A payment sent on a fake instruction is not a break-in, and your policy treats it differently.
A supplier writes to say the banking details have changed. The message is convincing, and it sits inside a thread you already trust. The money leaves on your own instruction, and that single fact decides which part of the policy answers and how much of the loss it carries. Most firms find the answer in a limit they have never read.
Start a quote file Read the short answer firstFunds transfer sits under a smaller limit.
You pressed send, so wordings differ.
One verified phone call ends most of it.
Does cyber insurance pay when money is wired on a fake instruction?
Often yes, but rarely up to the full policy limit. A transfer your own staff made sits in the funds transfer fraud or social engineering section of a cyber policy, and that section normally carries its own smaller limit inside the wording. A firm can hold a large cyber limit and still find the fraudulent instruction cap set at a small fraction of it. The number that matters is on the declarations page, not on the front of the policy.
The reason sits in how the loss happens. Nothing was forced. No system was broken into. Somebody in your office read a message, believed it, and released the payment. Insurers treat that as a different risk because it turns on office habits rather than on software, and a separately priced risk is what produces a separately capped limit.
The gap shows up at the worst moment, when the real supplier calls to ask why they have not been paid. By then the funds have usually moved through two or three accounts. The firm turns to its cyber policy and learns three things at once: the section covering this loss is capped, the cap may have to last the whole policy year rather than refreshing for each incident, and a deductible sits underneath it. The Canadian Anti-Fraud Centre describes the common version of this fraud plainly, as a spoofed email “informing the business of a change in payment details”, sent to a business that already deals with that supplier. Read the Anti-Fraud Centre page on spear phishing (opens in a new tab).
Four questions that decide what gets paid.
Which section the loss falls into
Funds transfer fraud, social engineering fraud and fraudulent instruction are three names for closely related cover. Some policies grant all of it, some grant one version and exclude the others. The wording bound at renewal settles this long before anything happens.
Whether the cap refreshes or runs out
A limit that applies to each incident behaves very differently from one that has to last twelve months. Firms hit twice in a busy season are the ones who find out which they bought, and they find out after the second loss.
Whose money moved
Cover for your own funds and cover for money you hold on behalf of a client are not always the same grant. A practice running a trust account should read both, because the second is the one that ends in a complaint to your regulator as well as a claim.
What the policy expected you to do first
Many wordings make payment conditional on a verification step, usually a call to a number you already held before the request arrived. Where that condition exists and the step was skipped, a claim can fail even though the cover is there.
Three ways the instruction arrives.
The supplier who changed banks
A familiar invoice arrives with new banking details and a short apology for the switch. Everything else about the message is ordinary, including the thread it sits in and the signature at the bottom. It is paid without a second look, because the relationship is years old.
The partner who is travelling
A message from a senior name asks for a transfer to close something before a deadline, and asks that it be handled quietly. Urgency and secrecy arrive together in almost every version of this. Both are there to stop the one phone call that would have ended it.
The client whose email was read
Here the fraudster spoofs nothing. They are sitting inside a client’s mailbox, reading a file until money is due, then sending the instruction from the client’s real address at exactly the right moment. Nothing about the message looks wrong, because almost nothing about it is fake.
The questions that follow a near miss.
We are small and we do not move large sums. Does this reach us?
The size of the firm is not what decides it. What decides it is whether you release money on written instructions and whether anyone would gain by changing where those instructions point. One misdirected payment can be worth more than a month of billings to a small practice.
Is this the same thing as employee theft cover?
No. Employee dishonesty answers when somebody inside the firm takes the money. Fraudulent instruction answers when somebody outside persuades an honest employee to send it. They sit in different sections, often in different policies, and holding one does not give you the other.
Can money be recovered once it has left the account?
Sometimes, if your bank is told quickly and the funds have not been moved on again. Speed matters more than anything else you do. Call your bank first, report it to the Canadian Anti-Fraud Centre, and tell your broker in the same hour rather than the next morning.
Our accountant approved the payment. Does that sink the claim?
Approval is not the problem. The question is whether the verification step written into your policy was carried out. Read that condition now and build it into how payments are released, so the honest answer is already yes on the day you need to give it.
What if the money that went astray belonged to a client?
Then your professional liability policy may be in play as well as your cyber policy, because the client has a claim against the firm on top of the firm’s own loss. Tell both insurers early. Choosing one and holding the other back is how firms lose cover they had paid for.
Two that sit next to this on the same site: what a cyber policy does not cover and how employee dishonesty cover works.
Not the question you had? Send the wording and your question together through the quote file and you will get a written answer, not a sales call.
Read the cap before you need it, not after.
The funds transfer section is short. It takes a few minutes to find, and it holds the number your firm would actually be claiming against.