Someone gets a convincing email from the finance team. The message looks normal. The name is familiar. Then money moves to the wrong account.

What Social Engineering Means for Insurance

Social engineering works by manipulating a person rather than breaking through a technical security system. An attacker may pretend to be a manager and ask for a payment. Or they may pose as a supplier and quietly change bank details.

The uncomfortable part is that the employee may actually follow the normal process. There’s no obvious malware. No dramatic system breach. Just a believable request that gets trusted.

Because of this, insurers often treat social engineering differently from a standard hacking incident. Coverage may sit under a specific social engineering endorsement or a separate fraud provision.

Why the Policy Wording Matters

Look for language that specifically addresses fraudulent instructions or impersonation. A policy that covers cybercrime doesn’t automatically mean it covers every loss caused by a deceptive email.

Some policies also set a lower limit for these claims. Others require certain security controls or verification steps to be followed before they pay.

• A separate endorsement may be required, and that little section of the policy can matter more than the headline coverage amount.

• Verification rules can get very specific. If a payment request was supposed to receive a callback but nobody made it, the insurer may question the claim.

• Limits are worth checking too, because a policy can look generous overall while giving social engineering claims a much smaller sublimit.

What Insurers May Look At

During a claim, the insurer will want to understand what happened and whether the company followed its required controls. The details can become important very quickly.

• Email authentication was in place, but the attacker still managed to make the request look genuine. That alone doesn’t decide the claim.

• A payment approval process existed, although the employee skipped one verification step. That could become a sticking point.

• The company reported the incident quickly, which is usually a much better position than discovering the loss months later.

So, Is Social Engineering Covered?

Yes, it can be. But don’t buy cyber insurance based on the phrase “cyber fraud” and assume you’re protected.

The better approach is to check whether social engineering losses are explicitly covered. Then look at the sublimit, exclusions, required security controls, and conditions attached to making a claim.