Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

BOLO: Cyber Attacks Against Retirement Plan Accounts

By Beth Alcalde & Christy S. Hawkins on April 22, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

Employer-sponsored retirement plans have long been targets for cybercriminals. Employers should be on the lookout as the COVID-19 pandemic has expanded the types and likelihood of potential cyber attacks against retirement plan accounts. After all, with many more Americans working remotely, interfacing with the secure plan recordkeeping sites is occurring around the clock from a wide range of personal computing devices. Americans have more reason now than ever to stay on top of their retirement accounts, due to a combination of general market uncertainty, workforce disruptions, and the adoption of corporate 401k plan amendments pulling back on company matching contributions or revising the definition of plan-eligible compensation definition. Also, the CARES Act relaxed plan in-service distribution rules in the event of a COVID-19 financial strain, and similarly expanded 401k plan loan procedures for COVID-19 reasons. It is arguable that never before have plan participants been flocking to this extent to their retirement plan accounts and remotely initiating various elective directions to plan custodians.

This new reality has set the stage for emerging areas of cyber liability. There are a number of helpful tips for employers sponsoring retirement plans in times of pandemic. For example, many plan sponsors are working with their outside plan recordkeepers to develop enhanced substantiation of electronic transfer instructions. From a fiduciary oversight perspective, plan fiduciaries are also taking seriously their obligations to review and monitor over time the privacy and security systems of their outside plan service providers. Also, plan fiduciaries are reviewing their existing ERISA fiduciary liability insurance policies, cyberinsurance, fidelity bonds, and general corporate errors and omissions policies to ascertain whether COVID-related cyber liability is already covered, or rather if a separate endorsement is available and advisable. Specifically, policies or endorsements should cover a variety of fact patterns involving business email compromise scams such as the following:

  • when a bad actor obtains the credentials for an company’s existing employee who is authorized to interact with a retirement plan service provider, and then postures as that employee in order to send fraudulent wire instructions to a plan trustee or custodian to misdirect contributions to or distributions from the retirement plan;
  • when a bad actor obtains the credentials for one of the company’s retirement-plan service providers and sends improper instructions to that plan sponsor with fraudulent wire instructions, instructing the corporate plan sponsor to pay the bad actor instead of the real outside vendor; or
  • combination of the above.

In many instances, separate insurance endorsements will be needed. Proceeding without adequate insurance is risky, given that the ultimate question of which entity(ies) would bear responsibility for plan losses is critical but unsettled. These types of compromise scams present a relatively new issue, and the law is far from settled across the U.S. In fact, in many jurisdictions, this issue hasn’t even been addressed by published court opinions. Therefore, companies that sponsor qualified retirement plans should work with their insurance brokers and outside privacy and security advisers to evaluate and mitigate such risks.

If you need further guidance with respect to your employer sponsored plans, contact your Akerman lawyer.

Photo of Beth Alcalde Beth Alcalde

A noted employee benefits lawyer, author, and speaker, Beth Alcalde represents Fortune 500 companies and other public and private entities, including those in the hospitality, healthcare, and higher education sectors, throughout the United States. As a leader within the firm, Beth is a…

A noted employee benefits lawyer, author, and speaker, Beth Alcalde represents Fortune 500 companies and other public and private entities, including those in the hospitality, healthcare, and higher education sectors, throughout the United States. As a leader within the firm, Beth is a longtime member of Akerman’s Board of Directors, and is also a current member of Akerman’s Executive Committee. Previously she chaired the firm’s Professional Development Committee, and served as office managing partner of the firm’s Palm Beach County offices. Noted in Chambers USA as “terrific at coming up with imaginative solutions,” Beth provides counsel on employer-sponsored benefit plans, from compliance with ERISA, the Affordable Care Act, and other federal regulations, to internal audits and benefits-related implications of corporate transactions. She assists clients in defending and responding to audits conducted by the Internal Revenue Service (IRS), U.S. Department of Labor (DOL), and U.S. Department of Health and Human Services (HHS). Of particular emphasis, Beth has represented group health plan sponsors in responding to audits of the quantitative and non-quantitative treatment limitations within their plans, as required by the Mental Health Parity and Addiction Equity Act.

Read more about Beth AlcaldeEmail
Show more Show less
Photo of Christy S. Hawkins Christy S. Hawkins

Christy Hawkins (CIPP/US, CIPP/E, CIPM, FIP, PLS) focuses her practice on privacy, cybersecurity, and incident response. She advises clients on state, federal, and international data security and privacy issues, including compliance and risk management. She supports organizations of all sizes and in various…

Christy Hawkins (CIPP/US, CIPP/E, CIPM, FIP, PLS) focuses her practice on privacy, cybersecurity, and incident response. She advises clients on state, federal, and international data security and privacy issues, including compliance and risk management. She supports organizations of all sizes and in various market sectors, including financial institutions, healthcare, hospitality, human resources, e-commerce, insurance, pharmaceutical, software/SaaS, and security. Christy conducts risk assessments and prepares key documentation, such as incident response plans, privacy policies and notices, and contracts addressing privacy and cybersecurity and beyond. As a first responder to potential data breaches and privacy incidents, Christy helps companies investigate, evaluate, respond, and recover. Her work includes completing investigations; identifying and coordinating with vendors to provide forensics, identity monitoring and restoration, and call centering services; evaluating legal and regulatory obligations; preparing notification communications; and engaging in reviews for lessons learned following incidents.

Read more about Christy S. HawkinsEmail
Show more Show less
  • Posted in:
    Employment & Labor, Privacy and Cybersecurity
  • Blog:
    HR Defense
  • Organization:
    Akerman LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo