Cyber Crime Coverage
Cyber crime coverage is a part of a cyber insurance policy that helps reimburse a business or individual for money or securities lost directly through certain electronic fraud schemes, such as being tricked into wiring funds to a criminal or having a computer manipulated to steal funds. It focuses narrowly on the direct financial loss of money, not on the broader costs of responding to a data breach. Whether a particular scheme is covered depends heavily on the specific policy wording, which insuring agreements were purchased, and applicable exclusions and conditions.
Cyber crime coverage refers to a set of first-party insuring agreements within (or endorsed to) a cyber policy that respond to the insured's own direct loss of money or securities arising from enumerated fraud perils. Commonly enumerated perils may include Funds Transfer Fraud, Computer Fraud, Social Engineering Fraud (fraudulent instruction/impersonation), Telephone Toll Fraud, and, in some forms, cryptojacking; each is typically defined narrowly and subject to its own sublimit, retention, and conditions precedent (such as call-back verification requirements for social engineering claims). This coverage should be distinguished from other cyber insuring agreements, such as Privacy/Data Breach and Incident Response coverage, that address forensic investigation, breach notification, and credit monitoring costs; those third-party and first-party response costs generally fall under separate agreements rather than the cyber crime clause, which is confined to direct loss of money or securities. Practitioners must also evaluate potential overlap, gaps, or conflict with a Commercial Crime/Fidelity policy, since fraud losses can implicate both forms and raise 'other insurance,' definitional, and trigger disputes. As with all coverage terms, scope is conditional on the specific wording, endorsements, exclusions, and jurisdiction, and cyber crime coverage transfers financial risk without reducing the likelihood of the underlying fraud.
Why it matters
Cyber crime coverage responds to a distinct and often costly problem: the direct loss of the insured's own money or securities through electronic fraud, such as being deceived into wiring funds to a criminal or having systems manipulated to divert payments. This is separate from the data-breach and incident-response costs that dominate discussions of cyber risk. An organization can suffer a substantial funds-transfer or social-engineering loss without any personal data being compromised at all, and the insuring agreements that pay for forensic investigation, breach notification, or credit monitoring generally do not respond to that direct financial loss. Understanding which insuring agreement is actually triggered, cyber crime versus privacy or incident response, determines whether a claim is paid and under what sublimit.
The stakes are heightened because cyber crime perils are typically narrowly defined and carry their own sublimits, retentions, and conditions precedent. A social engineering claim, for example, may be contingent on the insured having followed a specified call-back or out-of-band verification procedure before releasing funds; failing to meet that condition can defeat an otherwise valid-seeming claim. Because these clauses are drafted tightly, small differences in wording, the presence or absence of a particular endorsement, and the applicable jurisdiction can produce very different outcomes for economically similar frauds.
A further reason this coverage matters is its potential overlap and conflict with a Commercial Crime or Fidelity policy, which may also respond to fraud-based loss of money. When two forms are in play, practitioners must work through 'other insurance,' definitional, and trigger questions to establish which policy responds and in what order, and to avoid an unexpected gap where each insurer points to the other. Finally, it should be emphasized that this coverage transfers financial risk after a fraud occurs; it does not reduce the likelihood of the underlying scheme and is not a substitute for payment controls or staff training.
Who it's relevant to
Inside Cyber Crime Coverage
Common questions
Answers to the questions practitioners most commonly ask about Cyber Crime Coverage.
