The short answer

Your trustee bond is a fidelity bond — it answers for theft by you and your staff, not for fraud committed against you. When a criminal reroutes an estate distribution by impersonating a creditor or your bank, the bond almost certainly will not respond. Standalone cyber insurance with social-engineering fraud coverage (or a crime policy with third-party fraud) is the layer that does. Trustees are now prime targets: they control estate accounts with standing wire authority, and the FBI counted about $3.05 billion in business email compromise losses in 2025 alone.

Why this conversation is happening in August

Every year around the National Association of Bankruptcy Trustees annual convention, the same question surfaces in the halls: "Does my bond cover this?" A trustee stands up, describes a wire that left the estate on instructions that turned out to be forged — or a vendor invoice that was real-looking and completely fake — and the room goes quiet, because nobody is certain.

The uncertainty is the problem. By the time you're litigating whether your bond responds, the money is gone and the estate (and often your own liability) has a hole in it. The fix is to know the answer before the wire, not after. This article is that answer, in plain English, with the statute and the loss data to back it.

What your trustee bond actually is

Chapter 7, 11, 12, and 13 trustees must qualify by filing a bond with the bankruptcy court, as required by 11 U.S.C. § 322. The bond is "conditioned on the faithful performance of official duties" — the estate is protected against the trustee's failure to perform, including the trustee's own dishonest acts. In practice, most trustees operate under a blanket bond that covers them across all their assigned cases.

Read that insuring agreement carefully: faithful performance of official duties. That is a fidelity concept. It answers for the bonded person's own dishonesty — the trustee who dips into estate funds, or the office employee who embezzles while the trustee is accountable for it. The U.S. Trustee Program's own bond policies confirm the blanket bond's boundaries: it may not even cover the trustee in cases that involve operating a business, and it is a fidelity instrument, not a general liability or fraud policy.

The plain-English version

A fidelity bond asks: "Did your own people steal?" If yes, it pays. It does not ask: "Did an outsider deceive your people?" Social-engineering fraud is a different question — and most bonds don't answer it.

The fraud your bond doesn't see coming

Here is the attack pattern that empties estate accounts in 2026. A criminal monitors a pending estate transaction — a distribution to creditors, a real-estate closing, a settlement — or simply spoofs a trusted party's email. Then:

  1. They impersonate a known party. The creditor, the vendor, the title company, sometimes the bank itself. The email address is one character off, or the display name is identical.
  2. They change the payment instructions. "Our banking details have changed — please wire to the attached account." The attachment carries a routing and account number that belongs to the criminal.
  3. They create urgency. "Closing is Friday. This has to move today." Urgency is the social engineer's signature — it suppresses the verification everyone knows they should do.
  4. The wire leaves. Authorized by a real person, using their real credentials, under a real instruction that happened to be forged.

Nobody's passwords were stolen. No server was breached. The money left through the front door, with authorization — which is precisely why a fidelity bond does not respond. The trustee wasn't dishonest; the trustee was deceived. And a fidelity bond is not a deception policy.

The numbers: this is not a small fraud

The FBI's 2025 Internet Crime Report is the authoritative annual count of reported cyber-enabled fraud. Its headline numbers for 2025:

Metric2025 (IC3)What it means
Total reported cybercrime losses Surpassed $20 billion Roughly 453,000 complaints filed; losses up again year over year
Business Email Compromise (BEC) ≈ $3.05 billion 24,768 complaints — the single costliest complaint category
Share driven by social engineering ≈ 85% of losses Fraud against people, not technical system breaches

BEC is the umbrella term for exactly the pattern described above — a trusted party impersonated, payment rerouted. Trustees sit in the crosshairs because they are professional money movers. Standing wire authority, high-value single transactions, tight statutory deadlines, and a paper trail the public can partially read in the docket all make estates a more attractive target than an ordinary company's accounts payable.

What actually covers this: the two policies that do

Two coverage forms respond to third-party deception, and trustees should hold at least one — most buy both:

1. Cyber liability with a social-engineering fraud / funds-transfer fraud endorsement

Standalone cyber policies are built for the breach world — ransomware, data exfiltration, network interruption. But the endorsement most trustees actually need is the social-engineering fraud (SEF) or funds-transfer fraud (FTF) rider. SEF responds when an authorized person is induced to transfer money or data by a fraudulent instruction — the impersonated-creditor scenario. FTF responds when a financial institution is tricked into transferring funds on forged instructions. Limits are typically $250,000 to $1,000,000, and premiums are modest relative to the wire sizes involved.

2. Crime coverage with third-party fraud

Commercial crime policies traditionally cover first-party theft — employee dishonesty, forgery, computer fraud. A third-party fraud insuring agreement extends the policy to losses caused by outsiders deceiving your people. This is the coverage that pairs naturally with your fidelity bond: the bond handles the bonded-person angle; the crime policy's third-party fraud extension handles the deceived-person angle.

Underwriting reality

Insurers price and often grant this coverage based on your controls. Dual-approval over a set threshold, independent verification of changed payment instructions, and a documented authorization trail are not just good practice — they're what the application asks about. Clean controls get you coverage and a better rate; sloppy ones get you declined or excluded.

The controls that make the coverage work

Insurance pays after the loss. The point of the controls is to make the loss not happen in the first place — and to keep your coverage enforceable when it does. For a trustee's office, the non-negotiables are:

  • Verify changes out-of-band. Any change to payment instructions — new account, new payee, new routing — gets verified by calling the number on file (not the number in the email) and, for large amounts, a second authorized person confirms.
  • Dual approval above a threshold. One person initiates, a second authorizes. For estate accounts, the threshold should be low enough to catch the frauds that actually happen.
  • Test transactions for new payees. A small transfer that clears before the large one. Criminals routing to mule accounts often can't hold the test amount in place.
  • No same-day closings on changed instructions. The urgency in the email is the scam's engine. A 24-hour hold on any instruction change kills most of it.
  • Documented authorization trail. Written instructions, confirmations, and the verification record — insurers ask for exactly this when a claim is presented.

How the pieces fit: a quick map

ExposureResponding coverageTypical limit
Trustee or staff embezzlement Trustee bond (fidelity) — statutory under 11 U.S.C. § 322 Per U.S. Trustee Program schedule
Criminal impersonates creditor/vendor and reroutes a wire Cyber SEF endorsement or crime third-party fraud $250K–$1M (per occurrence)
Ransomware / data breach in the trustee's office Cyber liability (first-party + network liability) $1M–$5M typical for professional offices
Professional negligence claims against the trustee Professional liability / E&O (separate from the bond) $1M+

Notice what's not on this map: nothing under the bond answers for the impersonation row. If you are a trustee who has reviewed your program in the last few years and "social engineering" and "funds transfer fraud" never appeared in the conversation, your map has a hole in it.

Why this is an insurance conversation, not just an IT conversation

Most trustees treat fraud protection as an IT problem — spam filters, MFA, security training. Those matter, and they're cheap. But they reduce the frequency of the attack; they don't answer for the loss when the attack succeeds anyway, which the FBI's numbers say it will for someone. Insurance is the only instrument that converts a $900,000 estate loss into a $10,000 deductible. That conversion is the entire point of the coverage.

The August timing isn't accidental: this is the moment each year when the insolvency community is together, the NABT convention is on the calendar, and fraud-prevention sessions are top of mind. The trustees who act on it this month are the ones whose estates won't be the cautionary tale at next year's convention.

If you want a quick gap check

Send us your trustee bond schedule plus your current cyber and crime dec pages. We'll come back inside 48 hours with a one-page map: what responds to which exposure, and what the social-engineering gap would cost to close. No commitment. Email us or call (877) 237-8167.

Common questions