Does Restaurant Insurance Cover Credit Card Fraud?

It depends on the type of fraud. A data breach that exposes guests’ card numbers, such as POS malware or a skimmer, is generally a cyber insurance claim, and many cyber policies include PCI fines and assessments. Theft of your own money is a crime insurance claim. Ordinary chargebacks from stolen cards used on online orders are usually not covered by either, and general liability typically excludes data breaches.

Restaurants handle a high volume of card transactions across POS terminals, online ordering, delivery tablets and servers who walk away with cards. That makes card fraud one of the more confusing claim areas, because the answer changes depending on whose money was lost and how. This page separates the pieces.

Three kinds of card fraud, three different policies

  • Cyber insurance – responds to a breach of card data or personal information: forensic investigation, notification, credit monitoring, legal and regulatory defense, liability to customers and card brands, and PCI fines and assessments passed through by your payment processor, where the policy includes them. See restaurant cyber insurance.
  • Crime insurance – responds when the restaurant loses its own money or property through employee theft, computer fraud, funds transfer fraud, forgery, or counterfeit currency. Social engineering fraud, such as a fake vendor email changing bank details, usually needs a specific endorsement.
  • Chargebacks and card-not-present fraud – when someone uses a stolen card to place an order and the real cardholder disputes it, the lost sale is generally treated as a business risk under your merchant agreement, not an insured loss. A few cyber forms offer limited coverage, but it is not standard.

General liability is often assumed to cover data claims, but current ISO CGL forms include an exclusion for access or disclosure of confidential or personal information, and many carriers attach it. That is why cyber coverage exists as its own line. For a side-by-side comparison, see cyber vs crime insurance for restaurants.

Exclusions and conditions to watch

  • PCI sublimits – PCI fines and assessments are frequently subject to a sublimit well below the main cyber limit.
  • PCI compliance – some cyber policies ask about or require compliance with PCI DSS, and misstatements on the application can create coverage problems.
  • Contractual liability – cyber policies usually exclude liability assumed by contract, with a carve-back for PCI assessments; the exact wording matters.
  • Insurability of fines – whether fines and penalties can be insured depends on state law and the policy.
  • Employee exclusions – on a crime policy, coverage for an employee ends once you know of a prior dishonest act by that person.
  • Discovery and notice deadlines – crime policies and cyber policies both require prompt reporting once a loss is discovered.

Two card fraud scenarios

Skimmers on the handheld terminals at a sushi restaurant

A sushi restaurant’s processor calls: dozens of cards used at the restaurant have been flagged for fraud. Forensics find that an employee had been skimming guest cards on a pocket reader. The breach response, forensic costs, notification and any card brand assessments passed through by the processor are cyber claims, subject to PCI sublimits. The employee’s conduct also raises crime coverage questions if restaurant funds were taken.

A fake invoice at a multi-unit pizza group

The office manager of a pizza group receives an email that appears to come from its flour supplier, with new bank details. The payment goes to a fraudster. This is not a card breach, so cyber breach coverage may not respond. A crime policy with a social engineering fraud endorsement is the usual answer, and without that endorsement the loss may be excluded because the employee voluntarily authorized the transfer.

What to check on your own coverage

  • Cyber policy in place – not just a small data breach endorsement on your BOP.
  • PCI fines and assessments – included, and the sublimit shown.
  • Breach response costs – forensics, notification and credit monitoring, inside or outside the main limit.
  • Business interruption from a system outage – if your POS or online ordering goes down.
  • Crime policy – employee theft, computer fraud and funds transfer fraud insuring agreements.
  • Social engineering endorsement – added, with the verification conditions it requires.
  • Money orders and counterfeit currency coverage for cash-heavy operations.
  • Merchant services agreement – what you agreed to pay the processor after a breach.

Comparing cyber and crime quotes together

Through Provident Financial Group, US Restaurant Insure quotes cyber and crime coverage from multiple carriers alongside your restaurant package, so the pieces fit without overlap or gaps. Call (866) 964-6660 to review what you have. Our blog on cyber and data breach insurance for restaurants goes deeper on POS risk.

Frequently asked questions

Does my BOP cover a credit card data breach?

Usually only if a data breach endorsement was added, and those are often limited. A standalone cyber policy typically offers broader breach response and liability coverage.

What are PCI fines and assessments?

They are amounts card brands charge through your processor after a breach under your merchant agreement, such as fines and fraud recovery assessments. Many cyber policies cover them up to a sublimit.

Are chargebacks from stolen cards covered?

Generally no. Chargebacks are handled under your merchant agreement and are typically not an insured loss, though a few cyber policies offer limited coverage.

Does crime insurance cover an employee stealing guests’ card numbers?

Crime insurance covers the restaurant’s own money and property. Losses to guests and card brands from stolen card data are usually cyber liability claims.

Protect your card payments on every channel. Get Multiple Quotes within minutes.

Related pages

Scroll to Top