Cyber & digital risk

The email that isn't from your CEO: the Boss Scam, and what cyber cover does

India's market regulator has warned businesses about a fast-growing fraud it calls the Boss Scam: someone posing as your CEO or MD, instructing your finance team to move money. It doesn't break your systems. It breaks your process, and that is a different kind of risk to insure.

The message looks right. The name is right, the tone is right, the urgency is right. A senior person needs a payment made now, quietly, and someone in accounts wants to be helpful. That is the whole attack.

India's securities regulator has cautioned companies against a rising cyber fraud it named the Boss Scam, after the national cybercrime coordination body flagged a surge in cases. Fraudsters impersonate a chief executive or managing director over email, chat or messaging apps, and instruct a member of the finance or accounts team to transfer funds, usually with just enough pressure and plausibility to skip the normal checks. It is a version of what the industry calls business email compromise, and it is now one of the most common and costly frauds a business faces.

What makes it dangerous is that it is not really a hack. Your firewalls are intact, your systems are untouched, nothing was broken into. The target was a person and a process, and both did exactly what they were asked. Understanding that changes both how you prevent it and how you insure against it.

In short

  • The Boss Scam impersonates a senior leader to trick finance staff into transferring money, using urgency and plausibility rather than any technical break-in.
  • Because it exploits people and process, not systems, it is a different risk from a data breach or ransomware.
  • Cyber insurance can respond through a social-engineering or cyber-fraud extension, often with a sub-limit and, crucially, conditions.
  • The condition that matters most is usually a verification step — a call back on a known number before any payment or change of bank details.

Put simply: the Boss Scam is a social-engineering fraud, where a criminal manipulates a person into authorising a payment by pretending to be someone in authority. Cyber insurance may cover the resulting loss under a specific extension, subject to the policy's limits and to the business having followed its own payment-verification steps.

It doesn't break your systems. It breaks your process.

Most cyber defences are built to keep attackers out of your network. This attack does not try to get in. It arrives through the front door, as an ordinary-looking instruction from someone your team trusts, and it relies on a small, human wish to be responsive and not to question a senior person. That is why technology alone does not stop it, and why a business with excellent security can still lose money this way. The defence is not another firewall; it is a habit.

The habit that stops it

The single most effective control is boring, and that is its strength: verify any payment instruction, and especially any change of bank details, by calling the person back on a number you already have, never a number or contact given in the message itself. Build it into the process so it does not depend on anyone's judgement in the moment, make it a rule that no one is ever criticised for applying, even to the chief executive, and the Boss Scam largely stops working. Regulators pushing this exact protocol are not being cautious for its own sake; they are naming the one step that defeats the fraud.

How cyber cover responds, and the condition that decides it

Cyber insurance can answer for this, but not automatically. Social-engineering or cyber-fraud loss is often covered only under a specific extension, frequently with its own sub-limit, and almost always on the condition that the business followed its stated verification steps. That last point is the one that decides claims: a policy may cover the fraudulent transfer, but if the agreed call-back was skipped, cover can be jeopardised. In other words, the prevention and the cover are two halves of the same discipline, which is exactly how it should be read.

Where it sits among your other cyber risks

The Boss Scam is one member of a wider family. A genuine break-in that steals data, or ransomware that locks your systems, is a different attack with a different part of the policy behind it. Knowing which is which helps you buy cover that matches your real exposure, rather than assuming a single line item marked "cyber" answers for all of it.

How the Boss Scam maps to cover

It helps to separate the fraud from the wider cyber risks, because each is answered by a different part of a policy. This is category-level — it describes how cover generally works, not any one insurer's product.

How the Boss Scam and its cousins map to the cover that responds (general categories, subject to policy wording)
The lossThe cover that typically responds
Money transferred on a fraudulent "CEO" or vendor instructionCyber (social engineering / cyber fraud), subject to verification conditions
A genuine break-in that exposes dataCyber (data breach response and privacy liability)
Systems locked and operations stopped by ransomwareCyber (ransomware and cyber extortion)
A fraud where the verification step was skippedOften not covered — the condition matters

A five-minute check

You don't need a full review to find the biggest gaps. Five questions usually surface them:

  1. Do you have a call-back rule for payments and bank-detail changes?A verification step, on a number you already hold, that applies to everyone including the chief executive. This is the control that matters most.
  2. Does your cyber policy include social-engineering cover?Check whether it is there at all, at what sub-limit, and what conditions it places on you for a claim to stand.
  3. Does your finance team know they can pause a senior instruction?The fraud relies on people not questioning authority. Make it explicit that verifying is never insubordination.
  4. Do you also hold cover for a genuine breach and ransomware?The Boss Scam is one risk among several. Make sure the rest are covered too, not assumed.
  5. If money went out tomorrow, who do you call first?Fast action can sometimes recall a transfer. Know the bank contact, the cybercrime helpline and your broker before you need them.

Frequently asked questions

What is the Boss Scam, or business email compromise?

It is a fraud in which a criminal impersonates a senior leader, or sometimes a supplier, to trick a member of the finance team into transferring money or changing payment details. It uses urgency and plausibility rather than any technical break-in, which is why it can succeed even against a business with strong security.

Does cyber insurance cover it?

It can, usually under a specific social-engineering or cyber-fraud extension, often with a sub-limit and on the condition that the business followed its own payment-verification steps. Whether your policy includes it, and on what terms, is worth confirming before you rely on it.

Is it a hack? Will better IT security stop it?

It is not a hack in the usual sense; nothing in your systems is broken into. Better technology helps at the margins, but because the attack targets people and process, the decisive defence is a verification habit, not another security tool.

What is the single best way to prevent it?

A call-back rule. Verify any payment instruction or change of bank details by contacting the person on a number you already have, never one supplied in the message. Make it a fixed step that applies to everyone, so it never depends on someone's judgement under pressure.

Can a broker help if we are hit?

A broker's duty under IRDAI regulation is to you, the client, not the insurer, so a broker can help you respond quickly, meet the policy conditions and fight a complex claim on your behalf. That describes the effort put in, not a guaranteed outcome.

What happens when you talk to us

A 20-minute video call with a Growth Advisor — no obligation, and no quote pushed. It opens with a five-minute video from our founder on how the benefits stack works and why Ethika exists; the rest is your questions. You'll leave with an honest read on your current cover and claims experience, and a straight answer on whether we can genuinely help — even if you never become a client.

Talk to us

20 minutes with a Growth Advisor. No obligation.

A note on this page. Everything here is general information about cyber insurance, not insurance, legal, financial or tax advice, and nothing is an offer of cover. Whether social-engineering loss is covered, at what limit and on what conditions, depends on your own policy wording. For advice about your situation, talk to us. Regulatory references are the current position and should be confirmed with counsel.