Social engineering fraud is a scam that works on people instead of computers. Rather than breaking through a firewall, the criminal tricks one of your employees into handing over a password, wiring money, or opening a file, usually by pretending to be someone the employee trusts. The most common forms are phishing, business email compromise, pretexting, and baiting, and a well-structured cyber liability policy can be designed to respond to several of them, subject to underwriting.
These scams have become the everyday version of cybercrime for small businesses in Alpena, Gaylord, Petoskey, and everywhere in between. Below are the tactics we see most, the warning signs, and how coverage fits in.
What is social engineering, in plain terms?
It is manipulation. The attacker studies a little about your business from your website or LinkedIn, then uses trust, urgency, and authority to get a person to act before they think. The request usually looks completely normal, because it is built to. That is what makes it dangerous. According to Verizon's 2025 Data Breach Investigations Report, phishing was involved in 15% of breaches and stolen credentials in 22%, and roughly 60% of all breaches involved a human element rather than a purely technical failure.
What does a phishing attack look like now?
Phishing is the fake message that appears to come from a bank, a vendor, a payroll provider, or a coworker. The old giveaways, such as bad grammar and a foreign prince, are mostly gone. A modern phishing message often uses correct branding, references a real invoice or project, and arrives by text or a chat app rather than only email.
The warning signs are worth memorizing:
- An urgent payment or password request that pressures you to move fast
- A sender address that is off by one character from the real one
- A link that does not match the company it claims to be from
- An unexpected attachment
- A request to keep the matter quiet or to skip your normal approval steps
What is business email compromise, and why is it so costly?
Business email compromise, or BEC, is when a criminal gets into or convincingly imitates a real email account and uses it to redirect a payment. It is the version of this crime that empties bank accounts. The FBI's 2024 Internet Crime Report recorded $2.77 billion in reported BEC losses across 21,442 complaints in a single year. A typical case looks like an email from a vendor saying their banking details have changed, or a note from the owner asking accounting to send a wire right away. Both are worth verifying by phone before a dollar moves.
What are pretexting, baiting, and quid pro quo scams?
Pretexting builds a believable backstory over time. The caller poses as HR, IT, an auditor, or a trusted vendor, and gathers a little information on each contact until they have enough. Baiting dangles something tempting, such as a free download or a USB drive left in a break room, that installs malware when used. Quid pro quo offers a service in exchange for access, like fake tech support that offers to fix a problem if you will just log in for them. All three end the same way, with credentials or money in the wrong hands.
How does cyber insurance respond to social engineering fraud?
It depends on the policy, and this is an area where the fine print genuinely matters. A general liability policy usually does not respond to these losses. A cyber liability and crime policy can be structured to help with costs such as forensic investigation, legal defense, notifying affected people, and, in some cases, the funds lost to a fraudulent transfer. That last piece, often called social engineering or fraudulent instruction coverage, is frequently a separate add-on with its own limit, so it is worth asking about specifically rather than assuming it is included. None of this is bound or altered until an authorized representative confirms it, and every policy is subject to underwriting.
What should our team do before sending money or credentials?
Build one habit and it stops most of these cold: verify out of band. Before acting on any request to move money or change payment details, confirm it through a second channel you already trust.
- Stop when a request is urgent, unusual, or asks you to bypass normal steps
- Call the requester back on a number you already have, not one from the message
- Confirm any change to bank or wire details by phone with a known contact
- Require a second person to approve wires above a set dollar amount
- Report anything suspicious to your manager, even if you already acted on it
That last point matters. The faster a mistaken wire is reported, the better the odds of recovering it. For the password side of this, our post on building a strong password covers the habits that keep credentials out of these scams, and what is cyber liability explains how the coverage is structured overall.
Where does Top O' Michigan come in?
We have insured Northern Michigan businesses for 52 years, and we work with a panel of carriers so we can match cyber and crime coverage to how your business actually handles money and data. If you want someone to read your current policy for these specific gaps, an agent who knows the area will do it with you. Start on our cyber insurance page, or reach the team nearest you through the Gaylord or Petoskey office pages.
Call 800-686-8664 or email Service@TheSpireTeam.com and we will help you review your exposure. Coverage is subject to underwriting and is not bound until confirmed by an authorized representative.
.png)