A fake video call can now look convincing enough to fool someone inside a company. The face looks right. The voice sounds right. The request feels normal. Then money leaves the account.
So, can cyber insurance cover the loss? Sometimes. But there’s a catch, and it’s a pretty important one: the exact wording of your policy decides what happens next.
Deepfake Fraud Is Usually a Social Engineering Problem
Deepfake fraud often starts with impersonation. A criminal uses AI to copy an executive’s voice or face and then convinces an employee to approve a payment. From the company’s point of view, it may look like a normal business instruction.
Insurers don’t always treat that as a traditional cyberattack. Many policies separate hacking from social engineering because the criminal may never break into the company’s network at all.
That’s where things get messy.
What Your Policy Actually Covers
Some cyber insurance policies include coverage for social engineering fraud. Others offer it as an endorsement with a separate limit. Some policies exclude it completely unless specific wording has been added.
• Social engineering coverage can be the key, although the insurer may apply a lower sublimit than your main cyber coverage.
• A deepfake payment scam isn’t automatically covered just because you bought a cyber policy.
• Fraud involving an employee’s actions can receive different treatment, depending on the policy wording and the facts of the claim.
The trick is to look for language covering fraudulent instructions, impersonation or deception involving an employee. Don’t rely on the phrase “cyber insurance” sitting on the first page.
What Happens When You File a Claim?
Suppose an employee receives a video call from someone who appears to be the finance director. The person asks for a transfer. The employee follows the instruction, and the company later discovers that the executive was never on the call.
The insurer will look closely at what happened. They’ll want to know how the instruction arrived, what checks were followed, and what the policy says about social engineering or funds transfer fraud.
Raj had a similar scare at work. He kept reopening the same five tabs every morning to check payment requests, so the company added another approval step after a suspicious call. Nothing dramatic happened. That extra check simply became part of his morning routine.
The Small Details Can Decide the Claim
Documentation matters. So does timing. If your policy requires certain verification steps before sending money, ignoring those requirements can create problems when you make a claim.
• The amount involved may matter because a separate social engineering limit can apply.
• Verification procedures count too, especially if the policy sets specific conditions for payment fraud coverage.
• Report the incident quickly. Waiting around while everyone tries to work out what happened is a bad idea.
Check Before a Deepfake Tricks Someone
Deepfake scams are getting harder to dismiss as obvious fakes. A familiar voice is enough to make people lower their guard, and a convincing video makes the situation even harder.
That’s why I wouldn’t buy a cyber policy based only on the headline coverage amount. I’d read the social engineering section first. Then I’d check the exclusions and sublimits.
Because if someone uses AI to impersonate your CEO and your employee sends the money, the question isn’t simply whether you had cyber insurance.
It’s whether your policy was written for that exact kind of mistake.