When people think about cybercrime, ransomware is often the first threat that comes to mind. A successful attack can bring a business to a standstill, disrupting operations, locking critical systems and generating significant costs.
Global CFC cyber claims data, 1 Jan - 31 Dec 2025
But while ransomware attracts the attention, theft of funds is the cyber incident businesses are most likely to experience. In 2025, it accounted for 25% of global cyber claims resolved by CFC's claims team, making it the single most common cyber event we handled. Based on claims trends seen so far in 2026, that figure is rising sharply, with theft of funds incidents now approaching half of all cyber claims notifications. For many businesses, a single fraudulent payment can leave them severely out of pocket.
How theft of funds attacks work
Theft of funds, sometimes called funds transfer fraud or social engineering fraud, occurs when a cybercriminal tricks an employee, customer or supplier into transferring money to an account controlled by the criminal. Unlike ransomware, these attacks don't usually rely on sophisticated malware or advanced hacking techniques. Instead, they exploit trust.
One of the most common techniques is business email compromise (BEC). Here, the hacker gains access to a legitimate email account, often through phishing emails, stolen credentials or exploited vulnerabilities. Once inside, they monitor conversations, impersonate trusted contacts and wait for the right opportunity to intervene.
From there, the hacker may request urgent payments, ask for bank details to be updated, or alter invoice information before it reaches the recipient. The goal is always the same: convince someone into making a legitimate payment to the wrong account.
Why AI is making these attacks more effective
Theft of funds attacks have always relied on impersonation and deception. The difference today is that AI is making those tactics faster, cheaper and far more convincing. Cybercriminals can now generate highly polished phishing emails at scale, mimic writing styles and create fraud attempts that are increasingly difficult to distinguish from legitimate communications.
We're already seeing the impact. CFC has recorded a 14x surge in phishing threats following the release of AI coding agents, while research suggests that 82.6% of phishing emails now use AI-generated content.
Why SMEs are especially exposed
Many business owners assume cybercriminals focus on large enterprises with deep pockets. In reality, small and medium-sized businesses are often more attractive targets because they typically have fewer payment controls, less formal verification processes and limited cyber security resources.
At the same time, SMEs still transfer significant sums to suppliers, payroll providers and other trusted partners. Hackers know that all it takes is one employee making one payment to create a successful attack. The rise of hybrid working has only increased the risk, making it harder to verify payment requests and easier for impersonation attempts to go unnoticed.
How businesses can reduce the risk
While no business can eliminate the risk of theft of funds entirely, simple cyber security controls can dramatically reduce the chances of falling victim:
Verify payment requests independently by calling a known contact using a pre-verified phone number before changing bank details or processing unusual payments.
Enable multi-factor authentication (MFA) to help protect email accounts, even if credentials are stolen.
Strengthen payment controls through dual approval processes, segregation of duties and additional checks for high-value transactions.
Train employees regularly to recognize phishing emails, impersonation attempts and suspicious payment requests.
Create a questioning culture where people feel comfortable challenging unusual instructions, even when they appear to come from a senior executive or trusted supplier.
Even with strong controls in place, a convincing social engineering attack can still slip through. That's why cyber insurance is a vital part of any cyber risk management strategy.
In addition to providing cover for many cybercrime-related losses, a good cyber insurance policy offers access to specialist incident response experts who can help investigate the incident, work with banks and, where possible, recover stolen funds before they disappear. At CFC, policyholders can also access phishing training through our Response app – just one of our proactive cyber attack prevention services, there to help businesses stay ahead.
Learn more about incident response, cyber attack prevention, and comprehensive cyber cover here.