Cyber Liability

Funds Transfer Fraud and Social Engineering: The Cyber Claim Your Policy May Not Cover

The scenario is familiar to anyone who has read a cyber insurance claim summary. An accounts payable clerk receives an email that appears to come from a regular vendor, explaining that the vendor has changed banks and providing new wire instructions. The next invoice is paid to the new account. Weeks later the real vendor calls asking where the money is. There was no malware, no breach, no hacker inside the network. Someone was simply convinced to send money to the wrong place.

This is social engineering fraud, sometimes called business email compromise or funds transfer fraud, and it has become one of the most frequent and expensive events businesses face. It is also a category that many cyber and crime policies handle poorly. This article explains the coverage landscape and what to look for.

Why It Falls Between Policies

Two policies might plausibly respond to a fraudulent transfer: a cyber liability policy and a commercial crime policy. Historically, both had problems with it.

Traditional cyber policies were designed around unauthorized access to systems and data. A social engineering loss involves no unauthorized access; the employee who sent the money was authorized to do so. Many cyber forms therefore excluded it or never contemplated it.

Traditional crime policies cover theft by employees and certain thefts by outsiders, including computer fraud and funds transfer fraud. But those insuring agreements were written to cover a thief who fraudulently causes a transfer, not an employee who voluntarily initiates one after being deceived. Courts have gone both ways on whether a voluntary but deceived transfer is covered, which is exactly the kind of uncertainty insurance is supposed to remove.

The Coverage That Was Built for It

In response, carriers developed a specific insuring agreement, usually called social engineering fraud coverage or fraudulent instruction coverage, that is now available on many cyber policies and many crime policies as an endorsement. It is designed to cover the loss of money or securities when an employee is deceived by a fraudulent instruction purporting to come from a vendor, client, or executive into transferring funds.

The critical detail is the limit. Social engineering coverage is very commonly sublimited, often to a fraction of the policy limit. A cyber policy with a substantial aggregate limit may carry a much smaller sublimit for social engineering. Businesses that regularly wire large sums should compare the sublimit to the size of their typical transactions.

Related Insuring Agreements to Understand

Several adjacent coverages are easy to confuse with social engineering fraud. Funds transfer fraud, in the crime policy sense, typically covers a fraudulent instruction sent directly to your bank by an impostor, not through your employee. Computer fraud covers theft resulting from unauthorized use of a computer system. Invoice manipulation or reverse social engineering addresses the situation where your customers are tricked into paying an impostor instead of you, so you lose the receivable. Telecommunications fraud covers unauthorized use of your phone system. Each has its own definitions and its own sublimit, and a loss can fall into one or none depending on exactly how the fraud was carried out.

The Conditions That Decide Claims

Social engineering endorsements often come with conditions that must be met for coverage to apply. The most common is a verification requirement: the policy may require that your business confirmed the transfer instruction through a separate channel, such as a phone call to a known number, before sending funds. If your process did not include that step and the policy required it, the claim may be denied.

Other common conditions include a requirement that the instruction came from a person purporting to be a vendor, client, or employee (not a stranger), a requirement that the transfer was made by an employee acting in good faith, and prompt notice to the carrier and to the bank so that recall attempts can be made. Recovery is sometimes possible if the bank is notified within hours, which makes speed of reporting a coverage issue as well as a practical one.

Underwriting Questions You Should Expect

Carriers offering meaningful social engineering limits typically ask about your controls: whether you require out-of-band verification for new or changed payment instructions, whether wire transfers above a threshold require dual authorization, whether you use multi-factor authentication on email accounts, whether employees receive phishing awareness training, and whether vendor bank account changes require confirmation with a known contact. Businesses that cannot answer yes to most of these may face lower sublimits or exclusions.

These controls are worth implementing regardless of insurance. Most social engineering losses are preventable by a single phone call to a known number.

Who Is Most Exposed

Any business that pays vendors electronically is exposed, but the losses cluster in organizations that make frequent or large wire transfers: real estate and title companies, construction firms paying subcontractors, manufacturers with overseas suppliers, professional service firms handling client funds, nonprofits with small finance teams, and companies where executives travel and send instructions by email. Organizations with a single person handling accounts payable, with no second approver, are particularly vulnerable.

Reviewing Your Coverage

If you are not certain whether your cyber or crime policy includes social engineering coverage, what the sublimit is, and what verification conditions apply, that uncertainty is the problem to solve. An independent agent who works with cyber and management liability coverage can identify whether the coverage exists on your current forms, compare sublimits across carriers, and help align your payment controls with what the policy requires. The email that starts the loss will look legitimate. The coverage should be checked before it arrives.

Want this reviewed for your business?

Submit once and we'll bring back up to 10 carrier quotes, with the coverage differences explained in plain English. No obligation.

Get Up to 10 Quotes

General information only. Coverage is governed by the terms of the policy actually issued. This article is not legal advice.