It can, but Social Engineering and Invoice Fraud should not automatically be assumed to be covered under every Cyber Insurance policy.
Cover varies significantly between insurers.
What are Social Engineering and Invoice Fraud? #
Social Engineering involves manipulating a person into doing something that benefits the fraudster.
Examples can include someone impersonating:
- A supplier
- A client
- A director
- A senior employee
- A bank
- Another trusted organisation
The fraudster may attempt to convince someone to transfer money, change bank details or disclose confidential information.
Invoice Fraud commonly involves changing payment instructions so that money intended for a legitimate supplier or client is diverted to a fraudulent account.
This can occur through:
- Compromised email accounts
- Fake invoices
- Altered bank details
- Impersonation of suppliers
- Fraudulent payment requests
How is this treated under Cyber Insurance? #
Depending on the policy, Social Engineering or Invoice Fraud cover may:
- Be included
- Be optional
- Carry a separate sub-limit
- Have a separate excess
- Be subject to verification procedures
- Be excluded entirely
Some policies also distinguish between loss suffered directly by the insured business and loss suffered by a client or other third party.
Payment verification requirements #
Insurers may require particular payment controls or verification procedures.
Failure to follow required procedures can affect how a claim is treated.
Contact our team if you would like to confirm how Social Engineering or Invoice Fraud is treated under your Cyber Insurance policy.

