A February court decision shows how coverage can be limited for social engineering fraud without separate policy limits for such exposures.
In Mississippi Silicon Holdings LLC v. Axis Insurance Co., the policyholder’s recovery was limited to $100,000 under the sublimit included in the social engineering section of its management liability policy with the unit of Bermuda-based Axis Capital Holdings Ltd.
The chief financial officer at a silicon metal manufacturer was tricked into transferring more than $1 million to incorrect accounts after the company received an email with the name of a known employee of a Russian supplier in the “from” line that changed banking and payment instructions.
Two payments were made, electronic transfers of $250,030 and $775,851, using the new instructions, and the deception was only realized after a call from the supplier saying it had not received its payments.
Mississippi Silicon sought coverage under the $1 million policy limit, but a U.S. district court judge ruled the lower sublimit should apply.
In general, “the common loss we’ve been seeing is an email pretending to be a vendor saying that banking instructions have been changed,” said Cara LaTorre, vice president and special risk practice leader in New York with Aon PLC.
Such attacks are “constantly evolving as scammers become more sophisticated,” the FBI said in its 2019 Internet Crime Report from The Internet Crime Complaint Center.