Cyber Liability sounds like a tech-company coverage, but construction has become one of the more frequently targeted industries for a specific kind of attack: wire fraud. Large payments, multiple parties on a project, and email-based communication make contractors an attractive target.

The Risk That Actually Hits Contractors Most

Social engineering fraud — an attacker impersonating a vendor, GC, or client by email and redirecting a legitimate payment to a fraudulent account — is one of the most common cyber losses in construction specifically, not just a generic data-breach scenario. A single successful redirect can be a six-figure loss with no clean way to recover the funds.

What a Policy Typically Covers

First-party costs: breach response, forensic investigation, data recovery, and notification costs if client or employee data is exposed.

Third-party costs: liability if a client’s data was compromised through your systems.

Social engineering/fraud coverage, if specifically added — this is often a separate endorsement, not automatically included, and worth confirming explicitly rather than assuming.

Low-Cost Prevention Worth Doing Regardless of Coverage

Verify any changed payment instructions by phone, using a known number — never one provided in the same email requesting the change.

Use two-factor authentication on email and financial accounts.

Train office staff specifically on this scam pattern, since it targets people, not just systems.

Handling client payments or data digitally? Request a Quote and we’ll make sure fraud coverage isn’t just assumed.