Email-Initiated Transfer Fraud Exclusion Applies to Fraudulent Instructions Sent to the Insured, Even When Sent Internally from a Compromised Employee Account
Introduction
Office of the Special Deputy Receiver v. Hartford Fire Insurance Company (7th Cir. June 18, 2026)
addresses a recurring loss pattern: a spear-phishing compromise of a senior executive’s email account followed by
employee-authorized wire transfers. The plaintiff, the Office of the Special Deputy Receiver (OSD),
an Illinois nonprofit administering estates for insolvent or troubled insurers under
215 Ill. Comp. Stat. 5/192-93, 202, purchased a Financial Institution Bond for Insurance Companies
from Hartford Fire Insurance Company.
Hackers gained access to OSD’s CFO email, impersonated the CFO, and instructed other OSD employees to transfer funds
for purported investments. OSD wired the funds and suffered a multi-million-dollar net loss. Hartford denied coverage.
The central issue on appeal was a contract-interpretation question under Illinois law: whether a policy exclusion for
loss from “a fraudulent instruction sent to [OSD] through electronic mail” applies when the email is sent to OSD
employees from within OSD (i.e., using a compromised internal account).
Summary of the Opinion
The Seventh Circuit affirmed dismissal under Rule 12(b)(6), holding that the bond unambiguously excludes
OSD’s loss. The court concluded that the relevant emails were “fraudulent instruction[s] sent to” OSD because they were
sent to OSD employees (the recipient-focused trigger in the exclusion), regardless of whether the sender appeared to be
internal. Because OSD conceded its claim did not fall within Rider 17’s affirmative coverage grant, the exclusion barred
recovery.
Analysis
Precedents Cited
-
Alarm Detection Sys., Inc. v. Village of Schaumburg, 930 F.3d 812 (7th Cir. 2019): Cited for the
motion-to-dismiss standard—accepting well-pleaded allegations as true and drawing reasonable inferences for the plaintiff.
This framing mattered because the case turned on contract text rather than factual disputes about the hack.
-
Brownmark Films, LLC v. Comedy Partners, 682 F.3d 687 (7th Cir. 2012): Applied to justify considering
the policy text at the pleading stage under the incorporation-by-reference doctrine, since the complaint relied on and
was centered on the bond and riders.
-
United States v. Khalupsky, 5 F.4th 279 (2d Cir. 2021): Used for an explanatory definition of “spear phishing,”
supplying context for how the compromise occurred without altering the dispositive coverage analysis.
-
Fosnight v. Jones, 41 F.4th 916 (7th Cir. 2022) and Ashcroft v. Iqbal, 556 U.S. 662 (2009):
Provided the appellate standard of review (de novo) and plausibility pleading framework, reinforcing that the case could be
resolved on unambiguous contract language.
-
Hobbs v. Hartford Ins. Co. of the Midwest, 823 N.E.2d 561 (Ill. 2005): Established that insurance policies are
contracts governed by ordinary contract interpretation rules; also supported the court’s insistence on enforcing clear policy text.
-
Thounsavath v. State Farm Mut. Auto. Ins. Co., 104 N.E.3d 1239 (Ill. 2018) and
Crescent Plaza Hotel Owner, L.P. v. Zurich Am. Ins. Co., 20 F.4th 303 (7th Cir. 2021):
Provided the core interpretive tests—enforce unambiguous terms as written; ambiguity exists only if more than one reasonable
interpretation exists.
-
Bradley Hotel Corp. v. Aspen Specialty Ins. Co., 19 F.4th 1002 (7th Cir. 2021): Supplied the rule that exclusions
are read narrowly under Illinois law and applied only when their application is “clear and free from doubt.” The court treated
the exclusion as clear despite OSD’s “internal email” theory.
-
Gallagher v. Lenart, 874 N.E.2d 43 (Ill. 2007): Anchored the whole-contract approach—intent is not derived from
isolated clauses. This supported reading Rider 17’s exclusion together with Rider 17’s grant and the overall bond structure.
-
Decatur Lumber & Mfg. Co. v. Crail, 183 N.E. 228 (Ill. 1932) and Sheehy v. Sheehy, 702 N.E.2d 200
(Ill. App. Ct. 1998): Cited for the prohibition against adding words not written. This principle did the heavy lifting against OSD’s
argument that the exclusion implicitly contained a “sender-from-outside-the-office” limitation.
-
Thompson v. Gordon, 948 N.E.2d 39 (Ill. 2011): Supported the presumption that parties choose their words purposefully.
The court used this to justify treating the presence of sender limitations in Rider 17’s affirmative coverage—and their absence in the
exclusion—as intentional.
-
Citizens Ins. Co. of Am. v. Wynndalco Enters., LLC, 70 F.4th 987 (7th Cir. 2023),
Nat'l Fire Ins. Co. of Hartford v. Visual Pak Co., 243 N.E.3d 888 (Ill. App. Ct. 2023),
and Thermoflex Waukegan, LLC v. Mitsui Su-mitomo Ins. USA, Inc., 102 F.4th 438 (7th Cir. 2024):
Provided the “illusory coverage”/conflict framework—an exclusion creates ambiguity only when it swallows or nullifies the coverage grant.
The court relied on these cases to reject OSD’s argument that Rider 17’s exclusion impermissibly conflicted with Rider 13.
Legal Reasoning
-
Policy structure and the decisive drafting choice (recipient-focused exclusion).
Rider 17 contained both (a) an affirmative coverage grant for certain email-initiated transfer frauds (limited to instructions
purporting to originate from specified third-party categories such as a “Customer”), and (b) an exclusion that bars losses resulting
“directly or indirectly” from OSD transferring funds in reliance on a “fraudulent instruction sent to [OSD] through electronic mail,”
except when the loss falls within Rider 17’s affirmative grant. OSD conceded the claim did not satisfy Rider 17’s affirmative grant,
leaving only the exclusion question.
-
“Sent to [OSD]” includes internal recipients.
The court treated “sent to” as a plain-recipient concept. The hacked emails were sent to OSD employees and contained fraudulent instructions
that caused transfers. On that text, the exclusion applied. OSD’s attempt to recharacterize the emails as “sent within the Office” failed as
“semantics,” because internal transmission does not negate that the message was “sent to” the insured recipient.
-
No implied “external sender” limitation.
OSD argued that Rider 17’s exclusion should be read to apply only to emails originating outside OSD, pointing to (i) the affirmative coverage’s
explicit sender categories and (ii) other parts of the bond that expressly addressed intra-company communications in other contexts (fax/telephone).
The court rejected this because:
- Whole-contract reading (Gallagher v. Lenart) cannot justify importing new words;
- Courts may not add language (Decatur Lumber & Mfg. Co. v. Crail; Sheehy v. Sheehy); and
- Drafting differences are presumed intentional (Thompson v. Gordon): the affirmative grant had sender limits; the exclusion did not.
The exclusion, as written, turned on the recipient (“sent to [OSD]”), not the sender.
-
Rider interplay: exclusion can narrow Rider 13 without creating ambiguity.
OSD argued Rider 13 (computer systems fraud) covered the hack and that applying Rider 17’s exclusion would conflict with Rider 13. The court held that
both riders modified the entire bond and Rider 13’s coverage remained “subject to” exclusions, including Rider 17’s exclusion.
Even if some email-based computer systems fraud otherwise within Rider 13 is removed by Rider 17’s exclusion, that does not create ambiguity unless
the exclusion makes coverage illusory. Applying Citizens Ins. Co. of Am. v. Wynndalco Enters., LLC,
Nat'l Fire Ins. Co. of Hartford v. Visual Pak Co., and Thermoflex Waukegan, LLC v. Mitsui Su-mitomo Ins. USA, Inc.,
the court found “plenty of room for coverage” remained under Rider 13 for computer systems fraud not involving reliance on fraudulent instructions sent by email to OSD.
Impact
The decision clarifies (at least under Illinois-law contract principles as applied by the Seventh Circuit) how “email initiated transfer fraud”
exclusions operate in internal-compromise scenarios:
-
Internal-account compromise is not a loophole. If the exclusion is drafted around the instruction being “sent to” the insured,
the fact that the email arrives from a compromised internal account does not prevent the exclusion from applying.
-
Coverage grants and exclusions may be intentionally asymmetrical. The court validated a drafting approach where affirmative email-fraud
coverage is narrowly defined (e.g., customer-impersonation scenarios), while the exclusion broadly removes other email-reliance losses unless the narrow grant is met.
-
“Conflict” arguments face a high bar. Policyholders attacking exclusions by pointing to overlapping coverage elsewhere must show the exclusion
swallows the coverage (illusory coverage), not merely that it narrows it in a way that seems surprising in a particular fact pattern.
-
Pleading-stage resolution is likely when text is clear. Because the court applied incorporation-by-reference and treated the dispute as purely textual,
similar coverage disputes may be resolved early, without discovery, where the operative emails and policy language fit the exclusion’s plain terms.
Complex Concepts Simplified
-
“Rider”: An add-on document that modifies the main insurance policy. Here, Riders 13 and 17 both became part of the bond and must be read together.
-
“Affirmative coverage” vs. “exclusion”: The coverage grant says what the insurer will pay for; the exclusion says what it will not pay for.
A claim can fail even if it seems to fit a coverage grant if an exclusion clearly applies.
-
“Sent to [the insured]”: The court treated this as a recipient-focused phrase. If an email instruction is delivered to the insured’s organization
(here, its employees), it is “sent to” the insured—even if the sender appears internal.
-
“Ambiguity”: Not just uncertainty or unfairness in outcome; it exists only if policy language supports more than one reasonable interpretation.
-
“Illusory coverage”: Coverage is illusory when exclusions effectively eliminate the promised coverage. Narrowing coverage is permissible if meaningful
coverage still remains.
-
“Spear phishing”: A targeted email trick used to steal credentials. The method explains how the fraudsters gained control of the CFO’s account,
but the case turned on the policy wording about email instructions and reliance.
Conclusion
Office of the Special Deputy Receiver v. Hartford Fire Insurance Company establishes a clear interpretive rule for this bond language:
when an exclusion applies to loss caused by reliance on a fraudulent instruction “sent to” the insured by email, that exclusion can bar coverage even if the email
is transmitted internally using a compromised employee account. The court refused to rewrite the contract by importing an “external sender” limitation, and it held
that overlap between a computer-fraud coverage grant (Rider 13) and an email-instruction exclusion (Rider 17) does not create ambiguity unless the exclusion makes
the coverage illusory. The decision underscores that in social-engineering and business email compromise losses, the outcome often hinges on precise allocation of
risk in the policy’s email-related riders and exclusions—and courts will enforce those allocations as written.