Key takeaways

Financial impact

Account takeover and impersonation attacks can lead to unauthorized transactions, operational disruption and reputational damage.

Coverage considerations

Cyber, fraud and social engineering losses do not always fit neatly into traditional coverage definitions.

Stronger controls

Insurers increasingly expect businesses to implement robust controls and verification procedures to help reduce risk.

How are account takeover (ATO) and impersonation attacks changing the way businesses think about risk?

In 2025, Americans lost more than $20 billion to cybercrime, with the majority of losses tied to fraud and social engineering tactics such as impersonation and business email compromise1. Huntington’s latest report on emerging cyber and fraud trends highlights how these threats continue to evolve. For many business leaders, the concern is no longer whether these attacks will occur. It’s how quickly they can create financial and operational consequences.

An employee receives what appears to be a legitimate request from an executive. A trusted vendor’s account is compromised, or credentials fall into the wrong hands. Within minutes, funds can be transferred, systems can be accessed and sensitive information can be exposed.

As these attacks become more sophisticated, businesses are taking a closer look at their financial preparedness, including whether their cyber liability insurance coverage aligns with the way today’s losses occur.

Why account takeover fraud and impersonation attacks matter

Whether the attack involves stolen credentials or an impersonated executive, the consequences can be similar: financial loss, operational disruption and difficult questions about recovery.

In an ATO attack, cybercriminals gain access to a legitimate business account using stolen credentials. Once inside, they may redirect payments, access sensitive information or move through connected systems undetected. Impersonation attacks work differently. Threat actors pose as executives, employees, vendors or trusted partners to influence decisions, request payments or obtain confidential information.

Artificial intelligence (AI) is making both tactics more effective. Attackers can generate highly personalized emails, clone voices and create increasingly convincing communications that are harder to identify as fraudulent. These evolving tactics are contributing to the rise in brand impersonation and ATO attacks facing businesses today.

For businesses, the impact often extends beyond the immediate loss. Legal expenses, incident response costs, operational disruption and reputational concerns can all become part of the recovery process and affect broader business continuity planning efforts. In some situations, the financial consequences may continue long after the incident itself has been resolved.

Why cyber liability insurance coverage may not be as straightforward as expected

Cyber liability insurance policy language is not standardized. How a policy is used for an incident depends on the specific facts of the event, the policy language and any applicable terms, conditions or exclusions.

This can be particularly important with ATO and impersonation incidents, which often involve elements of fraud, social engineering and cybersecurity risk. While coverage for these exposures is widely available, coverage terms, limits and underwriting requirements can vary among carriers.

Businesses should understand several factors that can influence coverage:

  • Coverage terms and conditions vary: How a policy addresses ATOs, impersonations, and related exposures depends on the policy language and carrier. Understanding these differences can help organizations make more informed decisions when evaluating coverage.
  • Social engineering sublimits: Some policies provide coverage for social engineering and impersonation-related losses, but those coverages may carry lower limits than other cyber-related claims.

Understanding these distinctions can help organizations make more informed decisions when evaluating cyber liability insurance.

How insurers are responding to account takeover attacks

As ATO and impersonation incidents become more common, insurers are adapting how they evaluate cyber risk. For businesses, cyber liability insurance is no longer simply about purchasing a policy. Insurers increasingly want to see strong internal controls, documented security practices and clear procedures for verifying transactions before extending coverage.

Organizations may encounter requirements such as:

  • Multi-factor authentication (MFA)
  • Endpoint detection and protection tools
  • Formal incident response plans
  • Dual approvals for financial transactions
  • Independent verification procedures for payment changes

At the same time, insurers are adjusting policies to address emerging risks such as social engineering fraud and impersonation-related losses. These coverages are available in the market, although they often include specific limits, conditions and underwriting requirements.

The broader trend is clear: cyber liability insurance is becoming more closely tied to an organization’s ability to demonstrate effective cybersecurity and risk management practices.

What businesses should do now

As impersonation and ATO risks continue to evolve, businesses should review both their cybersecurity controls and their insurance strategy.

Consider taking the following actions:

  • Review policy language to understand how fraud, cyber events and social engineering incidents are defined.
  • Evaluate whether ATO, vendor fraud and executive impersonation scenarios are addressed by existing coverage.
  • Confirm the limits that apply to social engineering and fraud-related losses.
  • Implement MFA, dual approvals and verification procedures for high-risk transactions.
  • Train employees to recognize suspicious requests involving payments, credentials or account changes.
  • Access third-party relationships and access permissions that may introduce additional risk.
  • Review coverage regularly with an insurance advisor as threats and policy terms evolve.

Taking these steps can help businesses better understand their exposure, strengthen their controls and identify potential coverage gaps before an incident occurs.

Reassessing cyber liability coverage in a changing threat environment

ATO and impersonation attacks highlight how cyber risk continues to evolve. Increasingly, these incidents exploit trust, business processes and human behavior rather than technical vulnerabilities alone.

As businesses strengthen their cybersecurity programs, they should also consider whether their insurance coverage reflects how financial losses occur today. Coverage designed around more traditional cyber events may warrant review as attack methods continue to evolve. Businesses that regularly evaluate both their controls and their coverage are often better positioned to respond to incidents, recover from losses and navigate an increasingly complex risk landscape.

Helping organizations evaluate cyber risk

Cyber liability insurance is one component of a broader cyber risk management strategy. As ATO, impersonation and social engineering threats continue to evolve, businesses should evaluate whether their coverage, controls and response plans remain aligned.

Huntington Insurance works with organizations to assess cyber exposure, understand evolving coverage considerations and identify strategies that support broader risk management goals.

Ready to review your cyber liability coverage? Contact Huntington Insurance to explore solutions that can help your business address today’s cyber and fraud risks. Click here to get started.

Featured insights with industry expertise

Tap into insights designed to help you navigate today’s decisions and tomorrow’s opportunities.

Business Cyber Resilience

Midyear cybersecurity and fraud threat report

This year’s report highlights top trends threatening organizations and covers six key prevention strategies to help reduce risk.

Business Cyber Resilience

Understanding business email compromise (BEC): A guide to help protect your organization

Business Email Compromise (BEC) scams can be surprisingly convincing. A quick pause to verify unexpected requests can make a difference in preventing fraud.

Business Cyber Resilience

How to build a business resiliency plan for your company

A practical resiliency plan can help your organization protect its people, prioritize essential operations, and make informed decisions when normal processes are interrupted.

The information provided in this document is intended solely for general informational purposes and is provided with the understanding that neither Huntington, its affiliates nor any other party is engaging in rendering financial, legal, technical or other professional advice or services, or endorsing any third-party product or service. Any use of this information should be done only in consultation with a qualified and licensed professional who can take into account all relevant factors and desired outcomes in the context of the facts surrounding your particular circumstances. The information in this document was developed with reasonable care and attention. However, it is possible that some of the information is incomplete, incorrect, or inapplicable to particular circumstances or conditions. NEITHER HUNTINGTON NOR ITS AFFILIATES SHALL HAVE LIABILITY FOR ANY DAMAGES, LOSSES, COSTS OR EXPENSES (DIRECT, CONSEQUENTIAL, SPECIAL, INDIRECT OR OTHERWISE) RESULTING FROM USING, RELYING ON OR ACTING UPON INFORMATION IN THIS DOCUMENT EVEN IF HUNTINGTON AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF OR FORESEEN THE POSSIBILITY OF SUCH DAMAGES, LOSSES, COSTS OR EXPENSES.

Third-party product, service and business names are trademarks/service marks of their respective owners.