Cyber and crime

Social engineering fraud coverage

What is social engineering fraud coverage and why is it separate from cyber insurance? Coverage for money your own employee sends voluntarily after being deceived by a fake invoice, spoofed email, or impersonated executive.

Social engineering fraud is the category for losses where nobody broke in. An employee was tricked into sending the money themselves, usually after a convincing email about changed wiring instructions or a phone call that sounded exactly like the boss. Because the transfer was authorized by a real person with real credentials, many policies treat it very differently from a hacking loss, and a surprising number do not respond at all unless the coverage was specifically added.

That is the trap. Businesses buy a cyber policy, assume the wire fraud scenario is inside it, and discover the distinction only after the money has moved through several countries. Related coverages sit nearby with meaningfully different triggers: computer fraud generally contemplates an unauthorized intrusion, while funds transfer fraud contemplates instructions given to your bank without your knowledge. Deception of your own staff is its own animal.

Two questions settle it. Is social engineering fraud named in the policy, and what is its sublimit, which is often far smaller than the headline cyber limit. The controls carriers expect alongside it are equally concrete: callback verification to a known number before any payment change, dual approval on transfers, and training that happens more than once a year.

Heard on the show. Jessica works through this one in The Cyber Heist: How Cyber Insurance Can Save You From AI Voice Clones, with the full story and the transcript.

Related terms

This page is education, not advice. Policy language varies by carrier, form, and state, so confirm how your own program is written with a licensed insurance professional.