Payment fraud isn’t automatically excluded from cyber insurance. But assuming every stolen payment will be covered is a good way to end up disappointed.
The real answer sits in the policy wording. Some cyber insurance policies cover losses caused by fraudulent instructions or compromised accounts. Others exclude certain payment scams, especially when the fraud happens without a direct cyber event. That small distinction matters a lot.
Why Payment Fraud Gets Complicated
Imagine an employee receives an email that looks like it came from the finance head. The message asks for a supplier payment to be sent to a new bank account. The employee follows the instruction. Later, everyone discovers the email was fake.
That looks like payment fraud. But an insurer may ask a different question. Was the payment caused by a cyber incident covered under the policy?
If the policy defines social engineering or fraudulent transfer losses as covered events, there could be a claim. If those losses are excluded, the answer changes quickly.
The Cyber Event Question
This is where people often get caught. A payment can be fraudulent without involving a hacked system. Someone may simply trick an employee into approving a transfer.
Because of that, insurers sometimes separate cybercrime from social engineering fraud. The wording can specify exactly what counts as a covered event, and some policies require additional coverage for fraudulent payment instructions.
What Your Policy Might Exclude
Payment fraud exclusions aren’t always written in plain language. You might find them buried under exclusions relating to theft, dishonest acts, voluntary payments, or funds transfer fraud.
A policy could also have conditions that affect a claim. For example:
• A fraudulent transfer extension may exist, but only up to a separate sub-limit, which is easy to miss when you’re looking at the main policy limit.
• Social engineering fraud could be covered only after a specific endorsement has been added.
• If an employee knowingly sends the money, the insurer may examine whether the payment counts as an insured loss rather than treating it as a straightforward cyber claim.
• Multi-factor authentication or another security control may be required, and skipping it can create a problem during claim review.
Check These Details Before Assuming You’re Covered
Start with the sections dealing specifically with funds transfer fraud and social engineering. Then look at the exclusions. If there’s an endorsement, check its own conditions and limit rather than assuming it follows the main policy.
And pay attention to how the policy defines an “insured event.” A phishing email that leads to a payment may be treated differently from an attacker gaining access to an account and making the transfer themselves.
If payment fraud is a major concern for your business, I’d strongly prefer a policy that addresses it directly. Vague wording isn’t reassuring when the missing money is sitting in someone else’s bank account.
So, Is Payment Fraud Excluded?
Sometimes. But it isn’t universally excluded from cyber insurance.
The deciding factor is usually the actual policy wording, including any social engineering or fraudulent transfer coverage and its exclusions. Two cyber policies can look almost identical from the outside and still respond very differently to the same payment scam.