Vancouver · Closed, opens 09:00604-324-5711Delta · Closed, opens 09:00604-635-0890Surrey · Closed, opens 09:00604-319-1000
Business Insurance BC  /  Cyber Insurance for Accounting Firms BC  /  The Sub-Limit on Fraudulent Instruction
Fraudulent instruction

A payment sent on a fake instruction is not a break-in, and your policy treats it differently.

A supplier writes to say the banking details have changed. The message is convincing, and it sits inside a thread you already trust. The money leaves on your own instruction, and that single fact decides which part of the policy answers and how much of the loss it carries. Most firms find the answer in a limit they have never read.

Start a quote file Read the short answer first
Capped

Funds transfer sits under a smaller limit.

Voluntary

You pressed send, so wordings differ.

Callback

One verified phone call ends most of it.

The quick version

Does cyber insurance pay when money is wired on a fake instruction?

Often yes, but rarely up to the full policy limit. A transfer your own staff made sits in the funds transfer fraud or social engineering section of a cyber policy, and that section normally carries its own smaller limit inside the wording. A firm can hold a large cyber limit and still find the fraudulent instruction cap set at a small fraction of it. The number that matters is on the declarations page, not on the front of the policy.

The reason sits in how the loss happens. Nothing was forced. No system was broken into. Somebody in your office read a message, believed it, and released the payment. Insurers treat that as a different risk because it turns on office habits rather than on software, and a separately priced risk is what produces a separately capped limit.

Where firms find out

The gap shows up at the worst moment, when the real supplier calls to ask why they have not been paid. By then the funds have usually moved through two or three accounts. The firm turns to its cyber policy and learns three things at once: the section covering this loss is capped, the cap may have to last the whole policy year rather than refreshing for each incident, and a deductible sits underneath it. The Canadian Anti-Fraud Centre describes the common version of this fraud plainly, as a spoofed email “informing the business of a change in payment details”, sent to a business that already deals with that supplier. Read the Anti-Fraud Centre page on spear phishing (opens in a new tab).

What the cover answers

Four questions that decide what gets paid.

Which section the loss falls into

Funds transfer fraud, social engineering fraud and fraudulent instruction are three names for closely related cover. Some policies grant all of it, some grant one version and exclude the others. The wording bound at renewal settles this long before anything happens.

Whether the cap refreshes or runs out

A limit that applies to each incident behaves very differently from one that has to last twelve months. Firms hit twice in a busy season are the ones who find out which they bought, and they find out after the second loss.

Whose money moved

Cover for your own funds and cover for money you hold on behalf of a client are not always the same grant. A practice running a trust account should read both, because the second is the one that ends in a complaint to your regulator as well as a claim.

What the policy expected you to do first

Many wordings make payment conditional on a verification step, usually a call to a number you already held before the request arrived. Where that condition exists and the step was skipped, a claim can fail even though the cover is there.

How it usually happens

Three ways the instruction arrives.

The supplier who changed banks

A familiar invoice arrives with new banking details and a short apology for the switch. Everything else about the message is ordinary, including the thread it sits in and the signature at the bottom. It is paid without a second look, because the relationship is years old.

The partner who is travelling

A message from a senior name asks for a transfer to close something before a deadline, and asks that it be handled quietly. Urgency and secrecy arrive together in almost every version of this. Both are there to stop the one phone call that would have ended it.

The client whose email was read

Here the fraudster spoofs nothing. They are sitting inside a client’s mailbox, reading a file until money is due, then sending the instruction from the client’s real address at exactly the right moment. Nothing about the message looks wrong, because almost nothing about it is fake.

Send us the funds transfer section

Tell us your cyber limit and we will find the smaller limit sitting under it.

Send your declarations page and the policy wording. You will get a written note showing the fraudulent instruction limit, whether it applies to each incident or to the year, and what the policy expects your office to do before a payment goes out. If your cover is already sound, we will say so.

Find my real limit
What people ask us

The questions that follow a near miss.

We are small and we do not move large sums. Does this reach us?

The size of the firm is not what decides it. What decides it is whether you release money on written instructions and whether anyone would gain by changing where those instructions point. One misdirected payment can be worth more than a month of billings to a small practice.

Is this the same thing as employee theft cover?

No. Employee dishonesty answers when somebody inside the firm takes the money. Fraudulent instruction answers when somebody outside persuades an honest employee to send it. They sit in different sections, often in different policies, and holding one does not give you the other.

Can money be recovered once it has left the account?

Sometimes, if your bank is told quickly and the funds have not been moved on again. Speed matters more than anything else you do. Call your bank first, report it to the Canadian Anti-Fraud Centre, and tell your broker in the same hour rather than the next morning.

Our accountant approved the payment. Does that sink the claim?

Approval is not the problem. The question is whether the verification step written into your policy was carried out. Read that condition now and build it into how payments are released, so the honest answer is already yes on the day you need to give it.

What if the money that went astray belonged to a client?

Then your professional liability policy may be in play as well as your cyber policy, because the client has a claim against the firm on top of the firm’s own loss. Tell both insurers early. Choosing one and holding the other back is how firms lose cover they had paid for.

Two that sit next to this on the same site: what a cyber policy does not cover and how employee dishonesty cover works.

Not the question you had? Send the wording and your question together through the quote file and you will get a written answer, not a sales call.

Read the cap before you need it, not after.

The funds transfer section is short. It takes a few minutes to find, and it holds the number your firm would actually be claiming against.