This post uses hypothetical scenarios for illustrative purposes only. It does not describe any actual client, transaction, or representation, and is not legal advice.
Picture the last day of a Florida business sale. The purchase agreement is signed, the funds-flow spreadsheet has been through eleven versions, and everyone is watching for the fed reference number. At 9:40 the night before, an email arrives from the seller’s controller — same name, same signature block, same reply chain — saying the company’s bank has “flagged an issue” with the account on file and attaching updated instructions for a different bank. The buyer’s paralegal updates the spreadsheet. The wire goes out at 10:15 the next morning. The money is gone by lunch, and not to the seller.
Nothing about that sequence is exotic. Business email compromise is boring, high-volume crime — the FBI’s Internet Crime Complaint Center has tracked billions of dollars in annual BEC losses for years, and deal closings are a favorite target because the attacker knows a large wire is coming, knows roughly when, and has often been reading both sides’ email for weeks. The interesting question, for people who paper deals, is the one the parties confront the day after: the buyer says it paid, the seller says it was never paid, and somebody is out a seven-figure wire. Who eats it?
The courts ask who was in the best position to stop it
There is no purpose-built statute for misdirected closing wires, so courts have reasoned by analogy — most often to the UCC’s imposter rule, which puts a forgery loss on the party whose conduct made the forgery effective. The case Florida deal lawyers should know is Arrow Truck Sales v. Top Quality Truck & Equipment, out of the Middle District of Florida in 2015. A truck buyer wired approximately $570,000 for a fleet purchase after receiving competing invoices with conflicting wire instructions — one real, one from a hacker who had slipped into the email thread. The buyer picked the wrong one without calling to confirm. The court put the loss on the buyer: faced with conflicting instructions, the payor was the party best positioned to prevent the fraud by picking up the phone, and it didn’t.
The Sixth Circuit’s Beau Townsend Ford Lincoln v. Don Hinds Ford decision in 2018 runs the same logic from the other direction. There, the seller’s email account was the one compromised — the attacker sat inside it, set forwarding rules, and sent the buyer instructions for a fraudulent account, which the buyer paid to the tune of roughly $700,000. The trial court had given the seller summary judgment on the theory that payment to the wrong account is simply non-payment. The Sixth Circuit reversed, reasoning that a seller whose own inbox security failures enabled the fraud is at least partially responsible for the loss, and sent the case toward a comparative allocation.
Put the two lines together and the doctrine, such as it is, comes to this: courts typically assign the loss to the party whose negligence let the fraud work — the payor who didn’t verify, or the payee whose systems were breached — and increasingly they are willing to split it when both failed. That is a fact-intensive, litigation-shaped answer. In most cases it means two victims spending eighteen months and real legal fees arguing over which of them was more careless. The drafting lesson is that you do not want a court answering this question at all.
The funds-flow memo should be a contract, not a spreadsheet
The standard closing set already contains the fix in embryonic form. Every deal has a funds-flow memorandum listing each payee, each amount, and each account — sellers, payoff lenders, escrow agents, advisors with fee letters. What most deals do not do is give that document any legal significance. It circulates as an Excel attachment, editable by anyone and authenticatable by no one, which is exactly the artifact the attacker is waiting to replace. The payoff and fee amounts feeding it deserve their own scrutiny — that is the territory of the indebtedness definition and the cash-free, debt-free mechanics — but the account numbers deserve a security protocol.
Three provisions do the work. First, lock the instructions in the agreement itself: payment to the accounts specified in the executed funds-flow memo discharges the buyer’s payment obligation, full stop. Once discharge is contractual, a seller who wants to claim non-payment must attack its own signed document rather than argue about emails. Second, make changes hard by design: wire instructions may be modified only by a writing signed by a named officer and confirmed by voice call to a phone number listed in the agreement — a number written down at signing, not one supplied in the change request. The callback-to-a-known-number step is the single control that defeats nearly every BEC variant, because the attacker controls the inbox but almost never the phone. Third, allocate the residual risk expressly: a clause saying that a party whose payment systems or email accounts are compromised bears losses caused by instructions originating from that compromise. That converts the Beau Townsend comparative-fault fight into a rule the parties chose in advance.
Process beats paper when the wire is imminent
The contract language matters because it assigns the loss, but the loss is better avoided than assigned. The likely outcome of a callback protocol, honestly followed, is that the fraud simply fails. So the sell-side closing checklist — the same one that runs the NDA-to-term-sheet process at the front of the deal — should treat the final seventy-two hours as a security window. Instructions get exchanged early, verified by phone, and then frozen; every participant, including the paralegals and the escrow agent who actually push the buttons, is told in writing that any late change to any account is presumed fraudulent until verified by voice; and the first wire out is a small test wire confirmed received before the balance moves. None of this costs anything. All of it is easier than explaining to a founder that the retirement proceeds are in an account in another country.
One more layer deserves a sentence: insurance. Standard crime policies historically fought BEC claims on the theory that a voluntarily sent wire is not a “hacking” loss, and the coverage litigation of the late 2010s went both ways. The market response is the social-engineering-fraud endorsement — typically sublimited, but purpose-built for exactly this loss. A seller expecting a nine-figure wire and a buyer sending one should each know, before closing week, whether that endorsement is on their tower and at what limit.
Speed is the only real remedy after the fact
If the wire has already gone, the useful window is measured in hours. The bank should be told immediately and asked to attempt a recall and freeze; the FBI’s IC3 operates a recovery process that can sometimes intercept funds still sitting at the first-hop domestic bank, and its success rate drops steeply after the first day or two. After that, what remains is the litigation described above — which, as Arrow Truck and Beau Townsend teach, tends to find fault on both sides of the closing table and cannot guarantee either victim a recovery. The drafting cannot guarantee the fraud never happens, but it can decide in one paragraph what would otherwise take a lawsuit to decide.
If you are heading into a closing and want the funds-flow process hardened before the money moves, feel free to reach out to my firm manager, Magda, at Magda@montague.law, or fill out our contact form. Mention you read this post.


