What Insurance Covers Phishing Losses?

Cyber insurance may cover response costs after a phishing incident, and crime coverage may cover certain resulting financial losses. Whether stolen credentials, a fraudulent transfer, or a system outage is covered depends on separate policy grants and conditions.

Phishing describes a method of deception, not one single insurance loss. If a message leads to a data breach, cyber insurance may help with covered forensic work, notification, data recovery, interruption, or third-party claims. The Federal Trade Commission describes these as possible first-party and third-party cyber coverage categories. If a phishing message tricks staff into sending funds or exposes credentials used to transfer money, a separate crime grant or endorsement may be needed.

Coverage can turn on what happened after the message arrived: whether someone accessed a system without authorization, whether the business voluntarily sent money, whether the fraudster used a covered transfer method, and whether required security or verification controls were followed. AIG’s specimen cyber policy treats certain security failures as covered events but excludes specified theft or transfers of money under its security and privacy liability section. Those specimen terms show why cyber response and reimbursement for funds are separate questions.

Compare the policy’s definition of a security incident, social-engineering and funds-transfer wording, waiting period for interruption, approved response vendors, and notice requirements. Check any sublimit and ask the insurer to address credential compromise and fraudulent payment scenarios separately.

Sources

  1. Crime Terms and Conditions. The Travelers Companies, Inc.; Insuring Agreements A.1 Employee Theft, A.3 Employee Theft of Client Property, B Forgery or Alteration, F Computer Fraud, G Funds Transfer Fraud, PDF pp.1–5; definitions E and AA, pp.7 and 10; exclusions IV.C–H, pp.14–15. Accessed 2026-09-25.
  2. Cyber Insurance. Federal Trade Commission; First-Party Coverage; Third-Party Coverage; What Should Your Cyber Insurance Policy Cover. Accessed 2026-09-25.
  3. CyberEdge specimen policy. AIG; Security and Privacy Coverage Section, PDF pp.11–18, especially exclusions p.18; Cyber Extortion Coverage Section, pp.29–31. Accessed 2026-09-25.

Updated . Answers describe typical policies, not your coverage; your policy wording decides what is covered. See the editorial policy or contact Spot with a correction and supporting source.

Let Spot Handle the Insurance Legwork.

Get help buying coverage and managing renewals, with less paperwork for your team. Start with a free consultation.

Talk to Spot