Where Cyber Insurance Fits In
Cyber insurance can cover losses caused by phishing, but QR code phishing isn’t automatically covered just because a policy says “phishing.” The wording matters. A lot.
If a fake QR code sends an employee to a fraudulent login page and stolen credentials lead to a covered cyber incident, the policy may respond. But if someone scans a code and willingly transfers money to a scammer, the insurer may treat that differently, especially if the policy has a social engineering or funds transfer fraud exclusion.
Check the Actual Policy Wording
Look closely at how the policy defines phishing and social engineering. Some policies specifically address fraudulent instructions or deception involving employees. Others have exclusions that can seriously narrow protection.
• A phishing extension could cover credential theft, though the exact trigger still depends on the policy wording.
• Direct financial loss is trickier, particularly where an employee approved the payment after being deceived.
• A policy with social engineering coverage is worth a closer look because QR scams often rely on human trust rather than a technical system breach.
Why the Difference Matters
The second situation has a clearer connection to a cyber event. The first may look more like payment fraud, depending on what happened and what the policy actually covers.
So before assuming you’re protected, check the sections dealing with phishing, cyber crime and fraudulent transfers. Also look for exclusions around voluntary payments or employee-authorised transactions. Those boring paragraphs can decide the whole claim.
Don’t Assume a QR Code Changes the Answer
The QR code itself isn’t usually the important part. The method used to trick someone is.
If the scam leads to a covered cyber incident, there’s a stronger argument for coverage. If it results in a straightforward payment scam, the claim may depend on whether the policy includes specific social engineering or funds transfer protection.
So, Is QR Code Phishing Covered?
Sometimes. But don’t buy cyber insurance assuming every QR code scam falls under “phishing.”
The strongest position is having policy language that clearly addresses phishing-related losses and social engineering. You’ll also want to understand the exclusions before an incident happens, because discovering them while filing a claim is about the worst possible time.