If you have previously unsubscribed from Huntington marketing emails, subscribing reaffirms your agreement to receive email. This will not impact servicing email related to account activity. For questions, please consult Huntington’s Privacy and Security policy.

Account takeover and impersonation are risks: Is your cyber insurance keeping up?
Ashley Bauer, P&C Insurance Product Manager, Huntington Insurance
Account takeover and impersonation attacks are exposing businesses to growing financial risk. As these threats evolve, businesses should understand how cyber liability insurance may respond, where coverage gaps can exist and what insurers increasingly expect from policyholders.
Key takeaways
Financial impact
Coverage considerations
Stronger controls
How are account takeover (ATO) and impersonation attacks changing the way businesses think about risk?
In 2025, Americans lost more than $20 billion to cybercrime, with the majority of losses tied to fraud and social engineering tactics such as impersonation and business email compromise1. Huntington’s latest report on emerging cyber and fraud trends highlights how these threats continue to evolve. For many business leaders, the concern is no longer whether these attacks will occur. It’s how quickly they can create financial and operational consequences.
An employee receives what appears to be a legitimate request from an executive. A trusted vendor’s account is compromised, or credentials fall into the wrong hands. Within minutes, funds can be transferred, systems can be accessed and sensitive information can be exposed.
As these attacks become more sophisticated, businesses are taking a closer look at their financial preparedness, including whether their cyber liability insurance coverage aligns with the way today’s losses occur.
Why account takeover fraud and impersonation attacks matter
Whether the attack involves stolen credentials or an impersonated executive, the consequences can be similar: financial loss, operational disruption and difficult questions about recovery.
In an ATO attack, cybercriminals gain access to a legitimate business account using stolen credentials. Once inside, they may redirect payments, access sensitive information or move through connected systems undetected. Impersonation attacks work differently. Threat actors pose as executives, employees, vendors or trusted partners to influence decisions, request payments or obtain confidential information.
Artificial intelligence (AI) is making both tactics more effective. Attackers can generate highly personalized emails, clone voices and create increasingly convincing communications that are harder to identify as fraudulent. These evolving tactics are contributing to the rise in brand impersonation and ATO attacks facing businesses today.
For businesses, the impact often extends beyond the immediate loss. Legal expenses, incident response costs, operational disruption and reputational concerns can all become part of the recovery process and affect broader business continuity planning efforts. In some situations, the financial consequences may continue long after the incident itself has been resolved.
Why cyber liability insurance coverage may not be as straightforward as expected
Cyber liability insurance policy language is not standardized. How a policy is used for an incident depends on the specific facts of the event, the policy language and any applicable terms, conditions or exclusions.
This can be particularly important with ATO and impersonation incidents, which often involve elements of fraud, social engineering and cybersecurity risk. While coverage for these exposures is widely available, coverage terms, limits and underwriting requirements can vary among carriers.
Businesses should understand several factors that can influence coverage:
- Coverage terms and conditions vary: How a policy addresses ATOs, impersonations, and related exposures depends on the policy language and carrier. Understanding these differences can help organizations make more informed decisions when evaluating coverage.
- Social engineering sublimits: Some policies provide coverage for social engineering and impersonation-related losses, but those coverages may carry lower limits than other cyber-related claims.
Understanding these distinctions can help organizations make more informed decisions when evaluating cyber liability insurance.
How insurers are responding to account takeover attacks
As ATO and impersonation incidents become more common, insurers are adapting how they evaluate cyber risk. For businesses, cyber liability insurance is no longer simply about purchasing a policy. Insurers increasingly want to see strong internal controls, documented security practices and clear procedures for verifying transactions before extending coverage.
Organizations may encounter requirements such as:
- Multi-factor authentication (MFA)
- Endpoint detection and protection tools
- Formal incident response plans
- Dual approvals for financial transactions
- Independent verification procedures for payment changes
At the same time, insurers are adjusting policies to address emerging risks such as social engineering fraud and impersonation-related losses. These coverages are available in the market, although they often include specific limits, conditions and underwriting requirements.
The broader trend is clear: cyber liability insurance is becoming more closely tied to an organization’s ability to demonstrate effective cybersecurity and risk management practices.
What businesses should do now
As impersonation and ATO risks continue to evolve, businesses should review both their cybersecurity controls and their insurance strategy.
Consider taking the following actions:
- Review policy language to understand how fraud, cyber events and social engineering incidents are defined.
- Evaluate whether ATO, vendor fraud and executive impersonation scenarios are addressed by existing coverage.
- Confirm the limits that apply to social engineering and fraud-related losses.
- Implement MFA, dual approvals and verification procedures for high-risk transactions.
- Train employees to recognize suspicious requests involving payments, credentials or account changes.
- Access third-party relationships and access permissions that may introduce additional risk.
- Review coverage regularly with an insurance advisor as threats and policy terms evolve.
Taking these steps can help businesses better understand their exposure, strengthen their controls and identify potential coverage gaps before an incident occurs.
Reassessing cyber liability coverage in a changing threat environment
ATO and impersonation attacks highlight how cyber risk continues to evolve. Increasingly, these incidents exploit trust, business processes and human behavior rather than technical vulnerabilities alone.
As businesses strengthen their cybersecurity programs, they should also consider whether their insurance coverage reflects how financial losses occur today. Coverage designed around more traditional cyber events may warrant review as attack methods continue to evolve. Businesses that regularly evaluate both their controls and their coverage are often better positioned to respond to incidents, recover from losses and navigate an increasingly complex risk landscape.
Helping organizations evaluate cyber risk
Cyber liability insurance is one component of a broader cyber risk management strategy. As ATO, impersonation and social engineering threats continue to evolve, businesses should evaluate whether their coverage, controls and response plans remain aligned.
Huntington Insurance works with organizations to assess cyber exposure, understand evolving coverage considerations and identify strategies that support broader risk management goals.
Ready to review your cyber liability coverage? Contact Huntington Insurance to explore solutions that can help your business address today’s cyber and fraud risks. Click here to get started.
Subscribe
Huntington Business Insights
Financial news, insights, and guidance delivered right to your inbox.
Sign up to receive emails about our latest articles, case studies, and events on topics that matter to your business.
Featured insights with industry expertise
Tap into insights designed to help you navigate today’s decisions and tomorrow’s opportunities.


Business Cyber Resilience
Midyear cybersecurity and fraud threat report


Business Cyber Resilience
Understanding business email compromise (BEC): A guide to help protect your organization


Business Cyber Resilience
How to build a business resiliency plan for your company
1 Internet Crime Compliant Center. April 2026. “Federal Bureau of Investigation Internet Crime Report 2025.” Accessed July 15, 2026.
The information provided in this document is intended solely for general informational purposes and is provided with the understanding that neither Huntington, its affiliates nor any other party is engaging in rendering financial, legal, technical or other professional advice or services, or endorsing any third-party product or service. Any use of this information should be done only in consultation with a qualified and licensed professional who can take into account all relevant factors and desired outcomes in the context of the facts surrounding your particular circumstances. The information in this document was developed with reasonable care and attention. However, it is possible that some of the information is incomplete, incorrect, or inapplicable to particular circumstances or conditions. NEITHER HUNTINGTON NOR ITS AFFILIATES SHALL HAVE LIABILITY FOR ANY DAMAGES, LOSSES, COSTS OR EXPENSES (DIRECT, CONSEQUENTIAL, SPECIAL, INDIRECT OR OTHERWISE) RESULTING FROM USING, RELYING ON OR ACTING UPON INFORMATION IN THIS DOCUMENT EVEN IF HUNTINGTON AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF OR FORESEEN THE POSSIBILITY OF SUCH DAMAGES, LOSSES, COSTS OR EXPENSES.
Third-party product, service and business names are trademarks/service marks of their respective owners.