Cyber Insurance
Key Features
Shielding You in the Cyberverse
Coverage Highlights
Key benefits of this planNo Deductibles
Enjoy peace of mind with “no upfront payments” required for covered claims
No Sublimits
Benefit from comprehensive coverage with “no sublimits” for different areas
Smart Home Protection
Get coverage for the costs of restoring or decontaminating your smart home devices affected by malware attacks
Family Coverage Extension
Extend your coverage to include your family with an additional premium
Inclusions
What's covered?Digital Theft of Funds
Pays agreed amount in case of financial losses due to unauthorized access to your accounts caused by phishing or email spoofing
Identity Theft
Pays agreed amount in case of lost wages, credit monitoring costs, and the cost of prosecution related to identity theft.
Data Restoration
Pays for IT services to recover data or fix devices after a cyber attack
Cyber Bullying, Cyber Stalking, and Loss of Reputation
Covers the cost of prosecution against a third party for committing cyber bullying or stalking
Cyber Extortion
Covers Loss that the Insured Beneficiary incurs solely and directly as a result of a Cyber Extortion Threat first Discovered during the Period of Insurance
Social Media/Media Liability
Covers Legal liability that directly results from the Identity Theft of the Insured Beneficiary from a legitimate Social Media account of the Insured Beneficiary by Cyber Attack
Privacy Breach and Data Breach Liability
Pays agreed amount for costs including legal fees incurred by the Insured Beneficiary for a Claim for Damages lodged by the Insured Beneficiary
Malware Cover
Covers cost incurred due to damage caused by Malware received through SMS, File transfer, downloaded programs from Internet or any other digital means by the Insured Beneficiary’s Computer System which has resulted in information stored in the Insured Beneficiary’s Computer System being damaged or altered or disrupted or misused
Phishing Cover
Pays agreed amount for Direct and Pure Financial Loss sustained by the Insured Beneficiary by being an innocent victim of an act of Phishing by a third party
Note
Please read policy wording for detailed terms and conditions
Exclusions
What's not covered?Dishonest or Improper Conduct
Any: a) deliberate, criminal, fraudulent, dishonest or malicious act or omission; or b) intentional or knowing violation of any duty, obligation, contract, law or regulation; by the Insured Beneficiary c) Any losses that are caused intentionally & against the law
Bodily Injury
Any actual or alleged bodily injury, sickness, mental anguish or emotional distress or disturbance, disease or death of any person howsoever caused
Property Damage
Any damage to or destruction of any tangible property, including loss of use thereof
Contractual Liability
Any liability under any contract, agreement, guarantee or warranty assumed or accepted by an Insured Beneficiary except to the extent that such liability would have attached to an Insured Beneficiary in the absence of such contract, agreement, guarantee or warranty
Unsolicited Communication
Any distribution of unsolicited correspondence or communications (whether in physical or electronic form), wiretapping, audio or video recordings or telephone marketing
Trade Secrets and Intellectual Property
Any actual or alleged plagiarism or infringement of any Trade Secrets, patents, trademarks, trade names, copyrights, licenses or any other form of intellectual property
War, Terrorism including Cyber Terrorism and Governmental Acts and Trading
Any losses or liabilities connected with any types of purchase or sale transactions or other dealing in securities, commodities, derivatives, foreign or Federal Funds, currencies, foreign exchange, cryptocurrencies and the like
Note
Please read policy wording for detailed terms and conditions
Email spoofing, meaning the forgery of a sender address to trick recipients into trusting a fraudulent message, is a favourite weapon of cyber-criminals. By manipulating the “From” header or underlying SMTP commands, attackers make their emails appear to come from banks, suppliers or senior executives. Victims who trust the fake identity may reveal sensitive data, click on malicious links or authorise payments. Because spoofed messages can slip past basic spam filters and look perfectly legitimate, this threat fuels business email compromise (BEC) losses that now run into billions every year.
Spoofers exploit gaps in the Simple Mail Transfer Protocol (SMTP). They register look-alike domains or abuse open relays to send messages with a forged “MAIL FROM” command. Unless a receiving server validates Domain Keys Identified Mail (DKIM), Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting & Conformance (DMARC) records, the counterfeit passes unhindered. Once delivered, persuasive wording, cloned logos and urgent calls to action lure users into clicking booby-trapped links or wiring money to criminal accounts. Advanced campaigns pair spoofed emails with phone calls (“vishing”) to add credibility and rush the victim.
1. Domain look-alikes – swapping letters (“bajajgeneralinsurance.com”) or adding sub-domains.
2. Display-name deception – keeping the real domain but changing the visible name.
3. Reply-to manipulation – legitimate sender address in “From”, rogue address in “Reply-To”.
4. Compromised SMTP servers – hijacking trusted mail relays to avoid blacklists.
5. Embedded tracking pixels – confirming the address is live before follow-up extortion.
6. HTML obfuscation – hiding malicious URLs behind benign anchor text.
7. Thread hijacking – injecting malware into an existing email chain to bypass suspicion.
In 2024, European retailer Pepco Group lost €15.5 million when spoofed CEO emails duped staff into wiring funds to fake suppliers. The infamous Colonial Pipeline hackers initially breached networks using spoofed password-reset emails, culminating in a multi-million-dollar ransom. Closer to home, an Indian pharma SME paid ₹1.8 crore after spoofed vendor invoices slipped through. Even individuals suffer: deep-fake video conference invites sent from spoofed Gmail addresses have led to sextortion blackmail. These cases underscore the ease with which forged emails bypass technical and human defences.
Look beyond the display name: hover over the “From” field to inspect the full address. Check domain spelling for extra characters or odd TLDs. Examine email headers for SPF, DKIM and DMARC results; “fail” flags signal forgery. Be wary of generic greetings, urgent payment requests, mismatched URLs and unexpected attachments. Secure Email Gateways (SEGs) with real-time threat intelligence can quarantine suspicious traffic, while DMARC enforcement blocks unauthorized use of your domain entirely. User-awareness training remains vital: teach staff to forward questionable messages to IT before clicking.
Find the best coverage options side by side, tailored to your needs.
| Coverage Name |
Plan 1 |
Plan 2 |
Plan 3 |
Plan 4 |
|---|---|---|---|---|
| Digital Theft of funds | Yes | Yes | Yes | Yes |
| Identity theft | Yes | Yes | Yes | Yes |
| Data Restoration | Yes | Yes | Yes | Yes |
| Cyber Bullying/Stalking/Loss of reputation | Yes | Yes | Yes | Yes |
| Cyber Extortion | Yes | Yes | Yes | Yes |
| Online Shopping | Yes | No | Yes | Yes |
| Online Sales | No | No | No | Yes |
| Social Media/Media Liability | No | Yes | No | Yes |
| Network Security Liability | No | No | No | Yes |
| Privacy Breach and Data Breach Liability | No | Yes | No | Yes |
| Privacy Breach and Data Breach by Third Party | No | No | No | Yes |
| Loss of Professional Income | No | No | No | Yes |
Spoofing fuels direct financial theft, data breaches, malware infections and reputational damage. Businesses face wire-transfer fraud, loss of intellectual property and regulatory fines if customer data leaks. Individuals risk identity theft, blackmail and drained bank accounts. Incident-response, legal and PR costs often dwarf the ransom or stolen amount, while distrust among clients and partners can linger for years.
Factor | Email Spoofing | Phishing |
Goal | Impersonate a trusted sender | Steal data or money |
Method | Forge header/domain | Fake websites, malware links |
Technical layer | SMTP manipulation | Social engineering + payload |
Detection | SPF/DKIM/DMARC failure | Suspicious URLs, content cues |
1. Publish SPF, sign messages with DKIM and enforce DMARC at “reject”.
2. Use SEGs and AI-based anomaly detection for inbound mail.
3. Enable multi-factor authentication on email accounts.
4. Train employees to verify payment requests via secondary channels.
5. Regularly patch mail servers and disable open relays.
6. Register defensible look-alike domains to reduce spoofing options.
7. Back up critical data offline to mitigate malware delivered via spoofed mail.
Get instant access to your policy details with a single click.
How To List
How to Buy
1
Visit Bajaj General website
2
Enter personal details
3
Compare cyber insurance plans
4
Select suitable coverage
5
Check discounts & offers
6
Add optional benefits
7
Proceed to secure payment
8
Receive instant policy confirmation
How to Renew
1
Login to the renewal portal
2
Enter your current policy details
3
Review and update coverage if required
4
Check for renewal offers
5
Add or remove riders
6
Confirm details and proceed
7
Complete renewal payment online
8
Receive instant confirmation for your policy renewal
How to Claim
1
Notify Bajaj General about the claim
2
Submit all the required documents
3
Choose cashless or reimbursement mode for your claim
4
Avail treatment and share required bills
5
Receive claim settlement after approval
How to Port
1
Check eligibility for porting
2
Compare new policy benefits
3
Apply before your current policy expires
4
Provide details of your existing policy
5
Undergo risk assessment by Bajaj General
6
Receive approval from Bajaj General
7
Pay the premium for your new policy
8
Receive policy documents & coverage details
Comprehensive cyber policies reimburse fraudulent transfers, pay for forensic investigation, legal representation, customer notification and reputational PR services. They also fund system restoration after malware delivered through spoofed mail. Some insurers provide 24 × 7 incident-response hotlines, helping businesses contain damage quickly and comply with breach-reporting laws.
Yes—policies often list “email spoofing” or “phishing” under cyber-crime clauses. Coverage typically includes direct financial loss, extortion payments where lawful and crisis-management expenses. Companies should check sub-limits, waiting periods and whether social-engineering fraud is a standard inclusion or an optional rider.
The Cyber Insurance Policy from Bajaj General Insurance explicitly covers email spoofing, phishing and IT theft loss. If a forged email tricks you into transferring funds or leaks sensitive data, the policy reimburses the financial hit and pays for legal action against fraudsters. It also covers costs to restore compromised systems and provides expert guidance on strengthening SPF, DKIM and DMARC. Affordable premiums (from roughly ₹1 per day) and sums insured up to ₹1 crore make it an accessible shield for individuals and SMEs alike, supported by a 24×7 claims helpline.
Email underpins supply-chain orders, payroll and client communication. A single spoofed invoice can wipe out quarterly profits, while leaked correspondence may hand competitors strategic plans. Regulators can levy hefty fines for data exposure and breached partners may sue for negligence. Proactive defences and a cyber-insurance backstop are therefore essential operational safeguards.
Not exactly. Spoofing forges sender's identity; phishing uses deceptive content. Many phishing emails rely on spoofing, but spoofing alone may aim merely to impersonate.
Yes; spoofed emails reach your inbox even if unopened. Risk arises once recipients act on forged messages or click embedded links.
Most policies pay solicitor and court fees incurred in defending civil claims or regulatory investigations stemming from a spoofing incident.
It reimburses unauthorised fund transfers, pays for data restoration and covers service-provider costs related to compromised email communication.
Yes. In India it violates the IT Act 2000 and IPC provisions on impersonation and fraud, exposing offenders to fines and imprisonment.
Victims may suffer bank fraud, identity theft or reputational harm if personal contacts receive malicious content posing as them.
They steal money, credentials or data, spread malware and gain footholds in corporate networks for larger attacks.
Notify your bank, change passwords, preserve the email as evidence, lodge a cybercrime report and contact your cyber-insurance provider.
Yes. Business email compromise now accounts for over 70 % of reported cyber incidents worldwide, making spoofing a daily corporate threat.
Yes. Most policies, including Bajaj General Insurance, cover direct financial losses caused by fraudulent transactions.
Yes. Optional add-ons allow coverage for family members of all ages under certain policies.
Generally, a FIR/police report, identity proof, transaction statements, and evidence of the fraudulent activity are required for claim processing.
Don’t stress the small things in life! The easiest and quickest way to renew your life insurance policy is by doing it online. Topping up your health cover gives you freedom from worrying about heavy medical expenses.
We know that reading through the ponderous terms and conditions section of a health insurance policy isn’t always easy. So, here is the quick answer. Your renewal premium is calculated based on your age and coverage. As always, you can put the power of compounding to good use by investing in health insurance as early as possible.
Yes, of course. Life can get really busy and even things as important as renewing your health insurance plan can get side-lined. With Bajaj General, we turn back the clock to give a grace period where you can renew your expired policy. For 30 days from the expiry date, you can still renew your health cover with ease. Now, you can run the race at yo
Absolutely! All you have to do to renew your health insurance is click or tap a few times! You can definitely renew health insurance policies online and also buy new policy for your family & friends click here to know more.
Yes, as per IRDAI regulations, insurance portability between providers is allowed. This also includes transfer of benefits like Cumulative Bonus and credits relating to waiting period for pre-existing diseases.
Download Bajaj General App!