Telephone Hacking Coverage
Telephone hacking coverage is an optional add-on to a cyber, crime, or similar insurance policy that helps pay for financial losses when criminals break into a company's telephone system and run up fraudulent charges. Because it is typically offered as an extension rather than as a standard part of a base policy, whether it applies depends on the specific policy and its endorsements. It addresses the insured organization's own losses, not liability owed to third parties.
Telephone hacking coverage is a first-party insuring agreement, commonly available as an optional endorsement or extension to a Cyber Liability & Privacy policy, a Crime policy, or a comparable form, that indemnifies the insured for financial losses arising from the fraudulent use of its telephone system by unauthorized parties (for example, toll fraud following compromise of a PBX or VoIP system). It responds to the insured's own direct financial loss rather than to third-party liability claims, and it should not be conflated with the broader network security, privacy liability, or business interruption components of a cyber program. Its availability, scope, sublimits, retentions, and applicable exclusions vary by insurer form and endorsement wording; the evidence references at least one dedicated form (Telephone Toll Fraud, Form CY 20 15) as an example of how such coverage is incorporated. Whether a given loss is covered is subject to the specific policy language, conditions, and exclusions, and this entry does not establish limits, figures, or triggers beyond noting that they are policy-dependent.
Why it matters
When criminals compromise an organization's telephone system, they can route large volumes of calls through it before the intrusion is noticed, and the resulting toll charges become the insured's own direct financial loss. This is a first-party exposure: the harm is the money the organization owes for fraudulent usage, not liability to a third party. Because telephone hacking sits at the intersection of communications infrastructure and financial crime, it is easy to overlook when assessing a cyber program that is focused on data breaches, privacy liability, and network security.
The practical significance is that this loss is not automatically covered. Telephone hacking coverage is typically offered as an optional extension to a Cyber Liability & Privacy policy, a Crime policy, or a comparable form rather than as a standard component of a base policy. Whether a given loss responds depends on the specific policy wording, the presence of the relevant endorsement, and the applicable sublimits, retentions, conditions, and exclusions. An organization that assumes its cyber policy addresses this exposure may find, subject to the specific wording, that the loss falls outside the coverage actually purchased.
It is also worth distinguishing what this coverage does and does not do. Insurance is a risk-transfer mechanism; it can help fund the financial loss after a fraudulent-usage event but does not by itself reduce the likelihood of a telephone system compromise. Technical mitigation of the underlying system remains a separate matter from the decision to transfer residual financial risk through an endorsement.
Who it's relevant to
Inside Telephone Hacking Coverage
Common questions
Answers to the questions practitioners most commonly ask about Telephone Hacking Coverage.
