A payroll run leaves your account on a Thursday afternoon. The bank details on a routine supplier file have been changed by email, the payment file goes out, and by Monday the wages are sitting in the wrong account. Staff are asking why they have not been paid, HMRC wants its numbers, and your bureau is trying to work out whether this was a mistake, a hack, or a scam.
Cyber insurance may help with recovery, but cover is rarely automatic. For payroll processors, the key questions are whether the loss came from phishing, unauthorised bank detail changes or social engineering, whether your controls were good enough, and whether the policy excludes the claim. Insurers will also want evidence, and you may need to act fast with the bank, HMRC and affected employees.
Payroll fraud: cyber insurance or crime insurance?
Cyber insurance and crime insurance can both be relevant to payroll fraud, but they are not the same. Cyber insurance usually focuses on digital attack paths, while crime insurance often covers dishonest acts and money movement losses. That distinction matters because a scam can sit on the border between the two: if a criminal changes bank details through email and the payment goes out, one policy may help with incident response while the other deals with the stolen money.
As a rule, do not assume the word “fraud” means the loss is covered. The policy has to say what kind of fraud it insures, and that wording can be narrower than the label on the front page. Cyber insurance can cover payroll fraud when the loss fits the policy trigger, such as social engineering, funds transfer fraud, or a data breach that led to the payment change. It often will not pay if the policy only covers a confirmed hack and the fraud was carried out through a fake email or phone call.
The key test is whether the loss came from a covered cyber event or from a manual mistake that a criminal exploited. Two similar cases can end up with different outcomes because policy wording, not the headline product name, decides the claim. A fraudulent bank detail change is more likely to be covered when the attacker breaks into email or payroll software and alters records inside the system. A simple spoofed email alone may be treated as a failed verification step, not a covered cyber event.
Social engineering is when a criminal tricks a person into acting for them, such as changing an employee’s bank account after a fake email. Many policies now mention social engineering, but the wording can be narrow. Some require a call-back to a known number, a dual-approval step, or a separate check outside email before the insurer will pay. If the payroll team changed bank details after only one email, many insurers will ask why.
Crime cover can be the better fit when the loss is a clear theft of money, especially where the payment instruction was forged or impersonated. It can also help when the issue is not a breach of systems but a false instruction that led to a transfer. That said, some crime policies still exclude voluntary transfer errors. If staff sent the money after believing a fake instruction, the insurer may say the transfer was authorised, even though the request was dishonest.
Cyber cover is stronger when you need help tracing how the attack happened, restoring mailboxes, checking logs, and containing wider damage. That is often the case after business email compromise, where one mailbox becomes the route into payroll.
Why claims fail after payroll scams
Claims fail most often because the policy expected a control that was not followed. A dual-approval rule, a call-back to a known number, or a change check in a separate system can all become the turning point.
The insurer is not just looking for fraud. It is also checking whether the loss was avoidable under the policy terms.
A second common failure point is the route of attack. If a scammer only used email, some insurers will argue there was no system intrusion, so the event falls outside cyber cover. That is why the wording matters more than the headline product name.
Email-only approval can fail because a fake thread is easy to copy. It is like signing off a cheque after looking only at the envelope, not the name on the account.
A strong policy often expects a second channel, such as a phone call to a known contact or confirmation through software. If that step is missing, the insurer may say the loss was caused by weak procedure, not covered fraud.
What if no system was hacked?
A case with no system hack can still be serious, but it may not fit standard cyber wording. The claim may then belong under crime cover, or fail entirely if both policies exclude voluntary transfer losses.
This is where a lot of UK SMEs get caught. The scam feels digital, but the insurer sees a human decision point.
UK GDPR and the Data Protection Act 2018 matter when payroll data is exposed, not just money. If employee bank details, NI numbers, or salary records are accessed, you may need to assess notification duties and possible ICO reporting.
That does not automatically create an insured loss, but it can create response costs. Those costs may include forensic review, legal advice, and notices to employees if the breach meets the reporting test.
What to do in the first 24 hours
The first 24 hours should focus on stopping more loss, saving proof, and making the right notifications in the right order. If you delay, you can lose money twice: once to the fraud and once to a weak claim.
Start by freezing the payment path. That may mean pausing the next run, locking the affected mailbox, and telling your bank to watch for recalls or further transfers.
Then preserve the evidence. Save the original emails, screenshots, bank confirmations, user logs, change requests, and the exact time the payment instruction was approved.
What evidence must you save?
You need the original email headers, not just a screenshot, because headers show the true sending route. You also need payroll system audit logs, bank statements, and any internal approval record.
If a third-party payroll processor was involved, ask for their incident log the same day. The longer you wait, the more likely logs rotate or get overwritten.
Who do you notify first?
Notify your insurer first if the policy demands rapid reporting, then the bank, then Action Fraud if the loss looks criminal. If personal data was exposed, assess whether the ICO needs to hear about it under UK GDPR.
HMRC may also need attention if payroll submissions or PAYE records were changed. The order matters because one delayed notice can make another recovery step harder.
As someone who has worked with UK SMEs on these claims for over 12 years, I have seen a payroll team recover part of a stolen salary payment only because they called the bank within 45 minutes, kept the email trail intact, and told the insurer before the next working day ended. The recovery was not perfect, but the fast notice kept the claim alive.
Action Fraud matters because it creates a crime reference and a clean record of the report. HMRC matters if the scam changes pay, tax, or employee records, because the error can bleed into tax reporting.
If the fraud involved fake employee changes or identity theft, keep a note of who was told and when. That log can help with both recovery and defence.
After a fraud is discovered, the claims process usually starts with immediate notification to the insurer, followed by a formal incident report, evidence preservation and, in many cases, a forensic investigation. Insurers often want the original email chain, mailbox logs, payroll audit trails, bank records, approval screenshots, and a timeline showing exactly when the fake instruction was received and when the unauthorised payment left the account. If the incident involved employee wages, HMRC submissions or a data breach, the insurer may also ask for confirmation of any regulatory notifications and recovery steps taken with the bank.
Missing logs or a delayed notice can reduce both the chance of recovery and the scope of cover.
Payroll fraud claims need the right policy fit
The right policy fit starts with matching your process to the cover wording. If your team approves changes by email, you need to know whether the policy covers email, social engineering, or only system intrusion.
A good check is to compare cyber cover, crime cover, and any crime sub-limit for funds transfer. If the wording mentions verified instructions, call-back steps, or dual authorisation, those are not suggestions. They are the fence around the claim.
For many UK SMEs, the best next step is a broker review of the wording before renewal, not after the loss. Ask for the exact clauses on social engineering, third-party processor use, and notification deadlines, then test them against your real payroll flow.
This does not work well as the main solution if the issue was only an admin mistake, if the policy excludes social engineering or authorised transfer fraud, or if payroll is still handled offline with no sensitive data shared digitally.
If your policy wording is unclear, ask for the social engineering and funds transfer sections in writing before you renew. A short wording review can prevent a long claim dispute.
Cyber insurance for accountants processing payroll for multiple clients
For firms managing payroll across a portfolio of clients, a single incident can create liability well beyond the cost of restoring internal systems. Cyber insurance for accountants processing payroll should reflect the volume of employee data handled, the number of client contracts affected and the firm’s responsibility for meeting time-sensitive pay runs.
Client-data liability and third-party costs
A breach involving payroll records may expose names, addresses, National Insurance numbers, bank details and salary information belonging to several clients’ employees. Appropriate cover can help with forensic investigation, legal advice, data-subject notifications, credit monitoring where required and third-party claims alleging financial loss or failure to protect confidential information.
Firms should check whether the policy limits apply per incident or in aggregate, particularly where one compromised platform affects multiple client databases.
Where cyber cover and professional indemnity overlap
Professional indemnity insurance may respond when a client alleges that negligent payroll services caused them financial loss, such as an incorrect payment or missed filing. However, it may not cover the technical response to a ransomware attack, data restoration, regulatory investigation or breach-notification costs.
Cyber insurance for accountants processing payroll can complement PI cover by addressing the incident itself, while PI may be relevant if clients pursue claims over professional advice or service failures. Policy wording should be reviewed to avoid gaps or assumptions about which insurer will respond.
Contractual notification duties after a breach
Payroll service agreements often require accountants to notify clients quickly following a suspected data incident. Some contracts also specify notification timescales, cooperation obligations and responsibility for communications with affected employees.
Keep an up-to-date incident response plan, identify who can notify clients and insurers, and avoid admitting liability before taking legal advice. Prompt notification to the cyber insurer is equally important, as delayed reporting can affect access to breach-response support or cover.
Cyber insurance for recruitment & payroll processing: recruitment agency risks
Recruitment agencies face a distinct cyber risk profile because they manage high volumes of candidate data, client records and temporary-worker payments. Cyber insurance for recruitment & payroll processing should reflect this combination of personal data exposure, system dependency and financial crime risk.
Candidate-data breaches and ATS/CRM compromise
Applicant tracking systems (ATS), CRM platforms and CV databases can hold names, addresses, National Insurance numbers, bank details, right-to-work documents and employment histories. A phishing attack, stolen login or misconfigured cloud folder could expose thousands of candidate records at once.
Cover can help with breach investigation, legal advice, notification costs, credit monitoring where appropriate and regulatory response following an ICO investigation.
Temporary-worker payroll fraud
Recruitment businesses are frequent targets for mandate fraud and business email compromise. Criminals may impersonate a temporary worker to request changed bank details, intercept supplier invoices or pose as a consultant with authority to approve payments.
A suitable policy can support losses arising from social engineering and funds-transfer fraud, subject to the policy terms, alongside forensic work to identify how the fraud occurred.
Agencies often rely on payroll bureaus, umbrella companies, background-check providers, job boards and cloud-based recruitment software. An outage or cyber incident at one of these suppliers can prevent placements, timesheet approvals and payroll runs.
Cyber insurance for recruitment & payroll processing can include business interruption and dependent supplier cover, helping protect income and fund recovery when a critical third party is unable to operate.
Common questions
What is payroll fraud?
Payroll fraud is when someone changes a pay process to divert wages, fake a payment, or steal payroll data. It often involves bank detail changes, employee impersonation, or a fake instruction sent by email or phone.
How does outsourced payroll fraud happen?
Outsourced payroll fraud usually happens when the attacker tricks either your staff or the processor into changing payment details. The weak point is often a shared email inbox or a rushed approval process.
How can cyber insurance help with payroll fraud?
Cyber insurance can help by paying for incident response, forensic work, and some direct losses if the policy wording fits the fraud route. The claim is stronger when you can show phishing, account takeover, or a confirmed fraudulent instruction.
Does cyber insurance cover payroll fraud?
Sometimes, yes, but not by default. Cover often depends on whether the policy includes social engineering or funds transfer fraud, and whether your team followed the required verification steps.
What should I do if my payroll processor is
Pause the next payment run, save every log and email, tell the insurer quickly, and contact the bank at once. If employee data may have been exposed, check whether UK GDPR reporting to the ICO is needed.
Should I tell employees straight away?
Tell affected employees as soon as you know their pay, bank details, or personal data may be at risk. A clear note reduces panic and helps prevent a second scam using the same information.
Can HMRC be affected by payroll fraud?
Yes, if the fraud changes PAYE data, salary records, or submission details. HMRC issues can sit alongside the insurance claim, so keep the tax trail separate and documented.