As a general partner, you already manage a long list of risks: subscription agreement legalese, personnel matters, fundraising, and thematic bets gone awry.
Wire fraud targeting your limited partners belongs on that list, too, and it’s a particularly insidious risk. Why? Because wire fraud preys upon the unseen vulnerabilities of your LPs, and those are a huge problem.
In 2025, the FBI received almost 25,000 reports of business email compromise (BEC). That’s almost 68 cases per day and those are just the reported cases. Factor in the average financial loss of $123,000 per claim, and you easily run up a significant contribution to an overall cyber crime problem that surpasses $20 billion annually, and that’s only in the United States.
With numbers like that, the potential for criminals sitting in your LP’s email inbox suddenly becomes a risk you can’t afford to ignore.
Your LP's cybersecurity matters more than yours
This is the uncomfortable truth: when it comes to preventing funds transfer fraud, your own cybersecurity can’t detect or prevent a compromise of your LP’s systems.
Within your own environment, you can buy every best-in-class cybersecurity solution, pass every audit, and have an award-winning managed security service monitoring your networks for threats. While those may protect you from a fraudster gaining access to your accounts and impersonating you on a capital call to your LP, it won’t protect you from a fraudster who is impersonating your LP from inside the LP’s own email account.
When the fraudster emails your team with updated payment instructions, it looks like a legit message because it is from your known LP’s account, but the person behind it is a fraud, and your cybersecurity won’t detect or stop it. That’s the core problem, and it’s why we’re here (more on that below).
Third-party risk is notoriously hard to manage, and most attempts at it come down to machine-to-machine security controls, questionnaire-based attestations, or a compliance framework checklist. With hundreds or even just a handful of LPs on your balance sheet, your exposure to fraudulent payment instructions scales directly with your LP count.
Reputation loss is existential
Your reputation is harder to rebuild than your balance sheet. If word gets out that an LP distribution was lost to negligence or a lapse in controls, the hit to your reputation can be significant. It’s an own goal that makes your next raise harder for a long time.
Private equity and venture capital funds operate like marketplaces: on one side, investors choosing which funds to back; on the other, portfolio companies choosing which funds to take money from. Your success depends on both sides having trust in your brand.
A conspicuous loss event doesn’t just cost you money. It can suppress both the supply and demand of capital moving through your fund, and that can pose an existential problem.
How LP distribution fraud happens
These are the main threat vectors you’ll want to be mindful of when fortifying your firm against distribution fraud. Investing in a robust security awareness training program for your team is a good idea since fraudsters target employees at all levels, typically using one of these tactics:
- LP email account takeover. They gain control of an LP’s inbox and send your fund accountant a message about updated payment instructions. With access to that inbox, they have all the cover and context they need to time a convincing request.
- Phone impersonation. They call your accounts payable department, claim to work for an organization or LP you already know, and provide fraudulent payment instructions for an account they control. SIM swapping lets them clone a real person’s phone number digit-for-digit, so the call looks completely legitimate.
- Referral setup via text. They text you impersonating an LP you have a relationship with, and ask who they should contact to update payment information. That internal referral makes the follow-up call to your fund coordinator far more convincing.
It’s easy to picture your fund accountant receiving a message with a screenshot of your own text attached, telling the fraudster to reach out to them.
A message that says “John Smith (your name here) told me to update my banking information with you” is the kind of manufactured confidence that is often a fraudster’s powerful lever in social engineering attacks against your people and processes.
What to do if you make a fraudulent distribution
If you suspect you’ve been hit by LP distribution fraud, there’s a chance you can still recover the funds, but you will have to move quickly. The moment you suspect something is wrong, follow these steps:
- Engage your cyber insurance carrier. While fraud prevention is always preferable to remediation, an insurer’s cyber incident response team (CIRT) can start an investigation and coordinate the remaining steps with their panel partners. (If you don’t have cyber insurance, get it, and make sure it covers funds transfer fraud.) The insurance carrier will often handle steps 2 through 5 below.
- Contact your bank. Despite what your bank might have told you, wire transfers can sometimes be stopped before they reach a fraudulent account. The faster you move, the better your odds of clawing the money back.
- Start an investigation. Whether internal, third-party, or both, use your cybersecurity resources to find out how the fraud happened. You need to identify the point of failure, even if that means an uncomfortable conversation with an LP about the state of their security.
- Talk to counsel. Your legal team can help you determine your total exposure. Do your subscription agreements indemnify you against losses from LP negligence or insufficient cybersecurity? Your attorney should know.
- Line up a crisis communications firm, just in case. Funds transfer fraud rarely makes headlines the way ransomware does. Fraudsters already have your money and don’t need to shame you into paying. Still, be ready to protect your reputation if word does get out about a loss.
Secure your LP distributions with DoubleCheck
Even with the breadth and depth of your limited partners’ cybersecurity being almost impossible to assess, you still need to be able to pay them securely.
You also need to take into account the friction in your instruction verification process. Your LPs’ time is valuable as is your team’s.
This is why we built DoubleCheck. It’s fast and easy for your LPs to submit payment instructions, and once they do, you’re covered by our guarantee.
Forget calendar coordination for callback scheduling or wondering if you paid the right account.
DoubleCheck works on your schedule, gives you the peace of mind that the person on the receiving end of your payment is who they say they are, and that your funds are going to the account they specify.
Get a demo today and see how you can protect your distributions from LP distribution fraud.