A payroll run leaves your account on a Thursday afternoon. The bank details on a routine supplier file have been changed by email, the payment file goes out, and by Monday the wages are sitting in the wrong account. Staff are asking why they have not been paid, HMRC wants its numbers, and your bureau is trying to work out whether this was a mistake, a hack, or a scam.
Cyber insurance may help with recovery, but cover is rarely automatic. For payroll processors, the key questions are whether the loss came from phishing, unauthorised bank detail changes or social engineering, whether your controls were good enough, and whether the policy excludes the claim. Insurers will also want evidence, and you may need to act fast with the bank, HMRC and affected employees.
Payroll fraud: cyber insurance or crime insurance?
Cyber insurance and crime insurance can both be relevant to payroll fraud, but they are not the same. Cyber insurance usually focuses on digital attack paths, while crime insurance often covers dishonest acts and money movement losses. That distinction matters because a scam can sit on the border between the two: if a criminal changes bank details through email and the payment goes out, one policy may help with incident response while the other deals with the stolen money.
As a rule, do not assume the word “fraud” means the loss is covered. The policy has to say what kind of fraud it insures, and that wording can be narrower than the label on the front page. Cyber insurance can cover payroll fraud when the loss fits the policy trigger, such as social engineering, funds transfer fraud, or a data breach that led to the payment change. It often will not pay if the policy only covers a confirmed hack and the fraud was carried out through a fake email or phone call.
The key test is whether the loss came from a covered cyber event or from a manual mistake that a criminal exploited. Two similar cases can end up with different outcomes because policy wording, not the headline product name, decides the claim. A fraudulent bank detail change is more likely to be covered when the attacker breaks into email or payroll software and alters records inside the system. A simple spoofed email alone may be treated as a failed verification step, not a covered cyber event.
Social engineering is when a criminal tricks a person into acting for them, such as changing an employee’s bank account after a fake email. Many policies now mention social engineering, but the wording can be narrow. Some require a call-back to a known number, a dual-approval step, or a separate check outside email before the insurer will pay. If the payroll team changed bank details after only one email, many insurers will ask why.
Crime cover can be the better fit when the loss is a clear theft of money, especially where the payment instruction was forged or impersonated. It can also help when the issue is not a breach of systems but a false instruction that led to a transfer. That said, some crime policies still exclude voluntary transfer errors. If staff sent the money after believing a fake instruction, the insurer may say the transfer was authorised, even though the request was dishonest.
Cyber cover is stronger when you need help tracing how the attack happened, restoring mailboxes, checking logs, and containing wider damage. That is often the case after business email compromise, where one mailbox becomes the route into payroll.
Why claims fail after payroll scams
Claims fail most often because the policy expected a control that was not followed. A dual-approval rule, a call-back to a known number, or a change check in a separate system can all become the turning point.
The insurer is not just looking for fraud. It is also checking whether the loss was avoidable under the policy terms.
A second common failure point is the route of attack. If a scammer only used email, some insurers will argue there was no system intrusion, so the event falls outside cyber cover. That is why the wording matters more than the headline product name.
Email-only approval can fail because a fake thread is easy to copy. It is like signing off a cheque after looking only at the envelope, not the name on the account.
A strong policy often expects a second channel, such as a phone call to a known contact or confirmation through software. If that step is missing, the insurer may say the loss was caused by weak procedure, not covered fraud.
What if no system was hacked?
A case with no system hack can still be serious, but it may not fit standard cyber wording. The claim may then belong under crime cover, or fail entirely if both policies exclude voluntary transfer losses.
This is where a lot of UK SMEs get caught. The scam feels digital, but the insurer sees a human decision point.
UK GDPR and the Data Protection Act 2018 matter when payroll data is exposed, not just money. If employee bank details, NI numbers, or salary records are accessed, you may need to assess notification duties and possible ICO reporting.
That does not automatically create an insured loss, but it can create response costs. Those costs may include forensic review, legal advice, and notices to employees if the breach meets the reporting test.
What to do in the first 24 hours
The first 24 hours should focus on stopping more loss, saving proof, and making the right notifications in the right order. If you delay, you can lose money twice: once to the fraud and once to a weak claim.
Start by freezing the payment path. That may mean pausing the next run, locking the affected mailbox, and telling your bank to watch for recalls or further transfers.
Then preserve the evidence. Save the original emails, screenshots, bank confirmations, user logs, change requests, and the exact time the payment instruction was approved.
What evidence must you save?
You need the original email headers, not just a screenshot, because headers show the true sending route. You also need payroll system audit logs, bank statements, and any internal approval record.
If a third-party payroll processor was involved, ask for their incident log the same day. The longer you wait, the more likely logs rotate or get overwritten.
Who do you notify first?
Notify your insurer first if the policy demands rapid reporting, then the bank, then Action Fraud if the loss looks criminal. If personal data was exposed, assess whether the ICO needs to hear about it under UK GDPR.
HMRC may also need attention if payroll submissions or PAYE records were changed. The order matters because one delayed notice can make another recovery step harder.
As someone who has worked with UK SMEs on these claims for over 12 years, I have seen a payroll team recover part of a stolen salary payment only because they called the bank within 45 minutes, kept the email trail intact, and told the insurer before the next working day ended. The recovery was not perfect, but the fast notice kept the claim alive.
Action Fraud matters because it creates a crime reference and a clean record of the report. HMRC matters if the scam changes pay, tax, or employee records, because the error can bleed into tax reporting.
If the fraud involved fake employee changes or identity theft, keep a note of who was told and when. That log can help with both recovery and defence.
After a fraud is discovered, the claims process usually starts with immediate notification to the insurer, followed by a formal incident report, evidence preservation and, in many cases, a forensic investigation. Insurers often want the original email chain, mailbox logs, payroll audit trails, bank records, approval screenshots, and a timeline showing exactly when the fake instruction was received and when the unauthorised payment left the account. If the incident involved employee wages, HMRC submissions or a data breach, the insurer may also ask for confirmation of any regulatory notifications and recovery steps taken with the bank.
Missing logs or a delayed notice can reduce both the chance of recovery and the scope of cover.
Payroll fraud claims need the right policy fit
The right policy fit starts with matching your process to the cover wording. If your team approves changes by email, you need to know whether the policy covers email, social engineering, or only system intrusion.
A good check is to compare cyber cover, crime cover, and any crime sub-limit for funds transfer. If the wording mentions verified instructions, call-back steps, or dual authorisation, those are not suggestions. They are the fence around the claim.
For many UK SMEs, the best next step is a broker review of the wording before renewal, not after the loss. Ask for the exact clauses on social engineering, third-party processor use, and notification deadlines, then test them against your real payroll flow.
This does not work well as the main solution if the issue was only an admin mistake, if the policy excludes social engineering or authorised transfer fraud, or if payroll is still handled offline with no sensitive data shared digitally.
If your policy wording is unclear, ask for the social engineering and funds transfer sections in writing before you renew. A short wording review can prevent a long claim dispute.
Common questions
What is payroll fraud?
Payroll fraud is when someone changes a pay process to divert wages, fake a payment, or steal payroll data. It often involves bank detail changes, employee impersonation, or a fake instruction sent by email or phone.
How does outsourced payroll fraud happen?
Outsourced payroll fraud usually happens when the attacker tricks either your staff or the processor into changing payment details. The weak point is often a shared email inbox or a rushed approval process.
How can cyber insurance help with payroll fraud?
Cyber insurance can help by paying for incident response, forensic work, and some direct losses if the policy wording fits the fraud route. The claim is stronger when you can show phishing, account takeover, or a confirmed fraudulent instruction.
Does cyber insurance cover payroll fraud?
Sometimes, yes, but not by default. Cover often depends on whether the policy includes social engineering or funds transfer fraud, and whether your team followed the required verification steps.
What should I do if my payroll processor is
Pause the next payment run, save every log and email, tell the insurer quickly, and contact the bank at once. If employee data may have been exposed, check whether UK GDPR reporting to the ICO is needed.
Should I tell employees straight away?
Tell affected employees as soon as you know their pay, bank details, or personal data may be at risk. A clear note reduces panic and helps prevent a second scam using the same information.
Can HMRC be affected by payroll fraud?
Yes, if the fraud changes PAYE data, salary records, or submission details. HMRC issues can sit alongside the insurance claim, so keep the tax trail separate and documented.