Skip to main content
Insurance for
Travel Agents
E&O · GL · Cyber

Cyber Liability

Cyber liability for travel agents

Few small businesses hold as much sensitive personal data as a travel agent. Passport scans, dates of birth, home addresses, and card numbers — often all for the same family, often sitting in an inbox.

Informational only. This page does not constitute insurance, legal, or financial advice. Coverage terms vary by carrier, policy, and jurisdiction. Full disclaimer.

What you are actually holding

To book international travel you need a passport number, a full legal name, a date of birth, and a way to pay. That combination is close to a complete identity record, and you may hold it for everyone on a twelve-person family trip. Most of it arrived as an email attachment and is still there.

A breach does not require a sophisticated attack. The common versions are a mailbox compromised through a reused password, a laptop taken from a car, or a phishing email that looked like a supplier confirmation. What follows is the expensive part: figuring out what was taken, notifying the people affected, and dealing with whatever they do next.

Notification is a legal obligation, not a courtesy

Every state has a breach notification law, and they apply to businesses of any size. If personal information was exposed, you are generally required to tell the people whose data it was, within a deadline, in a form the statute describes. Some states also require notice to the attorney general above a threshold count.

Cyber coverage exists largely to fund that response — the forensic work to determine scope, the legal advice on what the statute requires, the notification itself, and credit monitoring for the people affected. Those costs arrive whether or not anyone ever sues you.

Wire fraud and the fake supplier invoice

The version of this that hits travel agencies hardest is social engineering. An email that appears to come from a supplier, or from you, redirects a payment to a new account. The money leaves, and it is usually gone.

Coverage for this is not automatic. Funds transfer fraud and social engineering are frequently separate insuring agreements with their own, lower sublimits, and they often carry conditions — such as verifying account changes by phone using a number you already had. If this exposure matters to you, it is worth asking about specifically rather than assuming a cyber policy includes it.

Typically covered

  • Forensic investigation to determine what was accessed
  • Legally required breach notification and credit monitoring
  • Liability to clients whose information was exposed
  • Ransomware response and extortion payments, where permitted
  • Business interruption while your systems are down
  • Funds transfer and social engineering fraud, often by endorsement

Not covered here

  • Booking errors, even ones made in a compromised system — that is E&O
  • The cost of upgrading your systems after a breach
  • Loss of physical equipment — that is property coverage
  • Fraud committed by you
  • Breaches you were already aware of before coverage started

Common questions

I use a GDS and a CRM. Is their security my problem?
Their breach is their problem, but your obligation to your clients does not disappear because a vendor was the point of failure. Notification duties generally follow whoever collected the data.
Does my host agency cover this?
Some do for data held in the host systems. Data in your own inbox, your own laptop, and your own CRM is generally yours to protect. Ask specifically rather than assuming.
What is the fastest thing I can do to reduce this risk?
Stop keeping passport scans and card numbers in email once the booking is complete. Data you no longer hold cannot be part of a breach, and it shortens the notification list if one happens.

Related: errors and omissions and general liability.

Get cyber quoted

One form covers every line. About three minutes, and the questions adapt to how you operate.

Start Your Quote