A deepfake scam can look painfully real. You get a video call from what appears to be your company director. The voice sounds right. The face looks right. Then comes the request to transfer money.

Where Deepfake Fraud Gets Complicated

The problem starts with how the fraud happened. A deepfake might imitate an executive during a video meeting. It could copy someone’s voice during a phone call. The victim then authorises a payment because they believe the instruction is genuine.

From the company’s point of view, money has disappeared. From the insurer’s point of view, though, the incident may look like an authorised transfer caused by deception.

Social Engineering Coverage Matters

Many cyber insurance policies focus heavily on attacks involving computer systems or data. Deepfake fraud can work without breaking into either. The criminal simply convinces a person to send the money.

Some policies include social engineering or fraudulent instruction coverage. If yours does, a deepfake scam may fall within that protection, subject to the policy’s conditions and limits.

• Social engineering coverage is the big one here, although the exact wording can make a surprisingly large difference.

• A policy that only covers direct hacking losses won’t automatically cover money someone was tricked into transferring.

What Insurers Will Look At

After a claim, the insurer will want to understand what actually happened. And they’ll look closely at the policy language that applied when the incident occurred.

Expect questions around how the payment was approved. They may also examine whether internal verification rules were followed. If the policy requires call-back verification for unusual transfers and nobody did it, that could become a serious issue.

Read the Policy Before the Scam Happens

Honestly, waiting until after a deepfake incident to discover an exclusion is a terrible way to learn about insurance.

Check whether the policy specifically addresses social engineering, fraudulent payment instructions or impersonation fraud. Look at the sublimits too. Then check any requirements around employee verification and approval procedures.

And don’t rely on the word “cyber” alone. A cyber policy can be broad in one area and surprisingly narrow in another.

Deepfake fraud is moving quickly, while insurance wording tends to move more carefully. That gap is exactly where businesses can get caught.