Packaging Products Manufacturing Company
A phishing attack caused a business email compromise at a manufacturer, diverting customer payments. Travelers responded the same day, helping to cover losses and prevent further fraud.
Case study overview
A phishing attack targeting a mid-sized manufacturer led to fraudulent customer payments being diverted to a threat actor. The company incurred a financial loss when its customer unknowingly transferred funds to the threat actor’s account. A quick response from Travelers enabled the insured to confirm the scope of the incident, engage forensic and legal experts and implement employee training to prevent future compromises.
(DESCRIPTION)
Logo: Corvus By Travelers. A white umbrella sits next to the word "Travelers." Text: Risk Prevention Case Study, Manufacturing Industry. Two people stand inside a warehouse filled with boxes and steel shelves. Christine Mapes, Managing Director and Counsel*, Travelers Insurance. *Company Employee adjuster.
(SPEECH)
Today I'm going to tell you about a real claim situation we saw recently.
(DESCRIPTION)
A young man sits in front of a computer. Then a letter appears onscreen asking for future invoice payments to be redirected to a different account with bank details included. Text at bottom left corner of screen: This image is fictional and for illustrative purposes only.
(SPEECH)
An employee's email was compromised through a phishing attack. The attacker used that access to impersonate the employee and redirect customer payments, leading to significant financial loss and potential reputational damage when invoices went unpaid.
(DESCRIPTION)
Several professionals converse with each other.
(SPEECH)
Travelers assigned a claim professional right away and coordinated forensics, legal guidance, and law enforcement reporting. This quick action confirmed the scope of the breach while containing the threat and helping to prevent further fraudulent transfers. The investigation found that email security and payment verification procedures left gaps that the attacker exploited.
(DESCRIPTION)
A man focuses his attention on the computer screen in front of him, eyebrows drawn down.
(SPEECH)
Travelers' Cyber Risk Services team worked with the company to strengthen their authentication procedures and implement out-of-band confirmation for wire transfers. Even the most cautious organizations can be tricked.
(DESCRIPTION)
Three boxes appear onscreen. The top box is labeled ""Layered Security" and contains icons labeled "Phishing-resistant MFA" and" Regular employee training." The middle box is labeled "Clear procedures" and contains icons labeled "Out-of-band authentication' and "Use of verified contact information." The last box is labeled "Quick response" and contains icons labeled "Experienced cyber claim team" and Specialized forensics investigation."
(SPEECH)
That's why layered security, clear procedures, and quick response make all the difference in helping stop fraud before it spirals.
[MUSIC PLAYING]
(DESCRIPTION)
Logo: Corvus By Travelers. A red umbrella sits next to the word "Travelers." Text: Learn more about how to protect businesses against cyber threats: www.corvus insurance.com/cyber-risk-services.
Travelers Casualty and Surety Company of America and its property casualty affiliates. One Tower Square Hartford, CT 06183. This material does not amend, or otherwise affect, the provisions or coverages of any insurance policy or bond issued by Travelers. It is not a representation that coverage does or does not exist for any particular claim or loss under any such policy or bond. Coverage depends on the facts and circumstances involved in the claim or loss, all applicable policy or bond provisions, and any applicable law. Availability of coverages referenced in this document may depend on underwriting qualifications and state regulations. Case studies are based on actual situations, composites of actual situations or hypothetical situations. Resolution amounts are approximate of both actual and anticipated losses and costs. Facts may have been changed to protect confidentiality. Copyright: 2025 The Travelers Indemnity Company. All rights reserved. Travelers and the Travelers Umbrella logo are registered trademarks of The Travelers Indemnity Company in the U.S. and other countries.
The challenge
The incident began when a company employee unknowingly engaged with a phishing email, allowing a threat actor to compromise the employee’s email account. Using this access, the threat actor impersonated the employee and convinced a customer to change its usual method of payment from checks to ACH transfers. Believing the instructions were legitimate, the customer sent multiple payments directly to the threat actor’s account.
The fraudulent scheme went undetected for months until the insured reached out about overdue invoices and learned the customer believed it had already paid. At that point, the company not only faced the immediate financial loss, but also the possibility that sensitive data could have been exposed. In addition, there was a risk of reputational damage with key customers and potential regulatory obligations if the compromise extended beyond the single account.
Corvus by Travelers' response
Once the organization discovered that funds had been misdirected, it filed a claim with Travelers. The Travelers Cyber Claim team assigned a dedicated claim professional to the case and initiated a coordinated response process, including.
- Forensic investigation: A panel forensic team was engaged to confirm the scope of the intrusion and determine whether any systems or data beyond the single compromised account were impacted.
- Legal guidance: A data breach coach conducted a legal risk assessment, confirming that the company had no notification obligations arising from the incident.
- System containment: The compromised email account was locked and the credentials reset to prevent further unauthorized access.
- Law enforcement reporting: The insured filed reports with its local police department and with the FBI’s Internet Crime Complaint Center (IC3) portal.
- Customer protection: With assistance from the data breach coach and forensics team, the insured was able to alert another customer that received similar fraudulent payment instructions from the threat actor, preventing further losses.
Results & policy benefits
The coordinated response led by Travelers helped the manufacturer contain the incident quickly and limit its impact. The financial loss, along with the costs of forensic investigation and data breach coach, were covered under the company’s cyber policy.
Importantly, the company avoided further losses by quickly warning another customer and working with Travelers, their data breach coach and forensic experts to contain the threat. As a result, the company maintained uninterrupted operations, preserved customer trust and strengthened its defenses with new employee phishing training.
Note: Business email compromise continues to be one of the most common cyber threat vectors. From January 1, 2023, to December 31, 2024, Travelers managed more than 2,300 claims related to phishing and social engineering fraud, two common business email compromise schemes.
These incidents often lead to financial losses, and in many cases, provide threat actors with access that can escalate into a ransomware attack.
This material does not amend, or otherwise affect, the provisions or coverages of any insurance policy or bond issued by Travelers. It is not a representation that coverage does or does not exist for any particular claim or loss under any such policy or bond. Coverage depends on the facts and circumstances involved in the claim or loss, all applicable policy or bond provisions, and any applicable law. Availability of coverage referenced in this document can depend on underwriting qualifications and state regulations. Case study is based on actual situations, composites of actual situations or hypothetical situations. Resolution amounts are approximations of both actual and anticipated losses and costs. Facts may have been changed to protect confidentiality.