Cyber FAQs

Does cyber insurance cover wire transfer fraud and social engineering attacks?

Quick answer: Social engineering fraud, where an employee is tricked into wiring money to a fraudulent account, is one of the most common cyber losses.

Cyber insurance sometimes covers wire transfer fraud and social engineering attacks, but only when the policy is written to include that protection, and usually under a separate sub-limit well below the full policy limit. Verifying this before a loss matters, because many Georgia businesses discover the gap only after a claim is denied.

What is social engineering in a cyber insurance context?

Social engineering occurs when a criminal tricks one of your employees into sending money or sensitive data voluntarily. A common method is a fake email that appears to come from your CEO or a trusted vendor, asking your bookkeeper to wire funds to a new bank account. Because the employee was deceived rather than hacked, many cyber policies treat this differently from a direct network breach and do not automatically cover the loss.

What coverage types address wire transfer fraud?

Two distinct coverages apply here, and both are often add-ons rather than standard inclusions. Social engineering or deception fraud coverage pays when an employee is tricked into transferring funds. Funds transfer fraud coverage pays when a criminal gains unauthorized access to your systems and moves money without employee involvement. Knowing which type of loss your firm faces helps determine which coverage to add. See our FAQ on whether small businesses need cyber insurance for the broader context on when this coverage makes sense.

What sub-limits apply to social engineering losses?

Even when a policy includes social engineering coverage, the payout cap is often far lower than the full cyber limit. Common sub-limits run from $100,000 to $250,000. For a firm where a single fraudulent wire could exceed that figure, the difference falls on the business. An endorsement can sometimes raise those limits, but it must be requested and underwritten separately from the base policy.

For example, an Atlanta accounting firm's office manager receives an email appearing to come from a client and wires $48,000 to a new bank account. With a $50,000 social engineering sub-limit on the policy, the insurer reimburses most of the loss. Without that coverage, the claim is denied entirely and the firm absorbs the full amount out of pocket.

What verification requirements affect social engineering claims?

Some carriers require a callback or dual-approval step before they will pay a social engineering claim. If your team sent the wire without completing that process, the insurer may deny coverage even when the social engineering endorsement is present on the policy. Reviewing these conditions before a loss is the only way to know what your policy actually requires. Our FAQ on claims-made versus occurrence policies explains how policy conditions control when different types of claims are paid, which is useful background for reading any commercial policy carefully.

How do I check whether my Georgia cyber policy covers these losses?

Pull your current cyber policy and look for the terms social engineering, deception fraud, and funds transfer fraud in the coverage schedule. Check whether each is listed, what sub-limit applies, and whether any verification condition is attached. Many Georgia businesses assume this protection is included by default, then discover the gap after a loss.

For example, a Duluth technology firm assumes its $1 million cyber policy covers a $200,000 wire fraud loss, then learns the social engineering sub-limit is $100,000 and a required callback step was not followed. The firm covers the remaining $100,000 out of pocket. Our FAQ on what commercial coverage Georgia businesses typically need covers how cyber fits alongside other lines. A free coverage review at Olive Cover includes a check of your cyber liability insurance sub-limits and verification conditions so you know what is covered before a claim arrives.