If you sell on Amazon or eBay, cyber insurance can be worth having, but it is not the same as product liability or public liability cover. It can help after hacked logins, phishing, data breaches and some fraud, but only if the wording fits how you sell.
Amazon vs eBay: who actually needs cover?
If you sell through Amazon or eBay, you already carry cyber risk. A hacked account can lock you out, change payout details, trigger refunds, or expose customer data.
That risk exists even when the sale happened on a marketplace. The platform is a sales channel, not your insurer.
Peter White has seen sellers lose access after one reused password was caught in a phishing attack. The result was lost sales, chargeback costs, and urgent IT clean-up.
The most common mistake is thinking the platform will sort it out. It will not pay your policy excess, forensic bill, or legal advice.
Amazon and eBay can suspend an account, hold funds, or close a listing. They are not there to reimburse every loss after a cyber incident.
That matters most when a thief gets into your seller account and changes payout details. If £4,000 of stock is sold under your name, you may need your own insurer.
Seller accounts store more than people realise. They hold names, addresses, order histories, refund details, email threads, and payout links.
That can create a personal data breach under the UK GDPR and the Data Protection Act 2018. The ICO expects firms to secure personal data.
A poor password or missing MFA can make a claim harder to defend. So can old software and shared logins.
If your Amazon or eBay account is your main route to market, the cyber risk is real. One account takeover can stop sales, expose customer data, and create dispute work within hours.
The three cover gaps to check
First, check whether your cyber policy covers first-party losses. These are your own costs after an incident.
That usually means forensics, recovery, legal advice, notification letters, and sometimes lost income while systems are down. Think of it like repair costs after a break-in.
Second, check whether it includes third-party liability. That is the cost if a customer or partner says your breach caused them loss.
That matters if an email compromise sends bank details to the wrong person. It also matters if personal data leaks from your seller system.
Third, check whether it excludes social engineering. That is when someone tricks you or staff into sending money or changing payout details.
Many policies limit this or cap it at a low sublimit. A range of £25,000 to £100,000 is common.
What cyber insurance actually pays for
Cyber insurance usually pays for the costs that follow a covered digital incident. It does not pay for every online problem.
For a marketplace seller, that can include incident response, forensic work, legal advice, customer notification, data restoration, and some business interruption.
The Association of British Insurers and the British Insurance Brokers' Association both treat cyber cover as a mix of first-party and third-party protection. That is why wording matters so much.
One seller may need basic breach support only. Another may need wider cover because they store more customer data or process more orders.
First-party losses in plain english
First-party losses are the costs you pay yourself after the event. Think of them as your own repair bill.
For an Amazon or eBay seller, that can include digital forensics, restoring files, hiring an incident-response firm, and paying a lawyer.
It can also include telling affected customers if personal data was exposed. If the policy has business interruption cover, it may pay for lost gross profit.
That cover often lasts 7 to 30 days. Sometimes it runs longer, depending on the wording.
Third-party liability after a breach
Third-party liability is what you rely on when someone else says your incident harmed them. That can happen after a seller account breach.
A seller can face this if customer details are leaked. It can also happen if a phishing email appears to come from the seller’s account.
The claim may include legal defence costs, compensation, and regulatory work. But not every policy covers fines.
Under UK law, most fines under the UK GDPR and the Data Protection Act 2018 are treated carefully. Coverage depends on the wording and what is legally insurable.
| Incident |
What may respond |
Common limit or condition |
| Account takeover |
Forensics, recovery, legal help |
MFA may be required |
| Data breach |
Notification, advice, defence costs |
Fines are wording based |
| Social engineering |
Funds transfer loss |
Often sublimited |
| Business interruption |
Lost gross profit |
Waiting period applies |
A useful way to test a policy is to ask what happens in five real marketplace scenarios. If an attacker steals your marketplace login and changes the payout bank details, a good policy may cover incident response and forensics.
If a phishing attack leads to an account takeover, cover may depend on whether two-factor authentication was turned on. It may also depend on whether the insurer sees the loss as avoidable.
If a data breach exposes customer names and addresses, the policy may help with notification and legal defence. It will not usually pay for reputation damage alone.
If payment fraud triggers chargeback costs, some policies respond only where card data or a payment system was compromised. If your sales stop during business interruption, cover depends on the wording and waiting period.
My view is simple: buy cyber insurance for the digital mess after a breach, not for the products you sell. Then pair it with product liability and public liability, or a single online retail policy that clearly includes both.
Amazon, eBay and cover: a practical comparison
Amazon and eBay create different seller risks, but neither platform replaces your own insurance. Amazon often places more weight on account control and documentary proof.
EBay sellers often face more direct consumer disputes and account misuse. That can make message fraud and refund abuse more common.
A good seller policy does not promise to cover every online problem. It shows which event starts cyber cover, which starts liability cover, and which is a trading risk you carry yourself.
Comparison table: obligations and responses
Amazon does not usually give you a blanket cyber policy for your seller account. It can ask for evidence of cover in some cases.
That difference matters when a scammer gets in and changes bank details. If you do not have MFA, the same event can leave you with the loss and no payout.
According to UK Finance, fraud losses remain a live issue for small firms. Action Fraud still sees phishing as a common entry point.
That is why account security and policy wording have to be checked together. They should not be checked separately.
If the event is a hacked seller account, cyber cover is the first policy to read. If the event is a faulty charger that hurts a customer, cyber does nothing.
If the event is a four-hour platform outage that stops orders, cyber business interruption may help. But only if the wording covers that outage.
If the event is a customer complaint about late delivery after a suspension, that may be a commercial loss. It may not be an insured cyber event.
What Amazon and eBay do not cover
Marketplace rules can help with listing control and dispute handling. They do not replace insurance for your own losses.
A seller can still face legal costs, recovery work, and claim handling after a breach. The platform may be part of the problem, but it is not your insurer.
The key is to know where the line sits. That line changes the day you need it.
The claims most sellers get wrong
The biggest claims surprises come from account compromise and social engineering. A fraudster can trick you into changing payout details or paying a false invoice.
That loss may be treated very differently from a direct hack. The policy wording decides which one counts.
Peter White has seen a seller lose nearly a week of trading after a phishing email grabbed the marketplace login. The claim then turned on one missing control, MFA.
The lesson was blunt. The policy was not the problem, the setup was.
Account takeover after weak MFA
MFA means multi-factor authentication. It is a second check, like a code on your phone.
It is one of the simplest ways to stop a stolen password being enough. If your policy requires MFA, you need it turned on.
If you had not turned it on, the insurer may reduce the claim or refuse it. That is the sort of exclusion that turns stress into a bigger bill.
Phishing, fake invoices and transfers
Phishing is when someone sends a fake email, message, or login page to trick you. In marketplace selling, that often looks like a fake Amazon warning.
It can also look like a false courier bill or a message that seems to come from a buyer. These losses are often covered only if the policy includes social engineering.
A policy might pay £50,000 for cyber extortion but only £10,000 for social engineering. That can be far too small for a busy seller.
A practical claims example makes the gap clear. An eBay seller clicks a fake courier email and enters credentials on a spoofed page.
The attacker changes the payout account, sends suspicious messages to buyers, and downloads order data. In that case, cyber insurance may pay for containment and forensics.
It may also pay for legal advice and customer notifications. That depends on whether the event is treated as a covered phishing attack or account takeover.
If the seller then suffers a two-day stoppage while Amazon or eBay reviews the account, the claim for business interruption may depend on the waiting period. It also depends on the wording.
If fraudulent orders later create chargeback costs, that may be covered only under a payment-fraud extension. It is not always part of standard cyber cover.
The most common mistake is treating every online loss as cyber cover. Some losses sit under social engineering, some under liability, and some are not insured at all.
How to choose the right cover
The right cover starts with how you sell, not the logo on the marketplace page. If you handle customer data, store logins in shared tools, or rely on fast cashflow, cyber cover matters more.
If you import goods, brand products, or resell items from third parties, you likely need more than cyber. Product liability and public liability should sit beside it.
Ask whether the policy covers your exact marketplace accounts, not just "online business" in general. Ask whether MFA is a condition.
Ask what the excess is. Many cyber policies for smaller firms sit between £250 and £1,000.
That lower premium can hide a higher out-of-pocket cost after a claim. Also ask whether legal costs come from the main limit.
Ask about exclusions for old software, remote access, and unmanaged devices. Those are common weak spots for sellers working from home.
For most UK Amazon and eBay sellers, the better mix is cyber insurance plus product liability and public liability. That combination catches digital loss, physical claims, and ordinary trading risk.
If you store card data or build your own checkout outside the marketplace, check whether PCI DSS rules apply. If you only use the marketplace payment flow, your exposure is lower, but not zero.
For Amazon and eBay sellers, it helps to separate cover into what is essential and what is optional. A core cyber policy should usually include first-party breach response, customer data protection, forensic work, legal advice, notification costs, and some business interruption.
Optional extras may include social engineering fraud, cyber extortion, reputational support, PCI-related costs, and wider liability extensions. Amazon sellers often need tighter seller account security controls because a compromised account can change listings, prices, and payout instructions.
EBay sellers may face more message-based fraud and buyer dispute activity. In both cases, account takeover is a real risk.
You should only expect cover if MFA is enabled and the policy wording does not exclude credential theft. It should also not exclude unexplained payment diversion or misuse by a third party.
| Policy type |
What it mainly covers |
What it does not cover |
| Cyber insurance |
Hackers, breach response, fraud costs |
Product injury or faulty goods |
| Product liability |
Injury or damage from goods sold |
Hacked accounts and data breaches |
| Public liability |
Third-party injury or property damage |
Cyber attacks and stolen logins |
What people ask
Does Amazon have insurance for sellers?
No, Amazon does not give you a general cyber policy for your seller account. You still need your own cover for hacked logins, data breaches, and fraud.
Do i need public liability insurance to sell on amazon?
Yes, if there is any chance a customer, visitor, or courier could be injured or suffer property damage linked to your trading. Cyber cover does not pay for a broken item that causes injury.
Do you need insurance to sell items online?
Not always by law, but it is wise once you store customer data, take card payments, or depend on a marketplace account. For many small sellers, cyber plus product liability is the minimum to check.
Do i need liability insurance to sell on amazon?
Usually yes, because product liability deals with the goods themselves, while cyber deals with digital incidents. Amazon can also ask for evidence of cover in some situations.
The safest policy mix for sellers
The safest policy mix for a UK marketplace seller is usually cyber insurance, product liability, and public liability. Set the limits by turnover and the type of goods you sell.
If you use MFA, separate logins, and clean payment controls, your cyber claim position is usually better. Shared accounts and reused passwords make life harder.
The part many sellers miss is that one policy rarely fixes the whole problem. A hacked account, a fraud transfer, and a customer injury can all come from the same trading day.
Each one may sit under a different policy or an exclusion. That is why the wording matters as much as the price.
My view, based on years of reviewing claims and policy wording, is simple: buy cyber cover for the digital risk, not the goods.
Then pair it with product liability and public liability. If a policy says it covers online selling, read the exclusions before you trust it.