LEGAL PRECEDENT REPOSITORY

Cyber Insurance Precedents & Policy Exclusion Tracker

A comprehensive index of landmark judicial rulings governing cyber insurance claims. Track how federal and state courts interpret "Act of War" exclusions, physical damage thresholds, ransomware reimbursement, and MFA underwriting warranties.

War Exclusions: Narrow Interpretation Courts hold standard war clauses require conventional military hostilities.
Physical Damage: Loss of Utility Qualifies Software locking and data corruption meet property damage criteria.
Ransom Coverage: Covered Under Duress Extortion payments ruled involuntary when necessary to restore operations.
MFA Warranties: Policy Rescission Risk Inaccurate questionnaire answers allow insurers to cancel policies completely.
Superior Court of New Jersey, Appellate Division • 475 N.J. Super. 271, 292 A.3d 518 (App. Div. 2023)

Merck & Co. v. Ace American Insurance Co.

Policyholder Victory (Full Coverage Affirmed) Claim: $1.4 Billion
Incident Nature: NotPetya Destructive Malware (Russian GRU Unit 74455)
Contested Policy Provision: Hostile / Warlike Action Exclusion

Judicial Ruling & Findings: In the most significant cyber insurance ruling in history, the court held that standard war and hostile action exclusions apply only to traditional armed military hostilities involving sovereign nation states, not unannounced malware or global supply chain wipers, despite public government attribution to the Russian military.

Underwriting & Risk Implications: Insurers globally were forced to rewrite standard property/casualty policies and introduce specific cyber war clauses (e.g. Lloyd's LMA5564-LMA5567) explicitly defining state-backed cyber operations.

Related Dossier in Case Library: View /cases/notpetya/ →
Circuit Court of Cook County, Illinois • No. 2018-L-011008 (Ill. Cir. Ct. settled 2022)

Mondelez International, Inc. v. Zurich American Insurance Co.

Settled Favorably for Insured After Initial Rulings Claim: $100.0 Million
Incident Nature: NotPetya Supply Chain Infection via M.E.Doc Accounting Software
Contested Policy Provision: Hostile or Warlike Action by Sovereign Government

Judicial Ruling & Findings: The food conglomerate sued Zurich for denying coverage of $100M in hardware replacement and unfulfilled orders caused by NotPetya. Zurich argued that western intelligence attribution to Russia triggered the war exclusion. The case settled on confidential terms after the court indicated the exclusion was ambiguous.

Underwriting & Risk Implications: Demonstrated that insurers face extreme evidentiary hurdles when attempting to prove nation-state attribution in civil litigation without disclosing classified intelligence.

Related Dossier in Case Library: View /cases/notpetya/ →
U.S. District Court for the District of Maryland • 435 F. Supp. 3d 679 (D. Md. 2020)

National Ink & Stitch, LLC v. State Auto Property & Casualty Insurance Co.

Policyholder Victory (Physical Damage Affirmed) Claim: $300,000+ Replacement Costs
Incident Nature: Ransomware Infection of Core Art & Embroidery Servers
Contested Policy Provision: Direct Physical Loss of or Damage to Covered Property

Judicial Ruling & Findings: The insurer argued that because server physical hardware was intact and could be rebooted, no "physical damage" occurred. The federal court rejected this argument, ruling that loss of system reliability, operational utility, and data integrity constitutes physical damage.

Underwriting & Risk Implications: Established critical precedent that ransomware and data destruction meet traditional commercial property policy definitions of physical loss.

Related Dossier in Case Library: View /cases/colonial-pipeline/ →
Indiana Supreme Court • 165 N.E.3d 82 (Ind. 2021)

G&G Oil Co. of Indiana v. Continental Western Insurance Co.

Policyholder Victory (Ransom Payment Covered) Claim: $35,000 Ransom Payment + $45,000 Response Fees
Incident Nature: Multi-Server Ransomware Lockout
Contested Policy Provision: Computer Fraud & Voluntary Transfer Exclusion

Judicial Ruling & Findings: The insurer argued the payment of Bitcoin was a "voluntary transfer" rather than theft. The Indiana Supreme Court held that transferring cryptocurrency under digital duress to regain access to operational computers constituted a covered computer fraud loss.

Underwriting & Risk Implications: Clarified that extortion payments compelled by malicious encryption are involuntary losses directly resulting from computer hacking.

Related Dossier in Case Library: View /cases/change-healthcare/ →
U.S. District Court for the Central District of California • No. 2:22-cv-04645 (C.D. Cal. 2022)

Travelers Property Casualty Co. v. International Control Services, Inc.

Insurer Victory (Policy Rescinded for Misrepresentation) Claim: Full Policy Rescission
Incident Nature: Ransomware Incident Following Credential Theft
Contested Policy Provision: MFA Warranty & Material Misrepresentation on Application

Judicial Ruling & Findings: Travelers sued to rescind an entire cyber policy after discovering the insured had answered "Yes" to an application question asking if multi-factor authentication was required on all administrative access, when in fact MFA was only enabled on email accounts, not firewalls or servers.

Underwriting & Risk Implications: Serves as the leading industry warning that inaccurate representations on underwriting security control questionnaires will void cyber coverage entirely.

Related Dossier in Case Library: View /cases/mgm-resorts/ →
U.S. District Court for the District of Minnesota • No. 21-cv-00794 (D. Minn. 2022)

Fishbowl Solutions, Inc. v. The Hanover Insurance Co.

Split / Sub-Limit Application Affirmed Claim: $175,000 Wire Diversion
Incident Nature: Business Email Compromise (BEC) Invoice Fraud
Contested Policy Provision: Funds Transfer Fraud vs. Computer Attack Endorsement

Judicial Ruling & Findings: Threat actors compromised an executive email account and altered wire instructions sent to a customer. The court strictly enforced policy wording distinguishing between direct system manipulation and deceptive social engineering communications.

Underwriting & Risk Implications: Highlights the critical importance of reviewing separate sub-limits for social engineering and funds transfer fraud within cyber policies.

Related Dossier in Case Library: View /cases/equifax/ →