Theft Without a Thief: Participant Account Cybercrime, the Limits of the §412 Bond, and the Fiduciary Exposure Left Behind
ERISA bond cyber theft claims arrive at our underwriting desk with increasing regularity, and they nearly always begin the same way. A participant’s retirement account has been drained through a fraudulent distribution request. The plan sponsor, having dutifully maintained the fidelity bond that Section 412 of the Employee Retirement Income Security Act commands, tenders the loss to the surety and expects indemnity. The surety declines. The sponsor is incredulous. The participant sues. The sequence is now common enough that it deserves careful doctrinal treatment, because the instinct that produces the tender — “we were bonded, therefore we are covered” — rests on a misreading of what the ERISA fidelity bond is, whom it covers, and what Congress asked it to do.
What the §412 Bond Actually Insures
Section 412 requires that every fiduciary of an employee benefit plan, and every person who “handles funds or other property” of the plan, be bonded against loss “by reason of acts of fraud or dishonesty.” The operative regulation, 29 C.F.R. §2580.412-9, defines fraud or dishonesty to encompass larceny, theft, embezzlement, forgery, misappropriation, wrongful abstraction, wrongful conversion, and willful misapplication — an expansive catalogue, but a catalogue of acts committed by the bonded persons. The companion regulation at §2580.412-6 supplies the functional “handling” test: physical contact with cash or checks, authority to transfer or disburse, signatory power, supervisory or decision-making responsibility over activities that place plan assets at risk of loss through dishonesty.
The architecture is deliberate. Congress, legislating in the shadow of mid-century pension corruption, was concerned with the insider — the trustee, the administrator, the officer with his hand in the till. The bond is a first-party fidelity instrument protecting the plan against the dishonesty of its own people. It is not a crime policy, not a cyber policy, and not a guarantee that plan assets will never disappear.
Now place the modern account-takeover loss against that architecture. A criminal in another hemisphere harvests a participant’s credentials through phishing or credential-stuffing, impersonates the participant through the recordkeeper’s web portal or call center, changes the address of record, and requests a full distribution to a fraudulent bank account. Every element of the §412 trigger fails. The perpetrator is not a fiduciary. The perpetrator is not a person handling plan funds within the meaning of §2580.412-6; he was never authorized to touch anything. His act, though undoubtedly theft in the criminal sense, is not an act of fraud or dishonesty by a bonded handler, which is the only species of theft the bond form contemplates. The recordkeeper’s customer-service representative who processed the distribution acted without dishonest intent and, in most fact patterns, in facial compliance with the plan’s distribution procedures. There is theft, but for bond purposes there is no thief.
Sureties writing on standard forms have accordingly and correctly declined these tenders, and the Department of Labor’s own guidance (Field Assistance Bulletin 2008-04 remains the touchstone) confirms that the bond responds to dishonesty by covered persons, not to third-party criminality directed at the plan from outside. Sponsors who wish to understand precisely where their bond begins and ends, and to structure compliant coverage in the correct penalty, should consult the practitioner resources and application library we maintain at ERISA-Bonds.com. But no amount of careful bond placement converts a fidelity instrument into cyber coverage, and it is professional malpractice for any producer to suggest otherwise.
Where the Loss Actually Lands: Section 404 and the Governance Theory
If the bond does not respond, the loss does not evaporate. It migrates and it migrates toward the fiduciaries. The participant whose account has been emptied does not sue the anonymous hacker. She sues the plan sponsor, the administrative committee, and the recordkeeper, and she pleads the case not as a theft case but as a prudence case under ERISA §404(a)(1)(B): the fiduciaries breached their duty of care by maintaining, or tolerating, distribution and authentication procedures inadequate to the known threat environment. The litigation of the last several years has given the theory real shape. In Leventhal v. MandMarblestone Group (E.D. Pa. 2019), claims survived dismissal where fraudulent withdrawal requests were processed without adequate verification. In Bartnett v. Abbott Laboratories (N.D. Ill. 2020), the court dismissed claims against the sponsor while allowing the participant to proceed against the recordkeeping-adjacent service entity, illustrating that the allocation of exposure turns on granular facts about who performed which authentication function. In Berman v. Estee Lauder, a participant whose account was drained of roughly $99,000 obtained a confidential resolution after suing sponsor and recordkeepers alike. And in Disberry v. Employee Relations Committee of Colgate-Palmolive Co. (S.D.N.Y. 2022), the court permitted a full account-takeover case to proceed against the committee, the recordkeeper, and the custodian, reasoning that a plausible imprudence claim lies where red flags in the distribution process went unheeded.
The Department of Labor has amplified the exposure. Its April 2021 cybersecurity guidance, the tripartite release covering service-provider selection, cybersecurity program best practices, and participant online-security tips, announced the Department’s view that cybersecurity is squarely a fiduciary function. Compliance Assistance Release 2024-01 then confirmed that the guidance applies to all ERISA-covered plans, including health and welfare plans, not merely retirement plans. The practical consequence is that a documented cybersecurity governance process, i.e., vendor due diligence, contractual allocation of liability for account restoration, periodic testing of authentication protocols, is now part of the prudence baseline. A committee that cannot produce that record after an account drain is a committee litigating from a hole.
Note the elegant cruelty of the migration. The criminal act that the fidelity bond excludes becomes the evidentiary predicate for a personal-liability claim that ERISA §409(a) enforces against the fiduciaries individually, and that §410(a) forbids the plan to indemnify away. The sponsor’s officers discover, at the worst possible moment, that the only instrument in the insurance stack that responds to the ensuing litigation is fiduciary liability coverage purchased under the §410(b) safe harbor, a coverage that ERISA never required them to buy. Defense costs in these actions accrue quickly; the Disberry pattern of suing committee, recordkeeper, and custodian simultaneously guarantees a multi-front defense; and the settlement calculus is driven by the sympathetic fact of a retiree’s emptied account. For plan sponsors and committee members evaluating the scope, exclusions, and limits adequacy of that protection, our analysis and placement resources at FiduciaryLiabilityCoverage.com address the underwriting considerations specific to cybersecurity-governance exposure, including the interaction between fiduciary forms and the sponsor’s cyber and crime programs.
The Underwriting Problem of the Decorative Endorsement
A final word on a market development we view with some skepticism. Several carriers now offer “cyber” endorsements to ERISA fidelity forms, and producers occasionally present them as closing the gap described above. Read the forms. Most such endorsements extend the definition of covered acts to computer fraud committed by bonded persons, a genuine but narrow improvement, or provide modest sublimits for social-engineering losses subject to verification-procedure conditions precedent that the typical account-takeover fact pattern will fail. An endorsement that pays only when the plan’s people followed authentication procedures that, had they been followed, would have prevented the loss, is an endorsement that decorates the bond rather than expands it. The sponsor’s protection against the account-takeover epidemic is not found in the fidelity market at all. It is found in prudent cybersecurity governance, in contractual restoration guarantees extracted from recordkeepers, and in properly structured fiduciary liability coverage against the litigation that follows when the first two fail.
The §412 bond remains what it has been since 1974: a mandatory, valuable, and narrow instrument aimed at the dishonest insider. The modern thief never enters the building. Plans should be bonded because the law requires it and the insider risk is real. Fiduciaries should be separately insured because the outsider risk is now the one that finds them personally. Conflating the two instruments was always an analytical error. In the account-takeover era, it is an expensive one. Follow our ERISABlog for up-to-date news and information in the ERISA field.
~ C. Constantin Poindexter, MA, JD, CPCU, AFSB, ASLI, ARe, AINS, AIS, CPLP








