Invoice fraud sits in a frustrating grey area. You think, “Someone hacked our email, changed the bank details, and we lost money. Surely cyber insurance covers that.” Sometimes it does. Sometimes the policy says no.

Why Invoice Fraud Gets Complicated

Imagine a supplier sends an invoice by email. Later, someone gets into that conversation and changes the bank account details. Your finance team pays the invoice. The money goes to the criminal.

That’s invoice fraud, often linked to business email compromise. The cyber element can be obvious. The insurance response isn’t always obvious.

Some cyber policies include cover for funds lost because of fraudulent instructions that result from a network intrusion or compromised email account. Others draw a much harder line around social engineering, especially when an employee willingly makes the payment after receiving a fake instruction.

The Wording Matters More Than The Label

Don’t focus only on the phrase “cyber insurance.” Read the actual coverage section.

Look for language covering social engineering fraud, fraudulent funds transfer, computer fraud, or business email compromise. Then check the exclusions. A policy could provide protection for one type of invoice fraud while excluding another because no system was actually breached.

• A hacked mailbox followed by altered payment instructions may fit cyber-related coverage, depending on the policy wording.

• A fake invoice sent from a lookalike address is trickier, particularly if nobody’s account was compromised.

• Social engineering cover is often the important bit, though limits can be much lower than the main policy limit.

What If The Policy Excludes Invoice Fraud?

An exclusion doesn’t necessarily mean every invoice fraud claim is dead. The exact cause of the loss still matters.

For example, a policy might exclude losses caused by voluntary transfers of money. But another section could separately cover fraudulent electronic transfers following a computer attack. Those details matter because insurers look at how the incident happened, not simply what the payment looked like afterward.

And this is where buying a policy based on the brochure alone is a bad idea. The headline sounds reassuring. The small print decides the claim.

How To Check Your Policy

Before assuming invoice fraud is covered, check these points.

• The definition of “computer fraud” matters because some policies require an actual attack on a computer system.

• Social engineering coverage is worth checking separately. It can address situations where an employee is tricked into sending money.

• Sublimits can shrink the payout considerably, even where the underlying claim is covered.

• Some policies require specific security controls, and failing those conditions can create another problem during a claim.