Cyber & technology risk

Social Engineering Fraud: Cyber Insurance vs. Crime Insurance

Identify which policy may address a fraudulent transfer caused by phishing or impersonation and avoid assuming all cybercrime sits under cyber insurance. Practical U.S. small-business guidance.

By Morgan Reyes · Source-checked · Updated Aug. 19, 2026 · U.S. focus · Educational information
Quick answer

A business can lose real money to a phishing or impersonation scheme without any malware ever touching its network. Cyber policies, crime policies, and social-engineering endorsements can divide that loss differently depending on the mechanism — who was impersonated, what system was compromised, and who authorized the payment — so an everyday description like "we got scammed by email" does not point to one obvious policy.

Search intentIdentify which policy may address a fraudulent transfer caused by phishing or impersonation and avoid assuming all cybercrime sits under cyber insurance.
Primary topicsocial engineering fraud cyber vs crime insurance

The loss can be entirely human, not technical

An employee wiring funds, changing a vendor's bank details, buying gift cards for a fake executive, or handing over credentials to a convincing impersonator are all social-engineering losses. No server needs to be breached and no ransomware needs to run for the money to disappear.

That distinction matters because cyber insurance is generally written around computer systems and data, while crime insurance is generally written around theft, fraud, and dishonesty — and social-engineering fraud sits uncomfortably between the two, which is exactly why insurers write narrow, specific language for it rather than assuming one policy automatically covers it.

A believable email cost a real invoice payment

An accounts-payable employee at a small agency receives an email that looks like it comes from a long-time supplier, referencing a real invoice number and a plausible reason for updating banking details. The employee updates the vendor record and pays the next invoice to the new account.

The money is gone, the supplier never received it, and the agency has to decide whether this is a cyber claim, a crime claim, or both — while also contacting its bank about a possible recall, which is a race against time that insurance alone cannot win.

Verification conditions can decide the claim before it is filed

Many social-engineering and funds-transfer-fraud endorsements require proof that the business followed a verification procedure — a callback to a known number, a second authorization — before changing payment instructions. If that step was skipped, the endorsement can apply a reduced sublimit or no coverage at all, regardless of how convincing the fraud was.

This is a rare case where the insurance question and the fraud-prevention question are the same question: building a callback-verification habit into vendor-payment changes is both the best defense and, often, a condition of the coverage responding at all.

What to preserve within hours, not days

Preserve the original fraudulent email with full headers rather than a screenshot, the payment instructions that were changed, any callback or verification records, bank notices about the transfer, and a timeline of who did what and when.

  • Original email with headers, not a forwarded screenshot
  • Old and new payment instructions side by side
  • Any verification or callback attempt, successful or not
  • Bank contact log and recall request confirmation
  • Internal timeline: who received it, who acted, who caught it
  • Both the cyber and crime policy forms, not just the summary page

Ask the broker to map the mechanism, not the label

Rather than asking "is this covered," describe the mechanism precisely: who was impersonated, what communication channel was used, whether any system was actually accessed, and how the funds moved. That level of detail is what lets a broker point to the right insuring agreement instead of guessing from a one-line description.

Primary and regulator sources used

We use government, regulator, and other primary sources for insurance mechanics, state-authority routing, worker-classification, property, claims, and cyber-security guidance. Policy language and state rules still control your specific situation.

Frequently asked questions

If an employee is tricked by a fake email, is that automatically a cyber insurance claim?

Not automatically. If no computer system was compromised and the loss was purely a fraudulent payment, a crime or social-engineering endorsement may be the more relevant coverage, or the only one that responds.

Does it matter whether we called the vendor to confirm the new bank details?

It can matter a great deal. Many social-engineering endorsements condition coverage on a verification step like a callback to a known number before honoring changed payment instructions.

Should a small business carry both cyber and crime coverage?

Many small businesses do, specifically because social-engineering losses can fall on either side depending on the exact mechanism. Ask the broker to confirm which policy is intended to respond to a funds-transfer-fraud scenario before assuming either one does.

Keep researching

Related guides and tools

Free tools

Turn this article into an action list

Use our downloadable checklists, worksheets, and fillable PDF forms to review a contract, compare quotes, track COIs, prepare for renewal, or document a loss.

Browse free templates