$3.04 billion left US organizations last year on payment instructions that looked legitimate. Almost none of it came back.
For organizations where one instruction can move six figures.
For twenty years the control for a suspicious payment instruction was a phone call to a voice you recognize. It assumed a voice was hard to fake and a face was harder. Neither assumption survived.
The FBI logged more than 22,000 complaints referencing AI in 2025, with $893 million in associated losses. Detection is not the way out of this, because it is a bet that your filter keeps beating a model that improves every month. Authenary does not try to tell you whether the call was real. It asks the person.
The Bureau's Recovery Asset Team can ask receiving banks to freeze an account through the Financial Fraud Kill Chain. It works, when it is reached in time. The clock is the problem.
Three pieces of standard policy language decide what you actually collect after a fraudulent wire, and most buyers do not read them until the claim is filed.
Social engineering and funds transfer fraud are commonly capped between $25,000 and $250,000, inside a policy with a far larger headline limit. A $300,000 wire against a $100,000 sublimit leaves most of the loss with you.
Many crime and cyber policies exclude losses arising from the voluntary parting of funds. Your employee initiated the transfer. Carriers and courts do not treat deception consistently as an override.
Many endorsements condition payment on verification before the transfer: a callback to a number already on file, dual authorization above a threshold, independent confirmation of any banking change. No verification, no claim.
A Mississippi manufacturer wired more than $1 million on new payment instructions from what appeared to be a known supplier. A federal court held the loss capped at the policy's social engineering sublimit rather than its full limit. Separately, several carriers narrowed or excluded AI-generated content at 2026 renewals, so policies renewed this year may not cover deepfake-driven fraud at all. Read your definitions and exclusions before you need them.
We still recommend cyber insurance. But your policy already asks you to verify a request out of band before the money moves, and it asks you to show that you did. Authenary is that verification, and it produces the proof.
Wires over $25,000. Any change to vendor banking details. Sensitive document releases. Executive password resets. Your thresholds, your approvers.
Whoever received the instruction enters the exact action: amount, beneficiary, account, and how the request reached them.
The approver named by your policy gets it on their enrolled phone, sees exactly what is being authorized, and approves or denies with Face ID.
A signed, tamper-evident record of who approved what and when. Verifiable by anyone you hand it to, without giving them access to anything else.
Where we see this most often
Priced per approver per month, billed annually. Two approver minimum. Unlimited staff submitting requests, unlimited verifications, no per-transaction fee.
| Approvers | Essential | Advanced |
|---|---|---|
| 1 – 5 | $149 | $249 |
| 6 – 15 | $119 | $199 |
| 16 – 50 | $89 | $149 |
| More than 50 | Talk to us | Talk to us |
Twenty minutes, your real approval thresholds, and a live verification on your own phone.
Or write to us directly