Email spoofing looks simple from the outside. A fake message appears to come from a real person, often someone inside the company, and the recipient acts on it. The trouble starts when money moves or sensitive data leaves the business.
So, is that covered by cyber insurance? Sometimes. The answer sits in the policy wording, especially around social engineering, fraud, and funds transfer fraud.
Why Spoofing Gets Complicated
The tricky part is that spoofing itself usually isn’t the loss. It’s the method used to cause the loss. An attacker may copy an executive’s email address and ask an employee to change bank details for a payment. The employee follows the request. The company loses money.
That distinction matters. A basic cyber policy may cover certain cyber incidents but exclude losses caused by an employee being tricked into sending funds. A separate social engineering endorsement may step in instead.
Read the Fine Print
Look for wording that addresses social engineering or fraudulent instruction coverage. The exact language matters more than the section heading.
• Social engineering coverage is the big one, though the limit may be much lower than the main cyber policy limit.
• A requirement for callback verification can change the claim completely. If the policy says employees must verify payment changes by phone, ignoring that step may create a problem.
• Some policies cover the company’s loss only after certain conditions are met, and that part is easy to skim past during renewal.
A Small Example
Raj worked for a growing distributor and got an email that looked like it came from the finance director. The request was ordinary enough: update the bank details for a supplier before the next payment. He stopped reopening the same five tabs every morning because the new process seemed cleaner.
The payment went to the wrong account. No malware. No stolen password. Just a convincing email and a rushed decision.
That kind of incident is why policy wording matters. The insurer may view it as social engineering rather than a standard network security event.
What Your Policy Should Make Clear
Honestly, I think businesses are better off treating email spoofing as an insurance question before an incident happens. Waiting until a claim is filed is a lousy time to discover that the relevant coverage has a small sublimit.
Check These Details
• The social engineering limit. A million-dollar cyber policy doesn’t mean a million dollars applies to every type of fraud.
• Whether coverage applies to spoofed emails, because some wording focuses on fraudulent instructions rather than spoofing itself.
• Verification rules. If the policy expects a second form of confirmation, make sure your staff actually follows it.
• The definition of who counts as an insured person. That sounds boring. It can still matter.
And don’t assume that buying cyber insurance automatically covers every business email scam. It doesn’t.
The trick is to ask the insurer or broker a blunt question: “If someone spoofs our CFO’s email and an employee sends money to the attacker’s account, exactly which part of this policy responds?”
Get the answer in writing. Better yet, get it before renewal.
Because when the fake email arrives, nobody wants to discover that the coverage was hiding behind a definition they never noticed.