Skip to main content
Category: Coverage Types

Telephone Hacking Coverage

Also known as: Telephone Fraud Coverage, Telephone Toll Fraud Coverage, Telephone Hacking Fraud Coverage
Simply put

Telephone hacking coverage is an optional add-on to a cyber, crime, or similar insurance policy that helps pay for financial losses when criminals break into a company's telephone system and run up fraudulent charges. Because it is typically offered as an extension rather than as a standard part of a base policy, whether it applies depends on the specific policy and its endorsements. It addresses the insured organization's own losses, not liability owed to third parties.

Formal definition

Telephone hacking coverage is a first-party insuring agreement, commonly available as an optional endorsement or extension to a Cyber Liability & Privacy policy, a Crime policy, or a comparable form, that indemnifies the insured for financial losses arising from the fraudulent use of its telephone system by unauthorized parties (for example, toll fraud following compromise of a PBX or VoIP system). It responds to the insured's own direct financial loss rather than to third-party liability claims, and it should not be conflated with the broader network security, privacy liability, or business interruption components of a cyber program. Its availability, scope, sublimits, retentions, and applicable exclusions vary by insurer form and endorsement wording; the evidence references at least one dedicated form (Telephone Toll Fraud, Form CY 20 15) as an example of how such coverage is incorporated. Whether a given loss is covered is subject to the specific policy language, conditions, and exclusions, and this entry does not establish limits, figures, or triggers beyond noting that they are policy-dependent.

Why it matters

When criminals compromise an organization's telephone system, they can route large volumes of calls through it before the intrusion is noticed, and the resulting toll charges become the insured's own direct financial loss. This is a first-party exposure: the harm is the money the organization owes for fraudulent usage, not liability to a third party. Because telephone hacking sits at the intersection of communications infrastructure and financial crime, it is easy to overlook when assessing a cyber program that is focused on data breaches, privacy liability, and network security.

The practical significance is that this loss is not automatically covered. Telephone hacking coverage is typically offered as an optional extension to a Cyber Liability & Privacy policy, a Crime policy, or a comparable form rather than as a standard component of a base policy. Whether a given loss responds depends on the specific policy wording, the presence of the relevant endorsement, and the applicable sublimits, retentions, conditions, and exclusions. An organization that assumes its cyber policy addresses this exposure may find, subject to the specific wording, that the loss falls outside the coverage actually purchased.

It is also worth distinguishing what this coverage does and does not do. Insurance is a risk-transfer mechanism; it can help fund the financial loss after a fraudulent-usage event but does not by itself reduce the likelihood of a telephone system compromise. Technical mitigation of the underlying system remains a separate matter from the decision to transfer residual financial risk through an endorsement.

Who it's relevant to

Risk managers
Risk managers should treat telephone hacking as a distinct first-party financial exposure that may not be captured by a base cyber or crime policy. Confirming whether the relevant extension has been purchased, and understanding its sublimits and retentions, helps avoid an assumption that the exposure is already transferred. This coverage funds the financial loss but does not reduce the likelihood of a system compromise, so it complements rather than replaces technical mitigation.
Insurance brokers and underwriters
Because telephone hacking coverage is typically an optional extension to a Cyber Liability & Privacy policy, a Crime policy, or a comparable form, brokers and underwriters need to be precise about whether it is included, how it is worded, and which exclusions apply. Referencing the actual endorsement, such as a dedicated Telephone Toll Fraud form, and clarifying that scope and limits vary by insurer, supports accurate placement and avoids conflating this first-party cover with third-party liability or business interruption components.
Chief information security officers and telecom/IT teams
Security and IT leaders responsible for PBX and VoIP systems should recognize that the compromise of a telephone system can generate direct financial loss through fraudulent usage. Insurance may transfer some of that financial risk, but it does not harden the system; controls to prevent unauthorized access remain a separate resilience and security responsibility.
Legal and compliance professionals
Legal and compliance staff assessing coverage should note that whether a telephone hacking loss is payable depends on the specific policy language, conditions, and exclusions, and that this coverage addresses the insured's own losses rather than liability owed to third parties. Coverage determinations should be read against the actual endorsement wording rather than general assumptions about what a cyber program includes.

Inside Telephone Hacking Coverage

Toll Fraud / Phreaking Losses
Coverage typically responds to unauthorized use of an insured's telephone or PBX/VoIP system by a third party who routes calls, often to premium-rate or international numbers, generating fraudulent charges. This is generally structured as a first-party loss to the insured's own account, subject to the specific policy wording.
Sublimit
Telephone hacking cover is commonly provided subject to a sublimit that sits below the overall policy limit, meaning the maximum recoverable for this specific exposure is often lower than for other insuring agreements. The exact sublimit depends on the individual policy.
Retention / Deductible
The insured typically bears an initial portion of any covered loss through a retention or deductible before the insurer indemnifies the balance, subject to the terms of the specific policy.
Coverage Trigger
The event that activates cover, commonly the unauthorized access to and fraudulent use of the telecommunications system, must fall within the definitions and conditions set out in the policy. Whether a given incident triggers cover depends on the specific wording and any conditions precedent.
Failure-to-Maintain-Standards Conditions
Many forms condition cover on the insured maintaining reasonable security over its telephone systems (for example changing default credentials or securing remote access). Non-compliance may engage an exclusion or condition precedent; this varies by insurer form.
Scope Boundary
This cover addresses fraudulent charges arising from unauthorized use of telephony systems. It is generally distinct from third-party liability arising from a data breach, from business interruption cover, and from broader cyber extortion or data restoration insuring agreements, though placement within a cyber or crime policy varies.

Common questions

Answers to the questions practitioners most commonly ask about Telephone Hacking Coverage.

Is telephone hacking coverage the same as general cyber coverage for network breaches?
No. Telephone hacking coverage typically responds to fraudulent use of an organization's telephone system or PBX to place unauthorized calls, resulting in charges the insured must pay. That is distinct from coverage for network intrusions, data compromise, or privacy liability. In many programs it appears as a specific insuring agreement or endorsement, sometimes within a crime or telecommunications fraud form rather than a cyber form, and whether it applies at all depends on the specific policy wording. Do not assume a cyber policy automatically extends to toll fraud losses; check the schedule of coverages and any dedicated sublimit.
Does this coverage protect against my own liability to third parties, or is it about my own losses?
As commonly written, telephone hacking coverage is oriented toward the insured's own first-party loss, typically the fraudulent call charges the insured becomes obligated to pay to a carrier. It is generally not a third-party liability coverage responding to claims that others bring against the insured. If your concern is liability to others, that is a separate question addressed by different insuring agreements. As always, the categorization depends on the specific wording, endorsements, and how the insurer's form is structured.
What sublimit or retention should we expect on this coverage?
Telephone hacking or toll fraud coverage is frequently subject to a sublimit lower than the policy's main aggregate, and to a retention or deductible. The specific figures vary by insurer, program, and negotiation, so no single standard amount can be stated here. Review the declarations and any endorsement schedule to confirm the applicable sublimit and retention, and consider whether that sublimit is proportionate to the potential charges your telephone system could accumulate during an undetected fraud event.
What conditions or controls might the insurer require before this coverage responds?
Coverage may be subject to conditions precedent or to exclusions such as failure-to-maintain-standards provisions. Depending on the wording, an insurer may expect reasonable security configuration of the PBX or voice system, monitoring for anomalous call activity, or prompt notification once fraudulent charges are identified. Because these requirements differ across forms, read the conditions and exclusions carefully; a control expectation stated in the policy is a coverage condition, not merely a best practice, and non-compliance could affect the claim.
How does this coverage interact with any recovery we pursue against the telecommunications carrier?
Whether the insured can dispute charges with the carrier, and whether the insurer expects such disputes to be pursued, depends on the policy conditions and on the contractual relationship with the carrier. Some policies contain subrogation or cooperation conditions that bear on amounts recoverable from other sources. Because the interaction between carrier dispute processes and the insurance recovery is governed by the specific wording and by your carrier agreement, coordinate the claim notification and any carrier dispute rather than treating them as independent.
Is buying this coverage a substitute for securing our telephone system?
No. This coverage is a risk transfer mechanism for the financial consequences of toll fraud; it does not reduce the likelihood that a telephone system is compromised and does not by itself constitute resilience. Securing the PBX, restricting international and premium-rate dialing, and monitoring call patterns are mitigation measures that lower the probability and severity of an event. Insurance and mitigation are complementary, and some policy conditions may in fact assume that reasonable controls are in place, so treat the two as working together rather than as alternatives.

Common misconceptions

Telephone hacking coverage will pay the full policy limit for any fraudulent call charges.
This exposure is frequently subject to a dedicated sublimit and a retention, so recovery is often capped well below the overall policy limit and reduced by the deductible. The precise figures and availability depend on the specific policy wording.
Having this coverage means the insured does not need to secure its phone systems.
Insurance is a risk-transfer mechanism; it does not reduce the likelihood of a hacking incident. Many policies also condition cover on maintaining reasonable security controls, so poor system hygiene can engage exclusions or conditions precedent and defeat a claim.
Telephone hacking cover is the same as, or automatically included within, general cyber liability coverage.
It is typically a distinct insuring agreement or endorsement that may appear in a crime, cyber, or telecommunications form. Whether it is included, and how it interacts with first-party and third-party sections, depends on the specific policy and placement.

Best practices

Confirm exactly where telephone hacking cover sits in the program (crime, cyber, or standalone endorsement) and identify the applicable sublimit, retention, and coverage trigger in the specific wording.
Review any failure-to-maintain-standards conditions and conditions precedent, and document that the insured meets them, for example by changing default credentials and restricting remote access to PBX/VoIP systems.
Do not treat this coverage as a substitute for technical controls; pair risk transfer with mitigation such as monitoring for anomalous call patterns and disabling unneeded premium-rate and international dialing.
Clarify with the broker how this cover interacts with, and is distinct from, business interruption, data restoration, and third-party liability sections to avoid assuming losses outside its scope are covered.
Establish an incident response step for suspected toll fraud, including prompt carrier notification to cap accruing charges and timely notice to insurers within any policy-required reporting period.
Reassess the adequacy of the sublimit against the organization's realistic exposure at each renewal, recognizing that the sublimit may fall short of a large fraudulent charge event.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps