Hacked Company Loses Insurance Battle Over Customer Payment Scam
Hacked Company Loses Insurance Battle Over Customer Payment Scam
The information on this website is general in nature and does not take into account your objectives, financial situation, or needs. Consider seeking personal advice from a licensed adviser before acting on any information.
A company recently faced a significant setback after losing an insurance claim dispute related to funds stolen in a fraudulent email scheme.
Cybercriminals infiltrated the business's email system, sending out fake invoices that directed clients to pay into a bogus bank account.
Consequently, two customers inadvertently transferred a total of $66,148 to the fraudulent account.
Attempts to retrieve this money were unsuccessful, and the customers refused further payments to the company.
The company, holding a management liability insurance policy, sought to claim under its third-party crime coverage to recover the outstanding bills from the customers. However, AIG Australia denied the claim, stating that the policy only addressed "direct financial loss" from theft or fraud by a third party, and argued that since the stolen money belonged to customers, the business itself did not suffer a direct loss.
The Australian Financial Complaints Authority (AFCA) reviewed the case and acknowledged the company's loss. However, it determined that the loss did not align with the policy's specific terms. The ruling emphasized that only the company's customers faced direct financial loss, whereas the company experienced an indirect one due to subsequent non-payments.
The AFCA explained that the hack did not meet the company's policy definition of theft, as the stolen funds belonged to the customers, not the business. This discrepancy meant that the policy's electronic and computer crime coverage was not applicable. Additionally, the policy's criteria for "fraudulent act," which required acts of forgery or counterfeiting the insured had acted upon, were not met since the company was unaware of the false invoices.
This case highlights the critical distinction between direct and indirect financial losses in insurance claims, emphasizing the importance of understanding policy terms. For businesses, particularly those prone to cyber threats, it underscores the significance of having insurance coverage that appropriately addresses loss scenarios stemming from such events. It also serves as a cautionary tale of the complexities involved in recovering from cybercrime attacks without adequate protection.
Moving forward, businesses should ensure robust cybersecurity measures to prevent similar email hacks, coupled with clarifying insurance policies for adequate coverage against indirect financial losses as a result of customer fraud. This scenario may lead insurance providers to reevaluate their product offerings, potentially driving the development of more comprehensive cybercrime coverages. Additionally, the financial sector might witness increased discussions on how to formulate clearer policy definitions that align with the evolving nature of cyber threats.
Please Note: We do not endorse any specific products or companies. Some content is sourced from third parties, including press releases, and may not be independently verified for accuracy or completeness.
Australia's mandatory ransomware payment reporting regime is now a practical compliance issue for many business owners, not just a technology concern. Under the national cyber security reforms, entities above the relevant annual turnover threshold must report certain ransomware and cyber extortion payments within a short statutory timeframe. For SMEs operating close to, or above, that threshold, the change adds another layer to an already complex risk environment. - read more
Latest general insurance performance data from APRA points to an industry that remains financially resilient, with insurers benefiting from disciplined underwriting, investment income and a continued focus on pricing risk accurately. For Australian small and medium-sized businesses, that is useful context heading into renewal season, but it should not be read as a simple promise of cheaper premiums. - read more
Recent industry reporting on the latest insurance complaints environment points to a clear message for Australian small businesses: the hardest part of insurance is often not buying a policy, but relying on it when something goes wrong. Disputes continue to arise around claim delays, declined claims, settlement amounts, policy exclusions and communication breakdowns between customers and insurers. - read more
Australian businesses are increasingly using AI tools to research products, shortlist providers and understand policy options. That convenience now comes with a clear warning for small business owners: not every insurance answer surfaced by AI search is coming from a licensed, accountable or locally relevant source. - read more
A reported data breach involving Lifeline Australia has renewed attention on a widening protection gap in the Australian cyber insurance market. While Lifeline has indicated that help-seeker and financial information were not compromised, the incident is a timely reminder that staff, volunteer, client and supplier data can still create serious legal, operational and reputational exposure for any organisation. - read more
Understanding the ebbs and flows of your business finances is more than just knowing numbers; it's a vital component of your small business's longevity and success. In the ever-dynamic landscape of entrepreneurship, cash flow management emerges as a centerpiece in the grand puzzle of sustainability. Small businesses, with their limited resources, often face the pronounced challenge of maintaining a healthy financial heartbeat to thrive and grow. - read more
Professional indemnity insurance can help protect Australian businesses that provide advice, designs, health services, consulting, technology services or other professional work if a client alleges negligence, error, omission or breach of professional duty. - read more
Cyber security refers to the practices and technologies designed to protect computers, networks, programs, and data from unauthorized access, attacks, or damage. It's a crucial aspect of modern business operations, and understanding its importance is vital for all businesses, especially small ones. - read more
Public liability insurance can help protect Australian businesses against third-party injury or property damage claims. Learn what it may cover, common exclusions, when it may be required and what to check before arranging cover. - read more
Insurance is a vital component for any small business. It acts as a safety net, helping to protect your enterprise from unexpected financial losses. Whether you run a retail shop, a consultancy, or a manufacturing unit, having the right insurance coverages can make the difference between thriving and merely surviving. - read more
Knowledgebase
Term Life Insurance: A life insurance that provides a cover for a specific period of time - usually one to five years or until the insured reaches age 65 or 70.
No comments yet. Be the first to share your thoughts.