A Mississippi law firm lost $158,000 when it followed fraudulent instructions from an individual posing as a corporate representative trying to collect a debt. The firm sued several parties, including its insurance agency, when its cyber insurance carrier denied coverage for its loss.
The firm purchased the policy in the summer of 2023 because one of its clients required them to have it. They contacted an agency that billed itself as a leading provider of cyber insurance. The agency obtained a policy for them with an effective date of August 15, 2023.
The policy included a Social Engineering Coverage Endorsement that promised the insurer would pay for a loss resulting from a “social engineering incident.” The endorsement defined “social engineering incident” as the intentional deception of a company, resulting in the transfer of funds to an unauthorized person, location, or account. The incident had to result from an employee’s good faith reliance upon apparently legitimate but fraudulent email instructions. The instructions had to come from an imposter posing as a known vendor, customer, contractor, or internal colleague.
In May 2024, an individual contacted the firm to request its help collecting a $158,850 debt owed to his company. The firm emailed him a letter of engagement, he signed it and emailed it back in early June. Two days later, correspondence purporting to be from the debtor arrived at the firm along with a check in the full amount of the debt. The creditor told the firm by phone and email to wire the funds, net of the firm’s fees, to a bank account. The firm wired $158,425 to the account.
A few days later, the bank the check was drawn on returned the check to the firm’s bank, unpaid. In truth, the individual who contacted the firm was impersonating someone at the company. The company did not have an unpaid debt due from another company. The actual person at the company had never contacted the firm, had never done business with the company that supposedly owed the debt, and had no knowledge of the fraudulent transaction.
That same month, the firm submitted a claim under its cyber insurance policy, but the carrier denied coverage two months later. The incident, the claim adjuster said, did not fit the endorsement’s definition of “social engineering incident.” In July and August 2025, the firm sued the carrier, a third-party administrator (TPA), the agency, and unnamed individuals for claims including breach of contract, gross negligence, bad faith, and fraud.
The insurance defendants asked the court to dismiss the suit in August. In March 2026, the judge dismissed the suit. The breach of contract claim against the TPA and agency failed, she wrote, because they were not parties to the insurance policy. In any event, she ruled that the insurer’s interpretation of the endorsement was correct. For that reason, she also dismissed the allegations of gross negligence, fraud, and others.
Although the argument failed, one of the points the law firm raised was the language in the marketing materials for the coverage. The TPA and agency’s marketing promised the purchaser “peace of mind,” claimed that they were a “pioneer” in this type of coverage that innovated to make cyber insurance easy, and were “the leading provider of cyber insurance for small and medium-sized enterprises.” Agency errors and omissions (E&O) loss prevention experts often caution agencies against using this kind of superlative language in their marketing. Uninsured clients often point to it when claiming they were misled.
Agencies should be careful about the claims they make about their services on their websites, social media posts, and other marketing materials. Appearing to over-promise can increase the chances of an E&O action against the agency.







