81% of finance leaders saw AI fraud attempts in the past year. Your cyber month plan, mapped to your policies. And Revolut trusted a hacked inbox.


LION Specialty

Skim time: 5 minutes · Listening time: 6 minutes. Prefer to listen? Flip reads this week’s Brief here.


When most people hear fraud, social engineering or AI risk, they go straight to cybersecurity. That’s a big piece of it. For our clients, though, it starts with governance: how management runs the company, and the directors and officers (D&O) liability policy that sits behind the board. It’s cyber too. And the moment assets are stolen, your crime policy is in play.

So while October is Cybersecurity Awareness Month, I’d call it Cyber Crime Awareness Month. Three stories from this month show why:

  • The numbers. 81% of corporate finance leaders saw AI-driven fraud attempts in the past year, and only half were confident they’d catch one in time.
  • The calendar. One training firm’s four-week program for the month, mapped to the policies you already buy.
  • The inbox. Revolut staff sent data on about 680 customers to a hacked Italian police email account.

In each, someone inside the company did what they believed they’d been asked to do.


How to read the new deepfake numbers before your next wire goes out

Eight in ten corporate finance leaders say AI-driven fraud came at their company in the past year.

A deepfake is audio, video or an image made or altered by AI to show someone saying or doing something they never did. In practice that looks like a cloned voice of your CEO asking treasury for a wire, a video call where the other faces are synthetic, a job candidate who doesn’t exist, or a forged ID at account opening.

The survey comes from Early Warning, the company behind Zelle. It is owned by seven of the largest U.S. banks, and Zelle moved more than $1.2 trillion last year across about 2,500 banks and credit unions, so it sees payment fraud at a scale few others do. Its fraud unit, Certos, surveyed 230 senior finance executives in August. 81% said their company faced attempted fraud involving AI-generated content, and 84% said it is harder to detect than traditional fraud. Just half were very or extremely confident they could spot it before funds left.

The FBI’s numbers show how much goes unseen. Its 2025 Internet Crime Report tied $893 million in losses to complaints that mentioned AI, but only $30 million of $3.05 billion in business email fraud. A complaint counts as AI only when the victim says so, so a wire sent on a cloned voice’s instruction that nobody recognized stays in the untagged $3 billion.

Many companies that lose money to a deepfake may never know it was one.

(sources: Early Warning press release, October 8, 2026; Bloomberg, February 11, 2026, on Zelle volume; Payments Dive on Zelle’s network; FBI IC3 2025 Internet Crime Report, April 2026; American Banker, October 8, 2026; Pehlivanoglu et al., “Is this real? Susceptibility to deepfakes in machines and humans,” Cognitive Research: Principles and Implications, January 7, 2026)

So what?

For a regional or mutual carrier, the deepfake loss usually arrives as a wire your own treasury team sent.

This week JPMorgan Payments co-head Max Neukirchen described a Fortune 100 CFO who got a deepfake call from an AI agent posing as the chairman, asking for a wire on a “very confidential” merger. He said JPMorgan’s clients saw more fraud attempts by mid-2026 than in all of last year.

Your people can’t be the control. In a University of Florida study published in January, people spotted fake faces about half the time, no better than a coin flip. If a careful eye can’t tell, the check has to be a process that still works when the fake is perfect.

That loss lands in a narrow part of your program. When a deceived employee sends the money, the crime policy’s computer fraud and funds transfer fraud insuring agreements usually won’t pay, because an authorized employee sent it voluntarily. Social engineering cover may, sold as an add-on to a commercial crime policy, a financial institution bond or a cyber policy, and often capped at $100,000 to $250,000. Some of those add-ons make a callback before the wire a condition of payment. In September we read a Waco case where an insured wired $874,863 to a fraudster and its cyber policy paid the $250,000 sublimit.

Run three checks before your January 1 renewal:

  1. Size the sublimit to your largest wire. If one person can approve a $2 million wire, a $250,000 sublimit covers an eighth of it. Your retention comes off that too, and the rest is an uninsured loss in the quarter it happens.
  2. Check both policies. If your crime and cyber policies each carry social engineering cover, find out which one pays first, and whether you’d pay two retentions.
  3. Read the condition. If payment depends on a callback, make sure the callback happens every time and leaves a record.

Microsoft plans to add certified third-party deepfake detection and impersonator warnings to Teams in November. For our clients, that matters: Microsoft last counted more than 320 million monthly Teams users, and criminal groups have already posed as IT support on Teams calls to get inside companies. Turn the warnings on when they arrive. The controls that hold up are still the older ones: a callback to a number on file, a second approver for changes to that file, and a hold on first payments to a new account.

The month’s training calendar is built around this risk.

(sources: BleepingComputer, October 8, 2026, including its reporting on attackers posing as IT support on Teams; Microsoft 365 Roadmap items 573451 and 573157; Microsoft’s most recent reported Teams figure, 320 million monthly active users)


How to run the rest of Cybersecurity Awareness Month, mapped to your policies

Cybersecurity Awareness Month is a good excuse to go back to the fundamentals, and one training firm has made that easy this year.

Adaptive Security, a security-training vendor, published a free four-week toolkit of short videos, staff newsletters, rollout emails and posters, built around AI. AI basics opened the month. Deepfakes and impersonation started October 5, targeted AI attacks start October 12, and shadow AI and agents start October 19.

We’re highlighting it because it’s high level and easy to run, and the fundamentals are where these losses start. Plenty of companies already train their people. A yearly refresh still matters, because the attacks change faster than the training does. Any program that covers the same four themes does the job.

Each theme lands somewhere in your program, and not only on cyber.

(sources: Adaptive Security; National Cybersecurity Alliance)

The LION Lens

Week The risk Where it lands Ask at renewal
1: AI basics Stolen and reused passwords Cyber. An overstated multifactor answer on your application can cost you the claim. Is phishing-resistant multifactor on email, remote access and admin accounts?
2: Deepfakes (from Oct 5) Fake voices, videos and job applicants Crime, FI bond or cyber social engineering cover, usually a sublimit Is that limit sized to our largest wire? Does our help desk verify identity before a reset?
3: Targeted attacks (from Oct 12) AI-researched phishing that spreads in hours Cyber, and D&O if a failed response draws a regulator or a lawsuit Do we have round-the-clock detection, and backups we’ve restored this year?
4: Shadow AI (from Oct 19) Staff using unapproved AI tools that leak data Cyber privacy cover, and new AI exclusions in D&O and E&O (errors and omissions) forms Does any January 1 policy add an AI exclusion?

So what?

New York sets the bar even if you’re not based there.

Its Department of Financial Services oversees the banks and insurers licensed in the state, and its cybersecurity rule, Part 500, became the template for everyone else. When the National Association of Insurance Commissioners (NAIC) wrote its insurance data security model in 2017, it built it on New York’s rule, and its drafting note says complying with New York counts as complying with the model. Since then, 27 states and Puerto Rico have adopted that model. What New York expects tends to become what your own regulator expects.

Where the NAIC’s data security model is law

AK ME
VT NH
WA ID MT ND MN IL WI MI NY RI MA
OR NV WY SD IA IN OH PA NJ CT
CA UT CO NE MO KY WV VA MD DE
AZ NM KS AR TN NC SC DC
OK LA MS AL GA
HI TX FL PR

Adopted (27 states + PR)New York’s own rulePending (DC)

Source: NAIC Model #668 adoption map, status as of August 31, 2026

Part 500 requires “at a minimum annual, cybersecurity awareness training that includes social engineering for all personnel.” In 2024 the regulator warned about deepfakes beating biometric checks, and told companies to consider dropping verification by text, voice or video. Training leaves your crime wording as it is, but it gives you something to show an underwriter or an examiner: who was trained, on what, and when.

The fourth row is moving fastest. On October 6, CFC added cyber wording that expressly covers AI-related losses. In 2025, Berkley drafted an “absolute” AI exclusion for D&O, E&O and fiduciary cover. And about half the states have adopted the NAIC’s bulletin on insurers’ own AI, which sets what examiners expect of AI underwriting and claims decisions. Ask whether your E&O covers those decisions and the regulatory proceedings that follow.

By April 15, New York-regulated companies certify Part 500 compliance. The chief information security officer (CISO) and the most senior executive sign it, so check that your D&O covers regulatory proceedings against them. The board must also oversee the program and receive the CISO’s report each year, and minutes that show it are evidence too.

(sources: Akin Gump on the NAIC model and New York; NAIC Model #668 adoption map, as of August 31, 2026; 23 NYCRR 500.14; NYDFS industry letter on AI cybersecurity risks, October 16, 2024; Insurance Business, October 6, 2026, on CFC; Hunton Andrews Kurth via National Law Review, May 28, 2025, on Berkley)

The LION POV

Here’s how we’re advising clients: treat this month as your annual check on the fundamentals.

  • Refresh the basics. Good is the remaining three weeks run for everyone who can move money, reset a password or release data, and for the board. The tell: the same people as last year.
  • Write it down. Good is a record of who trained on what and when, kept where your renewal team can find it. The tell: an attendance sheet nobody can find in December.
  • Check what you told your underwriters. Good is every security answer on your January 1 applications compared with what’s actually switched on, before you sign. The tell: a multifactor answer nobody checked.

Want help working through those four questions against your own program? Book a confidential review.

Training covers the call that sounds wrong. The next story is about an email that looked right.


How to answer an “official” request for customer data

Revolut’s staff released customer data to a real government email address, and a criminal was reading the replies.

Revolut is one of Europe’s largest fintechs, with about 75 million customers, a UK banking licence and a valuation near $75 billion. If a regulated firm of that size can be fooled by a request that looked official, the same request can land on your desk.

For months, attackers used a compromised Italian police email account on the Interior Ministry’s own domain to request customer information. Revolut called it “a sophisticated external impersonation scam,” and its chief executive put the count at 680 customers. Revolut’s notice said the data could include passports, driving licences, addresses and transaction histories. The attackers publicly demanded $3 million, and the UK’s Financial Conduct Authority is looking into it.

Italy’s Interior Minister told lawmakers Revolut “could have and should have verified the request by doing minimal due diligence.” A real, compromised police mailbox passes every email check. It proves the account, not the person typing. Denis Calderone, chief technology officer at Suzu Labs: “You can reverse a wire transfer. You can’t unleak a passport.”

No system was breached, no money moved, and the data is still gone.

(sources: Fortune, July 3, 2026, on Revolut’s size; TechCrunch, September 12, 2026; TechTarget, September 17, 2026; SecurityWeek, September 17, 2026; MLex, September 21, 2026; Reuters via Global Banking & Finance, October 7, 2026)

So what?

Revolut has come up in my conversations with our London underwriters more than once this month. What they want to know is whether the companies we bring them have a process for checking who is asking for data, and who signs off before it goes out.

Use Revolut as a dry run. An insurtech that runs its own claims gets official requests every week: a state insurance department, law enforcement, a subpoena, a claimant’s lawyer. You probably verify a change to payment instructions. Do you verify a request for records? Put that process in front of your board or audit committee the way you would a payment control: who owns it, how a request is verified, and when it was last tested.

Three questions decide the coverage. Does your cyber policy treat a disclosure your own employee made on purpose as a privacy event? Does its extortion cover require a threat to your systems? And if claims staff sent claimant files, does your E&O respond? A social engineering add-on won’t help, because no money moved.

Before coverage comes notice. A release like this can trigger state breach-notice laws and, in New York, Part 500’s 72-hour reporting rule, so decide now who makes that call.

The fixes the experts proposed are all process:

  1. Deny by default until legal or compliance confirms the request through a publicly listed number.
  2. Two approvers before sensitive data leaves.
  3. One log of official requests that your security team can see.
  4. A named owner for the 6 p.m. Friday request, including at any outsourcer that takes requests for you.

Then ask your broker how your cyber form treats a data release no hacker forced.


What LION is seeing in financial institution (FI) lines

On the renewals we’re seeing, cyber is the softest line in the FI book. Regional and mutual insurers and MGAs are seeing −4% to +1%, and insurtechs 0% to +6%. A flat renewal is a good time to ask about the social engineering sublimit and the AI wording. A cheaper $250,000 sublimit still runs out on one deepfake wire.

(source: LION book observations, renewals quoted May–July 2026; rate only, before changes in retentions or terms; indicative, not quotes)


The Bottom Line

Good cyber crime awareness starts with the fundamentals: the processes, procedures and standard operating protocols your people follow before they move money or release data.

Even if those are in place, revisit them once a year. Look at what’s changing in the market and at the claims working their way through it, like this month’s deepfake wires and the Revolut release, and make the tweaks you need. Then tell your underwriters what you’ve done, on every line: D&O, crime, cyber and E&O. They can only credit the controls they know about.

Three for your board on Monday

  1. Test the callback, then check the limit. When did we last test, live, that nobody can send an urgent wire on a voice or video instruction alone? And is our social engineering limit as large as our largest single wire?
  2. Check the paperwork before we sign it. Do our application’s answers on phishing-resistant multifactor authentication and staff training match what’s actually in place, and does any policy renewing January 1 add an AI exclusion?
  3. Name who releases data, and who reports it. Who can send customer records in response to an outside “official” request, and how do they confirm it? If one goes out by mistake, who decides whether we must notify, and by when?

If the honest answer to any of them is “I’d have to check,” check before January 1.


ICYMI: In September we read two $250,000 cyber sublimits that went to court in Texas, including the wire-fraud cap that held in Waco. Read it here.


Thank you for reading today’s edition.

Want to share it? Copy the link below:

https://lionspecialty.kit.com/posts/81-of-finance-leaders-saw-ai-fraud-attempts-in-the-past-year-your-cyber-month-plan-mapped-to-your-policies-and-revolut-trusted-a-hacked-inbox

And if this was forwarded to you, subscribe here.

Stay Covered Everybody,

-FLIP

P.S. If you’re not sure how your crime and cyber policies would treat a deepfake wire or a data release your own staff approved, I can help you check. Reach out for a confidential conversation: book a time or reply to this email.

P.P.S. Nothing in this briefing constitutes legal advice. These are the opinions of the founder, and coverage is always subject to the terms of each policy. It’s market intelligence designed to help you ask better questions of your advisors and make sharper decisions at your next insurance renewal.


You're receiving this because you subscribed to the LION Specialty Boardroom Brief.
Unsubscribe  ·  Update your preferences

LION Specialty

Everything you need to know to navigate the financial institution insurance market in ≈ 5 minutes per week. Delivered on Fridays.

Read more from LION Specialty
The minutes said the plan protected stockholders. The transcript had the chairman saying it kept the board “in its position.” The judge quoted the transcript.

Skim time: 7 minutes · Listening time: 6 minutes. Prefer to listen? Flip reads this week’s Brief here. Three articles got my attention this week, and no one seems to be talking about them. Each one is a record somebody will read after something goes wrong. The prospectus. The Fidelis Partnership (TFP) told the SEC that one capacity provider backs 48% of its bound premium. The Delaware opinion. A court quoted a board’s AI-generated meeting transcript, and the transcript told a different story...

Skim time: 6 minutes · Listening time: 6 minutes. Prefer to listen? Flip reads this week’s Brief here. Two numbers this week. The first is $205 million: the charge Markel took at State National, a major U.S. fronting carrier, after a bankrupt backer’s collateral proved, by Markel’s account, real but too small. The second is $5,790: a premium an AI model supplied for an insurance application whose premium field was blank. It cited a page for it. The figure wasn’t in the document. One number...

Skim time: 6 minutes · Listening time: 7 minutes. Prefer to listen? Flip reads this week's Brief here. In April 2014, a New Jersey drug company bought a $2 million directors and officers (D&O) policy. Its chairman held roles across more than a dozen companies he owned or controlled. The allegations against him involved his role at the insured company. They also involved his roles at companies the policy did not insure. The cases settled for $12 million. Twelve years after the policy was...