and the procedures in general use by similarly situated customers and banks. A procedure the customer chose after refusing one the bank offered that was commercially reasonable for that customer is “deemed to be commercially reasonable” if the customer also expressly agreed in a record to be bound by any order issued in its name, whether or not authorized, that the bank accepts in compliance with its obligations under that procedure.
The deemed-reasonable rule is why I suggest reading any waiver your company signed when it declined dual approval or callback verification. A signed refusal, together with that express agreement to be bound, can make the procedure you kept commercially reasonable by statute, so a hacked login that passes it can become your company’s loss under § 336.4A-202(b).
In 2024, Minnesota amended Minn. Stat. § 336.4A-201 to add that “requiring a payment order to be sent from a known email address, IP address, or telephone number is not by itself a security procedure,” a change that matters for email-driven payments. For an order the amended text governs, a bank whose only check was the sending address cannot treat that check as the security procedure that § 336.4A-202(b) requires.
With stated exceptions, the 2024 act’s saving clause provides that “a transaction validly entered into before August 1, 2024, and the rights, duties, and interests flowing from the transaction remain valid thereafter” and may be enforced “as though Laws 2024, chapter 93, had not taken effect,” Minn. Stat. § 336.0A-201. A bank whose agreement with your company predates August 1, 2024, may argue that the agreement is such a transaction and that the pre-2024 definition, which lacked the email-address language, still governs orders under it. Your company may answer that each payment order is its own transaction, “issued when it is sent to the receiving bank,” Minn. Stat. § 336.4A-103(c), and governed by the text in force on that date.
Minnesota’s text governs your relationship with a bank located in Minnesota, Minn. Stat. § 336.4A-507(a)(1), unless your bank agreement chooses another state’s law, § 336.4A-507(b), or a funds-transfer system rule selects another jurisdiction’s law, § 336.4A-507(c). A system rule’s choice binds your company if, when it sent the order, it had notice that the system might be used and of that choice. A Fedwire transfer can also be governed by the Federal Reserve’s Regulation J, whose copy of Article 4A lacks the 2024 language, 12 C.F.R. § 210.25(b).
When does Article 4A move an account-takeover loss back to the bank?
Article 4A moves even a verified order back to the bank when the business proves the order was not caused, directly or indirectly, by anyone it entrusted at any time with payment duties or its security procedure, or by anyone who reached its transmitting facilities or obtained, from a source it controls and without the bank’s authority, information that helped breach the procedure, Minn. Stat. § 336.4A-203(a)(2). The bank must then refund the payment, to the extent it cannot enforce it, with interest, Minn. Stat. § 336.4A-204(a).
That route has a limit: the statute applies “regardless of how the information was obtained or whether the customer was at fault,” so security codes an employee gave to an impostor count against the business.
In my practice, I have seen that pattern: messages posing as the bank tell an employee that approving security-token prompts will stop fraud, the approvals release wires, and the bank calls the loss social engineering and asks the company to repay it. Under Article 4A, the answer turns first on whether the employee’s approvals made the wires the company’s authorized orders under the law of agency, § 336.4A-202(a). If they did not, it turns on whether the procedure the account agreement set was commercially reasonable, whether the bank followed it in good faith, § 336.4A-202(b), and the source of the criminal’s information, § 336.4A-203(a)(2). In that position, I suggest putting every request to the bank in writing, preserving the messages and confirmations, and getting those questions answered in writing before agreeing to repay. Before withholding any payment, I suggest checking your account and loan agreements for setoff and default terms.
A customer that fails “to exercise ordinary care to determine that the order was not authorized” and to notify the bank within a reasonable time, which the statute caps, loses the interest on its refund, § 336.4A-204(a). Your account agreement may fix that reasonable time within statutory limits, § 336.4A-204(b). Minn. Stat. § 336.4A-505 also sets an outer limit, running from the customer’s receipt of a notification reasonably identifying the order, for notifying the bank of an objection to the payment. A customer that has not objected within it can no longer assert that the bank is not entitled to keep the payment, so I suggest checking the section’s current text and your account agreement’s reporting terms against the date your company first received any confirmation, statement, or other notice reasonably identifying the order.
How does Article 4A treat a wire sent to the right name but the wrong account number?
When a payment order names your real supplier but carries a fraudster’s account number, the beneficiary’s bank (the bank holding the fraudster’s account) “may rely on the number” if it does not know that the name and number refer to different persons, Minn. Stat. § 336.4A-207(b)(1). That bank “need not determine whether the name and number refer to the same person.” Your obligation to pay your own bank for the order then turns on whether you had notice, before the order was accepted, that payment might be made by account number.
Under Minn. Stat. § 336.4A-207(c)(2), a business that proves the account holder “was not entitled to receive payment from the originator” is “not obliged to pay its order” unless its bank proves the business had notice before the order was accepted. The notice is that payment might be made by account number even when the number identifies someone other than the named payee. The statute adds: “Proof of notice may be made by any admissible evidence.” The bank meets that burden if the business “signed a record stating the information to which the notice relates,” so that sentence in your funds-transfer agreement is worth finding before any argument with the bank.
If you must pay, you have the right to recover from the account holder “to the extent allowed by the law governing mistake and restitution,” Minn. Stat. § 336.4A-207(d)(1). That right is worth what can still be found in the account or traced from it, which is why the freeze request comes first.
How does a wire recall work, and who bears the bank’s recall costs?
A recall asks the banks in the chain to agree to cancel the payment. Unless an agreement or a funds-transfer system rule provides otherwise, your company, as sender, owes its bank the loss and expenses that bank incurs from a recall it agrees to, Minn. Stat. § 336.4A-211(f). Once a bank has accepted a payment order, cancellation “is not effective unless the receiving bank agrees or a funds-transfer system rule allows” it, Minn. Stat. § 336.4A-211(c). At the bank holding the fraudster’s account, cancellation is effective only in listed situations, such as an unauthorized order or a sender’s mistake that resulted in a payment order to “a beneficiary not entitled to receive payment from the originator,” § 336.4A-211(c)(2).
Even after a cancellation, that bank is entitled to recover from its own customer, the account holder, only “to the extent allowed by the law governing mistake and restitution,” § 336.4A-211(c)(2). In practice, a recall reaches money still in the account; funds already moved have to be traced and pursued.
The sender’s liability to a bank that agrees to a cancellation after accepting the order covers “any loss and expenses, including reasonable attorney’s fees, incurred by the bank as a result of the cancellation or amendment or attempted cancellation or amendment,” § 336.4A-211(f). The same is true when a system rule allows the cancellation without the bank’s agreement, and the sender owes it “whether or not cancellation or amendment is effective.” A bank may also ask for a signed indemnity, and the FBI advises requesting a recall “along with any necessary indemnification documents.” I suggest reading whether the bank’s form reaches anything beyond the recall before you sign it.
How is the loss split when a hacked email diverts a payment between buyer and seller?
Article 4A does not by itself shift a diverted payment’s loss between buyer and seller; the parties’ contract and general Minnesota law decide it. Article 4A discharges the buyer’s debt only “to the same extent discharge would result from payment to the beneficiary of the same amount in money,” Minn. Stat. § 336.4A-406(b), and the beneficiary is “the person to be paid by the beneficiary’s bank,” Minn. Stat. § 336.4A-103(a)(2). When the order names the seller but carries the fraudster’s account number, the beneficiary’s bank, if it does not know the name and number refer to different persons, “may rely on the number as the proper identification of the beneficiary of the order,” Minn. Stat. § 336.4A-207(b)(1). Whether the order names the seller or the fraudster, the money reaches the fraudster.
The Minnesota Court of Appeals has held that “the exclusivity of Article 4A is restricted to situations that are covered by particular provisions of the Article.” The court added that “principles of law and equity may be applied to disputes relating to funds transfers,” as long as they create no rights, duties, or liabilities inconsistent with the article. Hedged Investment Partners, L.P. v. Norwest Bank Minnesota, N.A., 578 N.W.2d 765, 771 (Minn. Ct. App. 1998).
If your business sent the payment
A buyer that paid a fraudster may still owe the invoice. In disputes over who bears the loss, the parties often argue about facts such as:
- whether the change request came from the seller’s real mailbox or from a look-alike domain;
- whether anyone confirmed the new account by calling a number already on file;
- what warning signs the request carried, such as a new bank, a new country, an urgent tone, or a mismatched payee name; and
- whether payments continued after the seller said money was not arriving.
If your business was the one impersonated
A seller whose mailbox the fraudster used should expect the buyer to argue that the seller’s security failure caused the loss. Because Article 4A gives the cancellation request to the sender, Minn. Stat. § 336.4A-211(a), the recall has to come from the buyer and its bank.
When a customer offers to split the loss and sends part of the money, I suggest applying it as a partial payment and saying in writing that the balance remains owed, so the record does not read as an agreement to settle. If the payment comes with a statement that it settles the claim, the customer may argue that accepting it settled the claim whatever you wrote back, so I suggest reading what accompanies any payment before applying it.
For a check, a statute sets the rule: if the check or a letter with it conspicuously states that the check is tendered as full satisfaction of the claim, cashing it can discharge the whole claim, balance included, if the customer tendered the check in good faith and the amount owed was unliquidated or subject to a bona fide dispute, Minn. Stat. § 336.3-311(a)-(b). A written reservation of rights does not prevent that result, Minn. Stat. § 336.1-308(b). The statute’s exceptions include a designated-address rule for organizations and a limited window to undo the discharge by repaying the check amount, but proof that you, or an agent of yours with direct responsibility for the disputed debt, knew within a reasonable time before collection began that the check was tendered in full satisfaction can defeat both. If you have already cashed such a check, I suggest reading § 336.3-311(c)-(d) right away.
A split can be a sensible result between long-standing partners. I suggest not offering one in writing before the customer has asked its bank for a recall: a written offer anchors every later discussion, fixes what you can collect once the customer accepts it, and weakens the customer’s reason to pursue recovery.
What contract clauses allocate wire-fraud risk before a payment goes out?
Article 4A lets the payer and payee write their own rule: rights under Minn. Stat. § 336.4A-406 “may be varied only by agreement of the originator and the beneficiary,” § 336.4A-406(d). The clauses that do the work, alongside the other risk terms in a vendor contract, fix the payee’s account in the contract, require any change to be confirmed through a channel the contract names, and state who bears a payment sent without that confirmation.
- A payment-instructions clause puts the account details in a signed schedule and allows changes only by a signed amendment confirmed through a phone number already in the contract. The FBI’s advice runs the same way: “Use secondary channels and/or two-factor authentication to verify requests for changes in account information,” per IC3 Public Service Announcement I-091124-PSA.
- An allocation clause states that a payment sent to an unconfirmed account does not pay the invoice, or that the party whose systems were used bears the loss.
- A cooperation clause requires prompt notice of a suspected compromise, preservation of records, help with recall and IC3 requests, and assignment of recovery rights to whichever party bears the loss.
- An insurance clause, such as an insurance backstop for the allocation clause, gives the party bearing the risk a way to pay for it.
Your bank agreement matters too. Article 4A bars varying its authorized-order and verified-order rules, and its account-takeover rule in § 336.4A-203(a)(2), by agreement, with stated exceptions, Minn. Stat. § 336.4A-202(f). One exception lets a bank, by express agreement evidenced by a record, “limit the extent to which it is entitled to enforce or retain payment” of a verified order, Minn. Stat. § 336.4A-203(a)(1). Separately, a verified order shifts to your company only if the bank also complied with any agreement or instruction of yours, evidenced by a record, restricting which payment orders it accepts, such as a bar on international wires, § 336.4A-202(b). The bank need not follow an instruction that violates an agreement with you evidenced by a record. It also need not follow an instruction whose notice it did not receive at a time and in a manner affording it a reasonable opportunity to act on the instruction before accepting the order. I suggest asking for both the limit and the restrictions if your company sends large or frequent wires.
How do crime and cyber insurance policies respond to a business email compromise loss?
A crime or cyber policy pays a business email compromise loss only if an insuring agreement reaches it and no exclusion or condition takes it away. A computer fraud or funds transfer fraud agreement may not cover a payment your own employee sent on a fraudster’s instructions, so any social engineering or fraudulent instruction coverage, its limit, and its verification conditions matter most. The Minnesota Supreme Court interprets insurance policies “using the general principles of contract law.” It has said that “unambiguous language must be given its plain and ordinary meaning,” and that “the insured bears the initial burden of demonstrating coverage” while “the insurer carries the burden of establishing the applicability of exclusions.” Midwest Family Mutual Insurance Co. v. Wolters, 831 N.W.2d 628, 636 (Minn. 2013).
An insurer may answer a claim by blaming an employee’s lapse. In State Bank of Bellingham v. BancInsure, Inc., 823 F.3d 456, 459-61 (8th Cir. 2016), the U.S. Court of Appeals for the Eighth Circuit, applying Minnesota law, stated that for insurance contracts “Minnesota has adopted the concurrent-causation doctrine,” taking the doctrine’s terms from a Minnesota Court of Appeals decision that cited Minnesota Supreme Court cases. Under that doctrine, a loss can be covered even though an excluded cause contributed to it, if a covered cause was the efficient and proximate cause of the loss.
A policy can contract around the doctrine, but the court noted that clauses found to do so used “clear and specific” language and held the bond’s word “indirectly” insufficient. The court affirmed a ruling that a bank’s bond covered a hacker’s fraudulent wire, agreeing that the illegal transfer, not the employees’ violations of policies and procedures, was that cause. That application, to a bank’s bond rather than a business crime policy, is a federal court’s reading of Minnesota law, so a Minnesota court may find it persuasive but is not bound by it.
Bellingham involved a hacker’s transfer. When your own employee sends the payment on a fraudster’s instructions, two decisions of the federal district court in Minnesota show how a policy’s definitions, exclusions, conditions, and limits decide the claim. In SJ Computers, LLC v. Travelers Casualty & Surety Co. of America, No. 21-CV-2482 (D. Minn. Aug. 12, 2022), a company’s CEO wired payments on fake vendor invoices. The insurer agreed to pay under the policy’s social engineering coverage, which had a $100,000 limit, and the court held, among other grounds, that the $1,000,000 computer fraud coverage did not apply because the policy’s definition of computer fraud excluded an employee’s entry made in reliance on a fraudulent instruction.
In Interstate Removal, LLC v. National Specialty Insurance Co., No. 23-CV-0510 (D. Minn. Mar. 28, 2024), the court held that an employee-sent wire fell within the policy’s computer fraud insuring agreement, but an exclusion for an employee acting on an instruction “which instruction proves to be fraudulent” barred coverage. The social engineering coverage failed, among other reasons, because the company could not plead that it had followed an “established and documented verification procedure . . . before acting upon” the fraudster’s instruction, a condition precedent to that coverage. Both decisions are federal trial-court rulings on particular policy wording, so a Minnesota court may find them persuasive but is not bound by them. I suggest reading each crime, cyber, and package policy with these questions:
- Does a computer fraud or funds transfer fraud insuring agreement apply, and does its definition or an exclusion remove a payment your employee sent on a fraudulent instruction?
- Does the policy include social engineering or fraudulent instruction coverage, and what limit applies to it?
- Does any clause condition coverage on following a documented verification procedure, such as a callback, before acting on a payment change, and did your team follow it?
- Must the lost money be your own, or does the coverage reach a payment your customer sent to a fraudster instead of to you?
- What do the notice, proof-of-loss, and cooperation conditions require, and by when?
One company I advised learned after the fraud that it carried no crime, cyber, or social engineering coverage at all. I suggest answering these questions at renewal, while coverage can still be added.
Does Article 4A cover ACH payments as well as wires?
Generally yes, for credit payments. Minnesota’s Article 4A applies to funds transfers, Minn. Stat. § 336.4A-102, each beginning with the originator’s payment order, § 336.4A-104(a), which can be sent through a funds-transfer system, § 336.4A-103(a)(1). That term includes an automated clearinghouse (ACH), § 336.4A-105(a)(5), so Article 4A’s rules on authorization, security procedures, and cancellation reach an ACH credit you send, though your ACH agreement and network rules can change some results, § 336.4A-501(a)-(b). Apart from certain remittance transfers, the article does not apply to a transfer any part of which the federal Electronic Fund Transfer Act governs, § 336.4A-108(a)-(b).
Is a business wire protected the way a personal bank account is?
Generally not. The federal Regulation E protections for electronic transfers apply to accounts established primarily for personal, family, or household purposes, 12 C.F.R. § 1005.2(b)(1), and they exclude transfers through Fedwire or a similar wire system used primarily between financial institutions or between businesses, 12 C.F.R. § 1005.3(c)(3). A business wire answers instead to Article 4A of the Uniform Commercial Code, which assigns the loss through authorization, security procedures, and the customer’s own reporting duties. Minnesota’s version generally governs when your bank is located in Minnesota, Minn. Stat. § 336.4A-507(a)(1).
Can the bank that received the money be held responsible for crediting the fraudster's account?
Usually not under Article 4A alone. When a payment names one party but carries another party’s account number, the beneficiary’s bank, if it does not know the name and number refer to different persons, may rely on the number and need not determine whether the name and number refer to the same person, Minn. Stat. § 336.4A-207(b)(1). If that bank knew the name and number identified different persons and paid the fraudster, acceptance of the order cannot occur, and Article 4A’s refund rules can return your payment through your own bank, §§ 336.4A-207(b)(2), 336.4A-402(c)-(d).
Do we have to notify anyone if the hacker could read our email?
Possibly. Under Minn. Stat. § 325E.61, a business must notify Minnesota residents whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, and one holding such data for another must notify the owner, subd. 1. Personal information means a name plus a Social Security number, a driver’s license or Minnesota identification card number, or an account or credit or debit card number in combination with any required security code, access code, or password that would permit access to the financial account. Large breaches add notice to consumer reporting agencies, subd. 2. The section does not apply to a financial institution as federal law defines it, subd. 4.
Should we pay a recovery service that says it can trace the stolen money?
I suggest not paying any service that contacts you after a loss and promises recovery. The FBI warns that scammers impersonate FBI personnel and the Internet Crime Complaint Center, claim to have recovered victims’ lost funds, and use the contact to take more money from people who were already defrauded. The FBI also states that IC3 never contacts individuals directly by phone, email, social media, or online chat, so a real freeze request runs through your bank and your complaint at www.ic3.gov.
Between your business and its bank, Minnesota’s Article 4A decides who bears a fraudulent wire through authorization, verified security procedures, and your own duty to report. Between a buyer and a seller, the contract decides first, and general Minnesota law fills the rest. In both, the deciding terms are chosen before any fraud: the bank procedures you accept, the payment-change clause in your contracts, and the wording of your policies, all part of business compliance in Minnesota. If a payment has gone to the wrong account, or you would like your bank agreement, contracts, and policies reviewed against these rules, email Aaron Hall at [email protected] with a short description. I run an intake and conflict check before any documents change hands.