Skip to the stories

/Independent trade coverage

TC Bulletin

The trade record for transaction coordinators

Every figure on this site is attributed to a named primary source, dated, and corroborated where vendor data is involved.

Fraud & Closing SecurityToday

A title agency's 30-day notice deadline started at the IT review, not the lawsuit

A federal court dismissed Heart of Gold Title's coverage claim over a $480,150 diverted wire, ruling its cyber policy's notice clock began when the agency's own IT vendor investigated in March 2024, seven months before it told its insurer. The agency's cover was gone before the lawsuit that prompted the claim was even filed.

TC Bulletin Staff8 min readRead as markdown

What this story establishes

  • Spinnaker Insurance Company v. Heart of Gold Title, LLC, No. 2:25-cv-00330, was decided by the U.S. District Court for the Southern District of Ohio on 13 March 2026. The court dismissed the title agency's counterclaims with prejudice.
  • A buyer wired $480,150 to fraudulent instructions on 6 March 2024 after a spoofed email impersonating a Heart of Gold employee. The buyer's underlying negligence suit was filed in October 2024.
  • Heart of Gold's cyber policies required notice to the insurer within 30 days of 'Discovery,' defined as when the insured becomes aware of facts suggesting a covered loss, not when a lawsuit is filed.
  • Heart of Gold pleaded that its IT vendor reviewed its systems immediately after the March 2024 events. The court held that started the clock, putting the reporting deadline at 30 April 2024 at the latest, roughly six months before the agency actually gave notice on 7 November 2024.
  • The court also found a separate prior-awareness exclusion independently barred coverage, and dismissed the agency's bad-faith claim because the insurer's denial had 'reasonable justification.'

A title agency that investigates a suspicious wire the week it happens has done the responsible thing. A federal court in Ohio has now ruled that doing so can also be the moment a claims-made insurance policy's notice clock starts running, whether or not anyone yet believes a lawsuit is coming.

What happened at the closing table

On 5 March 2024, buyers Fadel Elkhairi and Mais Khourdaji received an email they believed came from an employee named Kendall at Heart of Gold Title, LLC, an Ohio title agency. It was, the buyers later alleged, a scam email from criminal hackers, referencing an earnest payment of $4,850 and a remaining balance of $480,150. On 6 March, after further phone and text contact with the scammers, Elkhairi wired $480,150 to the instructions he had been given.

The fraud surfaced on its own timeline. On 13 March 2024 the buyers confirmed with the real Kendall that Heart of Gold had never received the wire, and that the second set of instructions had come from someone impersonating the company. On 15 March they learned the funds were gone and the deal was cancelled. In October 2024 the buyers sued Heart of Gold Title and the brokerage, Platinum Real Estate Professionals, LLC, for negligence in the Franklin County Court of Common Pleas, alleging a failure to maintain cybersecurity protocols able to detect spoofed, doppelganger accounts.

The clause that decided the case

Heart of Gold held two consecutive cyber policies through Spinnaker Insurance Company, arranged through claims administrator Cowbell Insurance Agency LLC, both written on a claims-made-and-reported basis. The 2024 policy's Condition 14 required that after a situation that results in, or may result in, a covered loss is Discovered, the insured must notify the insurer in writing as soon as practicable, but not to exceed thirty (30) days from the date Discovered.

The policy defined Discovery or Discovered as the time when specified senior personnel first becomes aware of facts which would cause a reasonable person to believe that a Loss covered by this Policy has been or will be incurred, even if the exact amount or details of the loss are not yet known. Critically, that definition also states that Discovery does not require that a civil action already have been filed.

Heart of Gold argued it had no reason to believe it would face liability until the buyers' complaint was filed in October. Judge Algenon L. Marbley rejected that reading directly: that condition is triggered by discovery of a situation which may result in a covered Loss, not by the filing of a lawsuit. Because Heart of Gold's own counterclaim alleged that its IT vendor reviewed its systems immediately after the March 2024 events, the court held the counterclaim pleads facts establishing that the relevant situation was discovered, at a minimum, seven months before November 2024, putting the 30-day deadline at 30 April 2024 at the latest.

A second, independent reason coverage failed

The court did not stop at the notice condition. The 2024 policy also carried an exclusion for prior awareness of a cyber incident, and the court held that exclusion independently barred coverage on the same pleaded facts. Two separate provisions in the same policy reached the same result, which is the kind of redundancy an insurer's drafting is built to produce.

Heart of Gold's bad-faith counterclaim failed for a related reason. Under Ohio law an insurer acts in bad faith only where its refusal to pay lacks reasonable justification. The court found Spinnaker's position, resting on the notice condition and the exclusion alike, was reasonably justified even if a court ultimately disagreed with it, and dismissed that claim too. All of Heart of Gold's counterclaims were dismissed with prejudice on 13 March 2026.

Where this sits against the federal numbers

The FBI's Internet Crime Complaint Center recorded business email compromise losses of $3,046,598,558 across 24,768 complaints in 2025, the figure this publication has already reported from the same annual report. This case does not add to that count. It describes what happens after a BEC loss occurs, at the point where a title agency turns to its own insurance, and shows that the insurance can fail for a reason that has nothing to do with whether the fraud was foreseeable or the cybersecurity was adequate.

What a desk should do differently

  1. Read the notice condition in your firm's cyber and E&O policies before a fraud happens, specifically how the policy defines Discovery and whether it ties the clock to a lawsuit or to awareness of facts.
  2. Treat an internal IT investigation into a suspected fraud as a notice-triggering event, not a preliminary step you can complete before deciding whether to call the insurer.
  3. Notify the carrier in writing within the policy's window even where liability looks remote, since the definition in this case required only that a reasonable person believe a covered loss has been or will be incurred.
  4. Keep a dated record of when suspicious activity was first investigated internally. That date, not the date a demand letter or lawsuit arrives, is what a court will look to.
  5. On a claims-made-and-reported policy, confirm whether coverage carries across a renewal for a loss discovered under the prior policy period. Heart of Gold's 2023 policy was also held not to reach this claim.