Social engineering fraud occurs when a fraudster manipulates someone into voluntarily transferring money or providing access to financial information.
It is an increasingly important exposure for businesses.
What are common examples? #
Examples can include:
- Fake supplier emails requesting changed bank details.
- An email impersonating a director requesting an urgent transfer.
- Fraudulent phone calls pretending to be a bank.
- Fake invoices.
- Impersonation of a customer or supplier.
Why is social engineering different from traditional theft? #
In a traditional theft, the criminal directly takes the money.
With social engineering, an authorised employee may make the payment voluntarily because they have been deceived.
That difference can affect which policy section applies.
Is social engineering automatically included in Crime Insurance? #
No.
Depending on the insurer, cover may be:
- Included.
- Available as an extension.
- Subject to a sublimit.
- Subject to a separate excess.
- Excluded.
Some Cyber Insurance policies can also include social engineering or funds transfer fraud cover.
Can verification procedures affect cover? #
Yes.
Policies can require or expect businesses to follow financial controls such as:
- Verifying changes to supplier bank details.
- Dual payment approval.
- Call-back procedures.
- Independent confirmation of unusual payment requests.
Failure to follow required procedures can affect the insurance response.
Which policy should cover the loss? #
That depends on the wording.
Crime and Cyber policies should be reviewed together to understand where social engineering fraud is covered and whether limits overlap.

