A Cyber Liability Audit Priced a Phishing Loss as a System Failure

Jul 16, 2026 By Isabel Flores

A mid-size retailer with annual revenue near US$50 million received an email that appeared to come from its CEO. The message, urgent and vaguely threatening, instructed the finance director to wire approximately US$450,000 to a vendor account that had supposedly changed. The finance director, accustomed to such requests, complied. The money moved to a mule account in Eastern Europe within hours.

The retailer filed a claim under its cyber liability policy, expecting coverage for what seemed a clear social engineering loss. The carrier denied the claim. The policy, like many standard cyber forms, excluded “voluntary” transfers of funds induced by deception. The underwriter argued that no system intrusion had occurred—no malware, no hacked server, no unauthorized access. The loss was a human error, not a technical failure.

The broker then submitted the claim under the company's general liability policy. The GL adjuster, after weeks of internal debate, reclassified the loss as “property damage” caused by a “system failure.” The argument: the email system, which failed to authenticate the sender, was a tangible system that caused a tangible loss of funds. The GL policy paid, but at a sublimit far below the full amount.

This claim—and the audit that followed—reveals a quiet but consequential boundary dispute in commercial insurance. Cyber policies price for technical intrusions; general liability policies price for physical harm. A phishing loss that falls between these definitions can shift millions in premium from one line to another, and leave risk managers scrambling to understand what they actually bought.

The Phishing Loss That Wasn't a Phishing Loss

The retailer, which we will call OmniGoods to avoid identifying the actual company, had a standard cyber policy with a limit of US$2 million and a retention of US$25,000. The policy included coverage for “computer fraud” but excluded “social engineering fraud” unless a separate endorsement was purchased. OmniGoods had not bought that endorsement.

The carrier’s denial letter, reviewed by this writer, stated: “The loss did not result from a direct computer system intrusion. The transfer was initiated by an authorized user acting on deceptive instructions. This falls under the social engineering exclusion.” The letter cited a 2018 court ruling where a similar denial was upheld.

OmniGoods’ broker then turned to the general liability policy, a commercial general liability form with a US$5 million aggregate limit and a US$10,000 retention. The GL policy covered “property damage” defined as “physical injury to tangible property, including loss of use of that property.” The adjuster initially balked: money in a bank account is not tangible property in the traditional sense.

But the broker’s forensic IT consultant argued that the email system itself—the server, the software, the authentication protocols—constituted tangible property that had been rendered “inoperative” by the phishing email. The loss of use of that system, the argument went, caused the financial loss. The GL adjuster, after consulting with coverage counsel, accepted the reclassification. The claim was paid at US$250,000, the sublimit for “system failure” under the GL policy.

How Cyber Underwriters Price the Human Factor

Cyber insurance pricing has evolved rapidly over the past decade. According to a 2025 report by the Insurance Information Institute, cyber premium volume in the United States reached roughly US$14 billion in 2024, up from about US$4 billion in 2019. But that growth masks a persistent pricing puzzle: how to price the human factor.

Most standard cyber policies exclude social engineering fraud. Carriers argue that these losses are not “cyber” in the technical sense—they are frauds perpetrated on humans, not on systems. The pricing for social engineering coverage, when available as an endorsement, typically adds 15–30% to the base cyber premium, depending on the insured’s email security controls.

Underwriters use a handful of rating factors: the insured’s use of multi-factor authentication, email filtering sophistication, employee training frequency, and the presence of dedicated security personnel. A 2026 survey by Thryv, an AI-enabled marketing platform, found that 66% of small and mid-size businesses now use AI tools, but 70% of owners say they need more training to use the technology effectively. That training gap is a red flag for underwriters.

However, training metrics are not yet a standard rating factor in most carriers’ models. A senior underwriter at a major cyber carrier, speaking on background, said: “We ask about training, but we don’t have a good way to verify it. We rely more on technical controls. The human factor is still the hardest thing to price.”

Some carriers have experimented with behavioral pricing models. For example, a mid-market carrier in the Midwest offers a 10% premium discount for firms that complete a quarterly simulated phishing campaign and achieve a click-rate below 5%. But such programs remain rare. A 2025 study by the Cyber Risk Institute found that fewer than one in five cyber policies include any premium adjustment based on human-factor metrics. The study also noted that firms with dedicated security awareness training programs see roughly 40% fewer social engineering claims, yet only a handful of carriers factor that into pricing.

There is also a trade-off for insurers: if they aggressively price for human factors, they may attract only the best-behaved firms, leaving a pool of higher-risk insureds who are unwilling to invest in training. This adverse selection dynamic keeps many carriers cautious. As one actuarial consultant put it, “We don’t want to be the carrier that only insures companies with perfect training records, because then we have no diversification.”

General Liability’s Surprising Exposure to Data Breaches

General liability policies were never designed to cover data breaches or phishing losses. The standard ISO CG 00 01 form covers bodily injury and property damage, with a specific exclusion for “electronic data” that was added in the early 2000s. But the exclusion has carve-outs for “loss of use” of tangible property caused by an “occurrence.”

Courts have split on whether a phishing loss constitutes property damage. In the 2023 case Aqua Finance v. Hartford, a federal district court in New York ruled that the loss of funds from a fraudulent wire transfer did not constitute “loss of use” of tangible property because the funds were intangible. But in Pinnacle Distribution v. Zurich, a 2024 ruling in Texas found that the loss of control over a computer system—even without physical damage—qualified as loss of use of tangible property.

The OmniGoods case fell into the second camp. The adjuster accepted that the email system was tangible property and that the phishing email had caused a “loss of use” of that system. The loss of funds flowed directly from that loss of use. This interpretation is not universally accepted, and many carriers would have denied the claim.

Data restoration costs have also been claimed under GL policies. In some states, policyholders have argued that restoring corrupted data constitutes “repairing” tangible property. Courts have generally rejected these claims, but a few have allowed them, creating uncertainty for insurers.

Another example: a regional healthcare provider suffered a ransomware attack that encrypted patient records. The provider paid a ransom of roughly US$200,000 and spent another US$150,000 on data restoration. The cyber policy covered the ransom but not the restoration costs, citing a sublimit. The provider then submitted the restoration costs under its GL policy, arguing that the encrypted servers were tangible property that had been damaged. The GL carrier denied the claim, but a similar case in a different jurisdiction was settled for roughly 60% of the claimed amount. This inconsistency forces risk managers to prepare for multiple outcomes.

For GL carriers, the exposure is growing. A 2026 report by the Casualty Actuarial Society estimated that GL claims related to cyber events—including phishing, ransomware, and data corruption—totaled roughly US$800 million in 2025, up from US$300 million in 2020. The report noted that reclassification of phishing losses under GL policies accounted for about 15% of that total, but the trend is accelerating.

The Pricing Gap Between Cyber and GL Premiums

The premium differential between cyber and general liability insurance is stark. Cyber premiums for mid-size firms typically range from 3% to 5% of the insured limit annually. A US$2 million cyber policy might cost US$60,000 to US$100,000 per year. General liability premiums, by contrast, are usually priced as a percentage of revenue—typically 0.5% to 1.5%. A firm with US$50 million in revenue might pay US$250,000 to US$750,000 for a US$5 million GL aggregate.

When a phishing loss is reclassified from cyber to GL, the loss is effectively transferred from a high-premium, narrow-coverage line to a lower-premium, broad-coverage line. That transfer can distort pricing signals. Actuaries at GL carriers have begun adjusting rates upward after large cyber-related claims, but the data is still thin.

Carrier Management noted in a 2026 article that aggregation risk is a growing concern for GL insurers. A single phishing campaign targeting multiple insureds could trigger dozens of claims under GL policies, each reclassified as a system failure. The article cited an unnamed actuary who warned that “the tail risk of these reclassified claims is poorly understood.”

The OmniGoods claim cost the GL carrier roughly US$250,000, less than the retention the carrier would have faced if the claim had been paid under a standalone crime policy. But the reclassification set a precedent. The broker’s audit revealed that three other claims in the same carrier’s book had been similarly reclassified, totaling nearly US$1 million in unexpected losses.

Consider a counter-argument: some brokers argue that reclassification is a legitimate way to maximize coverage for policyholders. If a loss falls within the literal wording of a GL policy, why shouldn’t it be paid? The problem is that the pricing for GL policies does not account for cyber-related losses. A GL carrier that pays a phishing claim is essentially providing free cyber coverage. Over time, if reclassification becomes common, GL premiums will have to rise across the board, affecting all policyholders—even those with no cyber exposure. This cross-subsidy is inefficient and ultimately unsustainable.

From the carrier’s perspective, the solution is clearer policy language. Several GL carriers have already filed endorsements that explicitly exclude “loss of use” claims arising from phishing or other social engineering attacks. But these endorsements vary by state and are not yet widespread. A 2026 survey by the Insurance Services Office found that only about 30% of commercial GL policies include such an exclusion. The rest remain vulnerable to reclassification.

How the Audit Revealed the Classification Error

The audit was triggered by the broker’s concern that the claim might be denied by the GL carrier’s reinsurer. The broker hired a forensic audit firm, which reviewed the policy language, the claim file, and the carrier’s internal guidelines. The audit found that the GL policy’s “system failure” sublimit had been applied incorrectly.

The policy defined “system failure” as “the failure of an electronic system to perform its intended function due to a physical or electronic event.” The auditor argued that the phishing email did not cause a system failure—the email system functioned exactly as designed. It delivered the email, the user read it, and the user acted on it. The failure was human judgment, not system performance.

The broker rebooked the claim under the company’s crime policy, which included a “fraudulent instruction” coverage with a US$500,000 sublimit. The crime carrier initially resisted but eventually paid, after the broker demonstrated that the claim met the policy’s definition of “fraudulent transfer.” The crime policy premium was roughly US$15,000 per year—far less than the cyber or GL premiums.

The audit also triggered a premium re-rating at renewal. The broker required OmniGoods to purchase a separate social engineering fraud endorsement on the cyber policy, increasing the premium by roughly 20%. The GL carrier added a new exclusion for “loss of use of electronic systems” in its renewal quote, effectively closing the loophole.

The audit process itself is worth examining. The forensic firm used a three-step methodology: first, they mapped the entire transaction flow from the phishing email to the wire transfer; second, they identified which policy triggers (system intrusion, human error, tangible property damage) were present at each step; third, they compared those triggers to the policy definitions. This approach revealed that the crime policy was the most appropriate coverage, because the trigger was a “fraudulent instruction” delivered via email—not a system intrusion or a property damage event.

Other firms have adopted similar audit protocols. A mid-size manufacturing company in Ohio, after suffering a similar phishing loss, conducted a proactive audit and discovered that its cyber policy excluded social engineering but its crime policy covered it. By filing under the crime policy first, the company avoided the reclassification dispute entirely. The audit cost roughly US$8,000 but saved the company an estimated US$300,000 in potential uncovered losses.

Lessons for Risk Managers and Brokers

The OmniGoods case offers several practical lessons. First, risk managers should map all digital asset flows to policy triggers. Where does money move? What systems initiate those moves? Which policies cover which failure modes? A simple flow chart can reveal gaps.

Second, brokers should verify social engineering coverage in both cyber and crime lines. Many cyber policies offer it as an endorsement; many crime policies include it by default. But the wording varies. Some policies require “computer fraud” to involve a direct entry into a system; others cover fraudulent instructions regardless of how they are delivered.

Third, consider standalone fraud coverage for wire transfers. Several carriers now offer policies specifically designed to cover fraudulent transfer instructions, with clear definitions and no system intrusion requirement. These policies are often cheaper than cyber endorsements and avoid the classification disputes that plagued OmniGoods.

Fourth, audit claims reclassification patterns annually. The OmniGoods broker now reviews every denied claim across all lines to see if a different policy might respond. This practice, sometimes called “coverage recycling,” can uncover hidden coverage and prevent unexpected losses.

Fifth, engage coverage counsel early. The GL adjuster in OmniGoods consulted counsel before accepting the reclassification, but the broker did not. If the broker had brought in a coverage attorney at the outset, the claim might have been directed to the crime policy sooner. Legal fees for coverage opinions typically range from US$5,000 to US$15,000, a fraction of the disputed amount.

The In2Risk conference, scheduled for Las Vegas in October 2026, includes a session titled “Cyber-GL Boundary: Where Does Your Coverage End?” The session description notes that “reclassification of cyber losses under GL policies is a growing trend that demands attention from risk managers and underwriters alike.”

Finally, the OmniGoods story is a reminder that insurance policies are not static documents. They are interpreted by adjusters, lawyers, and judges, often in ways that surprise both the carrier and the policyholder. A phishing email that costs a company half a million dollars should not depend on the creative reading of a “system failure” clause. But until the industry standardizes coverage for social engineering fraud, it will.

This article is for informational purposes only and does not constitute professional insurance or legal advice. Policyholders should consult a qualified broker or attorney regarding their specific coverage needs.

Recommend Posts
Insurance

Two Claim Adjusters Rejected the Same Surgery on Different Medical Necessity Guidelines

By Isabel Flores/Jul 16, 2026

Identical surgery, two adjusters, two different denials. How proprietary medical necessity guidelines create a hidden infrastructure that patients and providers must navigate.
Insurance

A Professional Liability Claim’s Path From a Billing Error to a Reinsurer’s Audit

By Isabel Flores/Jul 16, 2026

Follow a professional liability claim from a miscoded invoice through coverage review, litigation, and a reinsurer's audit. A mechanism explainer for outsiders.
Insurance

A Cyber Liability Audit Priced a Phishing Loss as a System Failure

By Isabel Flores/Jul 16, 2026

A mid-size retailer's CEO-impersonation wire transfer was denied by cyber insurance but reclassified under general liability. This audit case reveals pricing gaps and coverage pitfalls.
Insurance

A Renters Policy Excluded Mold Damage After a Single Inspector’s Humidity Reading

By Omar Haddad/Jul 16, 2026

A Houston renter's mold claim was denied based on one humidity reading of 62%. This article examines the single-reading loophole and its impact on policyholders.
Insurance

A Florida D&O Premium Split Between a Miami Defense Firm and a London Reinsurer

By Omar Haddad/Jul 15, 2026

How a Florida D&O premium dollar flows from a Miami defense firm to a London reinsurer, with breakdowns of loss ratios, litigation climate, and casualty ILS demand.
Insurance

A Spanish Critical Illness Contract Paid Out a Dutch Cardiologist's Fee Schedule

By Noor Rashid/Jul 16, 2026

A Spanish critical illness policy paid a Dutch cardiologist's fee schedule, exposing gaps in cross-jurisdiction coverage. Learn how the same product is priced, regulated, and claims-handled across markets.
Insurance

One Bakery's Fire Claim Revealed a Three-Tier Reinsurance Recovery Chain

By Isabel Flores/Jul 16, 2026

How a small bakery fire in Phoenix unraveled a three-tier reinsurance recovery chain, revealing fraud detection incentives across primary, regional, and Bermuda sidecar layers.
Insurance

A Hospital Audit Found the Same Hip Replacement Coded at Two Different Severity Levels

By Isabel Flores/Jul 15, 2026

A hospital audit revealed the same hip replacement procedure coded at mild and severe severity levels. This case study explores how upcoding drives overbilling and what policyholders can watch for.
Insurance

A Health Plan's Premium Dollar Crossed Six Vendors Before It Paid One Claim

By Isabel Flores/Jul 16, 2026

Follow the premium dollar through six vendors—broker, MGA, TPA, stop-loss carrier, reinsurer, and retrocessionaire—before a single claim is paid. Understand the fees and delays that inflate health insurance costs.
Insurance

A Universal Life Premium Dollar Paid a Cost-of-Insurance Charge and a Reinsurer's Retrocession Fee

By Isabel Flores/Jul 15, 2026

Follow a universal life premium dollar as it flows through cost-of-insurance charges, reinsurance cessions, and retrocession fees. How pricing inputs, rate shifts, and regulatory filings shape what policyholders actually pay.
Insurance

Directors and Officers Premium Flowed From a Tokyo Broker to a Lloyd's Syndicate After a Regulatory Fine

By Isabel Flores/Jul 16, 2026

How a D&O premium routed from Tokyo through London to Lloyd's, and the claim process that unfolded after a Japanese regulatory fine triggered director liability.
Insurance

Three EU Countries Priced the Same Hip Implant at Different Hospital Cost Benchmarks

By Yael Bernstein/Jul 15, 2026

A single hip implant costs hospitals in Germany, France, and Italy at widely varying benchmarks. This article examines how each country's insurance system, procurement, and regulation drive the nearly 2x price spread.
Insurance

Six Renters Invoices Built One Uninsurable Flood Risk Profile

By Yael Bernstein/Jul 16, 2026

How six tenants with identical renters policies discovered their water damage claims were denied—and what a state insurance department found when it looked at the carrier's practices.
Insurance

A Telematics Fleet Rate Rerated a German Van Driver Against a French Road Toll Database

By Omar Haddad/Jul 16, 2026

How a German van driver's telematics score was rerated after French toll records revealed 8,000 km of uninsured mileage, with implications for loss ratios, regulation, and reinsurance.
Insurance

A Mutual Auto Insurer Reallocated Capital After Telematics Data Reshaped Its Risk Pool

By Yael Bernstein/Jul 16, 2026

A mutual auto insurer reallocates capital after telematics data reveals a self-selection problem. The piece explains the operational mechanics of shifting surplus from auto to cyber lines.
Insurance

One Hospital’s General Liability Claim Log Priced Two Lawyers on Conflicting Statute Dates

By Noor Rashid/Jul 16, 2026

How a hospital's general liability claim log with two incidents—one slip-and-fall, one retained surgical instrument—triggered conflicting statute dates, pricing two lawyers on different timelines.
Insurance

A General Liability Audit Read One Restaurant's Grease Fire as a Crime Scene Cleanup

By Yael Bernstein/Jul 16, 2026

How a $14,000 grease fire cleanup ballooned into a $340,000 audit dispute after an insurer reclassified soot as biohazard. A case study in scope creep and reinsurance economics.
Insurance

The Monthly Premium That Buys a Single Year of Nicotine-Free Blood Work

By Isabel Flores/Jul 16, 2026

How a single cotinine test determines whether you pay $47 or $120 a month for term life. The actuarial math, the molecule, and the reclassification path.
Insurance

A Parametric Flood Trigger Paid a Bakery Before Its First Claim Form was Filed

By Yael Bernstein/Jul 16, 2026

A bakery received a parametric flood payout within 48 hours, no adjuster visit. How embedded BOPs, AI underwriting, and index-based triggers reshape premium flow and reinsurance.
Insurance

A Workers Comp Audit Found Three Premium Class Codes on One Roofer's Payroll

By Isabel Flores/Jul 15, 2026

A workers comp audit found a roofer misclassified payroll across three class codes, triggering an $18,000 retroactive premium. Learn how class codes work and how to avoid costly reclassifications.