Will Crime Insurance Cover a Fake Vendor Bank-Account Change?
It can, but do not assume a crime policy covers money an employee willingly sends after a fake vendor bank-change request. Look for wording that expressly addresses vendor impersonation and employee-authorized payments, including any endorsement changing a voluntary-parting exclusion. Then inspect verification conditions, the applicable fraud limit and cyber-policy coordination.
By Atlas Risk Partners ·
Start with the payment your team actually authorizes
Hypothetical example: A software company's accounts-payable team receives a bank-account update apparently from its development contractor. An employee edits the vendor record, and a manager approves the next payment. The money reaches a fraudster. Nobody accessed the software company's banking credentials or compromised its own network.
Use those facts when reviewing coverage. Ask specifically about an authorized employee sending company money because of a deceptive instruction—not simply about money being stolen electronically.
Chubb's cyber product overview distinguishes computer intrusion, deception directed at a bank, and deception directed at an employee. It lists these under separate cyber-crime headings available by endorsement. Those are Chubb's product descriptions, not universal definitions. The practical lesson is to match the payment scenario to the actual wording.
Find the coverage grant and the exclusion it changes
Chubb describes a crime-policy endorsement covering vendor impersonation and restoring protection otherwise affected by its voluntary-parting exclusion. That is a product-specific example of why an endorsement matters when an employee willingly transfers money to an impostor. It does not establish coverage under another policy.
For renewal, ask for the relevant coverage grant, definitions and exclusions to be identified together. Treat a missing or unclear answer as an unresolved coverage question, rather than assuming a computer-fraud heading is sufficient.
- Impersonation: Does the wording cover someone pretending to be an existing vendor or supplier?
- Authorization: Does it address an employee approving a payment because of deception?
- Intrusion: Would protection apply without unauthorized access to your own systems?
- People: Do the definitions accommodate outsourced bookkeeping staff who handle payments?
- Exclusions: What restrictions remain after the social-engineering endorsement is added?