Blog

​Social Engineering Fraud and Your Cyber Insurance Policy

Social engineering fraud is a common cause of cyber incidents, accounting for 16% of all breaches based on Verizon’s 2026 Data Breach Investigations Report. When committing social engineering fraud against businesses, criminals typically trick an employee into taking an action that exposes the business to financial or cybersecurity risk, such as disclosing a password, changing a vendor’s bank account, or authorizing a wire transfer. Unfortunately, many cyber insurance policies exclude coverage for social engineering fraud, which often must be specifically purchased as a policy enhancement.

What Is Social Engineering Fraud?

Social engineering fraud refers to the manipulation of people into taking an action that benefits the attacker. The fraudster may impersonate a company executive, vendor, customer, or another trusted party. The deception may take several forms, including “phishing” through email, “vishing” through phone calls, and “smishing” through text messages. For example, an employee might receive a message that appears to be from the company’s CEO directing the employee to transfer funds to a new bank account and providing instructions for completing the transaction. In more targeted attacks, criminals may research the company and the employee in advance, using information about their roles, relationships, and business activities to make the fraudulent communication appear more credible. Depending on the situation, losses from social engineering fraud can reach into the hundreds of thousands of dollars, or more.

What Does Cyber Insurance Typically Include?

Today, many businesses purchase cyber insurance, which helps protect policyholders from losses and liability associated with cyber attacks and data breaches. Policies often provide both first-party coverage and third-party coverage. In the wake of a cyber incident, first-party coverage helps the policyholder recover from the losses it sustains directly, while third-party coverage provides protection for losses suffered by clients, customers and other third parties as a result of the incident.

Every policy is different, and it is important to carefully read your policy to understand your coverage. Policies typically cover the cost of investigating the nature and scope of the breach or attack, containing the problem, restoring all affected systems, and developing a comprehensive recovery plan. Policies typically cover the cost of identifying and notifying impacted individuals, and they often pay for victim credit monitoring. The policy may also cover the cost of consulting legal counsel and managing public relations and crisis communications in the wake of a breach. Many policies also reimburse businesses for lost income suffered due to the business interruption caused by a covered cyber event. Policies may also include cyber extortion coverage to guard against ransomware attacks, in which criminals encrypt computer systems, devices, or files with malware, lock victims out of their own system, and then demand a ransom in exchange for regaining access. Third-party coverage often includes network security and privacy liability coverage, which guards against losses incurred by third parties and includes legal defense costs, settlements and judgments. Cyber liability coverage may also cover the cost of defense against actions brought by regulatory bodies as well as regulatory fines and penalties.

Social Engineering Fraud Coverage

Review your policy carefully to determine whether it covers social engineering fraud and fraudulent fund transfers. In many policies, this coverage must be purchased as an optional coverage enhancement, and it may be subject to lower sub-limits and higher deductibles than other cyber categories. For instance, for a policy that provides $5 million of cyber coverage, only $100,000 may be available for a particular social engineering loss. Social engineering fraud coverage is not limited to cyber insurance; it may also be available through an endorsement to a commercial crime policy.

Keep in mind that social engineering coverage often comes with specific risk-control requirements. These may include procedures for independently verifying requests to change vendor payment information, requiring more than one employee to authorize significant transfers, confirming payment instructions through a separate communication channel, and providing employees with regular training on fraud risks. It’s important to comply with your insurer’s obligations under the terms of the policy, as failure to do so could lead to claim denial or policy cancellation.

The Takeaway

Don’t assume your cyber insurance policy covers social engineering fraud. Carefully review your policy to determine if it includes a provision or endorsement for social engineering fraud, which may also be available under a commercial crime policy. Just as important, understand the applicable sub-limits, deductibles, and conditions before a loss occurs.

If your business insurance company has denied or is challenging your claim, contact Schwartz Conroy & Hack, PC. We have the expertise, experience and tenacity to make insurance companies keep their promises to you and your business.

CONTACT US

CATEGORIES

CASE STUDY

No Results Found

The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.