Skip to main content
Category: Coverage Types

Cyber Crime Coverage

Also known as: Cyber Crime Insuring Agreement, eCrime Coverage, Cyber Crime and Fraud Coverage
Simply put

Cyber crime coverage is a part of a cyber insurance policy that helps reimburse a business or individual for money or securities lost directly through certain electronic fraud schemes, such as being tricked into wiring funds to a criminal or having a computer manipulated to steal funds. It focuses narrowly on the direct financial loss of money, not on the broader costs of responding to a data breach. Whether a particular scheme is covered depends heavily on the specific policy wording, which insuring agreements were purchased, and applicable exclusions and conditions.

Formal definition

Cyber crime coverage refers to a set of first-party insuring agreements within (or endorsed to) a cyber policy that respond to the insured's own direct loss of money or securities arising from enumerated fraud perils. Commonly enumerated perils may include Funds Transfer Fraud, Computer Fraud, Social Engineering Fraud (fraudulent instruction/impersonation), Telephone Toll Fraud, and, in some forms, cryptojacking; each is typically defined narrowly and subject to its own sublimit, retention, and conditions precedent (such as call-back verification requirements for social engineering claims). This coverage should be distinguished from other cyber insuring agreements, such as Privacy/Data Breach and Incident Response coverage, that address forensic investigation, breach notification, and credit monitoring costs; those third-party and first-party response costs generally fall under separate agreements rather than the cyber crime clause, which is confined to direct loss of money or securities. Practitioners must also evaluate potential overlap, gaps, or conflict with a Commercial Crime/Fidelity policy, since fraud losses can implicate both forms and raise 'other insurance,' definitional, and trigger disputes. As with all coverage terms, scope is conditional on the specific wording, endorsements, exclusions, and jurisdiction, and cyber crime coverage transfers financial risk without reducing the likelihood of the underlying fraud.

Why it matters

Cyber crime coverage responds to a distinct and often costly problem: the direct loss of the insured's own money or securities through electronic fraud, such as being deceived into wiring funds to a criminal or having systems manipulated to divert payments. This is separate from the data-breach and incident-response costs that dominate discussions of cyber risk. An organization can suffer a substantial funds-transfer or social-engineering loss without any personal data being compromised at all, and the insuring agreements that pay for forensic investigation, breach notification, or credit monitoring generally do not respond to that direct financial loss. Understanding which insuring agreement is actually triggered, cyber crime versus privacy or incident response, determines whether a claim is paid and under what sublimit.

The stakes are heightened because cyber crime perils are typically narrowly defined and carry their own sublimits, retentions, and conditions precedent. A social engineering claim, for example, may be contingent on the insured having followed a specified call-back or out-of-band verification procedure before releasing funds; failing to meet that condition can defeat an otherwise valid-seeming claim. Because these clauses are drafted tightly, small differences in wording, the presence or absence of a particular endorsement, and the applicable jurisdiction can produce very different outcomes for economically similar frauds.

A further reason this coverage matters is its potential overlap and conflict with a Commercial Crime or Fidelity policy, which may also respond to fraud-based loss of money. When two forms are in play, practitioners must work through 'other insurance,' definitional, and trigger questions to establish which policy responds and in what order, and to avoid an unexpected gap where each insurer points to the other. Finally, it should be emphasized that this coverage transfers financial risk after a fraud occurs; it does not reduce the likelihood of the underlying scheme and is not a substitute for payment controls or staff training.

Who it's relevant to

Risk managers and finance leaders
Those responsible for treasury and payment functions face direct exposure to funds transfer and social engineering fraud. They need to understand which enumerated perils their policy actually names, the applicable sublimits and retentions, and any conditions precedent, such as verification procedures, that must be satisfied for a claim to respond. They should also confirm whether losses might instead fall under a Commercial Crime or Fidelity policy.
Insurance brokers and underwriters
Brokers and underwriters must map cyber crime insuring agreements against any concurrent Commercial Crime/Fidelity coverage to identify overlaps, gaps, and potential 'other insurance' conflicts. They also need to communicate that these clauses are limited to direct loss of money or securities and do not extend to breach-response costs handled under separate agreements.
Legal and compliance professionals
Because coverage turns on narrow definitions, exclusions, and conditions precedent, legal and compliance teams are often engaged when a fraud claim is contested, particularly in social engineering matters where verification conditions and definitional triggers are disputed. They should evaluate how wording and jurisdiction affect whether and which policy responds.
Chief information security officers and resilience planners
Security and resilience leaders should recognize that cyber crime coverage transfers financial risk after a fraud but does not reduce the likelihood of the underlying scheme. It complements, rather than replaces, payment controls, staff awareness training, and verification processes designed to prevent fraudulent fund transfers in the first place.

Inside Cyber Crime Coverage

First-Party Direct Loss Focus
Cyber Crime Coverage is a first-party insuring agreement that responds to the insured's own direct loss of money, securities, or other financial assets resulting from fraudulent electronic or computer-based conduct. It does not typically cover third-party liability, and its scope is generally limited to the direct financial loss rather than broader consequential or reputational harm. Whether a given loss qualifies as 'direct' is subject to the specific policy wording and has been a frequent source of dispute.
Funds Transfer Fraud
A commonly enumerated peril covering loss resulting from fraudulent instructions to a financial institution to transfer, pay, or deliver the insured's funds without the insured's knowledge or consent. Coverage terms, exclusions, and conditions precedent (such as callback or verification requirements) vary by form and can affect whether a loss is payable.
Computer Fraud
A peril addressing the fraudulent entry of, or change to, electronic data or computer instructions that causes money or securities to be transferred from the insured. The precise definition and the required causal link between the computer manipulation and the loss vary significantly across insurer forms and have been litigated.
Social Engineering Fraud
Coverage, often provided by endorsement or as a separately captioned insuring agreement, for loss where an employee is deceived into voluntarily transferring funds based on fraudulent communications impersonating a vendor, executive, or other trusted party. This peril is frequently sublimited and subject to specific conditions; because the transfer is voluntary, it is often distinguished from Funds Transfer Fraud and Computer Fraud in policy wording.
Other Enumerated Perils
Depending on the form, Cyber Crime Coverage may also enumerate perils such as telephone toll fraud (loss from unauthorized use of the insured's telephone system) and cryptojacking (loss from unauthorized use of computing resources to mine cryptocurrency). Availability, definitions, and sublimits are specific to each insurer's wording.
Sublimits, Retentions, and Conditions Precedent
Cyber crime perils are frequently subject to sublimits below the aggregate policy limit, separate retentions, and conditions precedent such as verification or authentication procedures. Failure to follow required controls can serve as a basis to deny or reduce a claim, subject to the specific wording and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Cyber Crime Coverage.

Does cyber crime coverage pay for forensic investigation, breach notification, and credit monitoring after an incident?
Generally no. Those incident-response costs are typically covered under separate insuring agreements, such as Privacy Breach or Incident Response/Breach Response agreements, rather than under a Cyber Crime or Funds Transfer Fraud clause. Cyber crime insuring agreements are usually narrow first-party coverages responding to the direct loss of money or securities from enumerated fraud perils. If your program needs response costs covered, confirm they appear under their own insuring agreements and check the sublimits and retentions applicable to each, because whether any cost is paid depends on the specific policy wording.
Is cyber crime coverage the same as the third-party liability protection in a cyber policy?
No. Cyber crime coverage is a first-party coverage addressing the insured's own direct loss of money or securities from fraud. It is distinct from third-party coverages that respond to liability owed to others, such as privacy claims or regulatory defense. The two categories have different triggers, different measures of loss, and often different sublimits. Do not assume a single 'cyber policy' automatically bundles both; review which insuring agreements are actually present and how each is scoped.
Which perils are typically enumerated under a cyber crime insuring agreement?
Cyber crime clauses commonly enumerate specific fraud perils rather than covering loss broadly. Depending on the form, these may include Funds Transfer Fraud, Computer Fraud, Social Engineering Fraud (also called deception or fraudulent instruction), Telephone Toll Fraud, and in some newer forms cryptojacking. Each named peril has its own definition and conditions. Because coverage is limited to the perils actually listed, and because insurers word these differently, confirm exactly which perils your form includes and how each is defined before relying on the coverage.
How does cyber crime coverage overlap or conflict with a Commercial Crime or Fidelity policy?
This overlap is a key issue practitioners must check. Similar fraud perils, particularly Computer Fraud, Funds Transfer Fraud, and Social Engineering Fraud, may appear in both a cyber crime insuring agreement and a Commercial Crime or Fidelity policy. That can create gaps, disputes over which policy responds, or 'other insurance' conflicts, and each policy may define the peril and set sublimits differently. Coordinate the two placements, compare definitions and sublimits side by side, and clarify the order of response so a claim does not fall between them or trigger a coverage dispute.
What conditions precedent commonly apply to social engineering fraud claims?
Social engineering losses often depend on conditions in the wording rather than the fact of loss alone. Many forms require verification or call-back procedures for payment or change-of-instruction requests, and some condition coverage on the insured following its own stated controls. Coverage is frequently subject to a separate, often lower, sublimit than other crime perils. Whether a given loss is paid turns on the specific definition of the covered fraud, any required authentication steps, applicable exclusions, and jurisdiction, so review these conditions carefully.
How is loss measured under a cyber crime insuring agreement, and what falls outside it?
Cyber crime agreements typically respond to the direct loss of money or securities, subject to the applicable sublimit and retention. Consequential or indirect losses, business interruption, data restoration, reputational harm, and third-party liability generally fall outside these clauses and, where covered at all, are addressed under other insuring agreements. Because the loss must usually be direct and the perils are enumerated, confirm how 'direct loss' is defined in your form and what is expressly excluded.

Common misconceptions

Cyber Crime Coverage pays for the costs of responding to a breach, such as forensic investigation, breach notification, and credit monitoring.
Those incident-response costs are typically addressed under separate insuring agreements (for example, Privacy Breach or Incident Response coverage) rather than under Cyber Crime / Funds Transfer Fraud clauses. Cyber crime insuring agreements are generally limited to the insured's direct loss of money or securities, subject to the specific policy wording.
If a loss is not covered by a Commercial Crime or Fidelity policy, it will automatically be picked up by Cyber Crime Coverage (and vice versa).
Cyber crime perils frequently overlap or conflict with Commercial Crime/Fidelity policies, and coverage for a single event can fall between the two or be disputed by both insurers. Practitioners should check how definitions, exclusions, 'other insurance' clauses, and enumerated perils align across both policies rather than assuming seamless coverage. The outcome depends on the specific wording of each policy and the jurisdiction.
Social engineering fraud is always covered because it is a form of cyber crime.
Because the funds are transferred voluntarily by a deceived employee, social engineering fraud is often treated separately from Funds Transfer Fraud and Computer Fraud and may be excluded, provided only by endorsement, or heavily sublimited. Whether a particular social engineering loss is payable depends on the specific insuring agreement, endorsements, and conditions.

Best practices

Map each enumerated peril (Funds Transfer Fraud, Computer Fraud, Social Engineering Fraud, and any others such as telephone toll fraud or cryptojacking) and confirm which are included, endorsed, or excluded in the specific form.
Compare the cyber crime insuring agreements against any Commercial Crime or Fidelity policy to identify overlaps, gaps, and conflicting 'other insurance' provisions before a loss occurs.
Identify applicable sublimits and retentions for each peril, since cyber crime perils are frequently sublimited well below the aggregate policy limit.
Review and operationalize any conditions precedent, such as callback verification or dual-authorization procedures, because failure to follow required controls can be a basis for denial subject to the wording.
Do not assume incident-response costs (forensics, notification, credit monitoring) fall under cyber crime clauses; confirm those are addressed under separate Privacy Breach or Incident Response insuring agreements.
Clarify with the broker and underwriter how the policy defines 'direct loss' for money or securities, and document how voluntary versus involuntary transfers are treated across the relevant perils.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.