Cyber Insurance Precedents & Policy Exclusion Tracker
A comprehensive index of landmark judicial rulings governing cyber insurance claims. Track how federal and state courts interpret "Act of War" exclusions, physical damage thresholds, ransomware reimbursement, and MFA underwriting warranties.
Merck & Co. v. Ace American Insurance Co.
Judicial Ruling & Findings: In the most significant cyber insurance ruling in history, the court held that standard war and hostile action exclusions apply only to traditional armed military hostilities involving sovereign nation states, not unannounced malware or global supply chain wipers, despite public government attribution to the Russian military.
Underwriting & Risk Implications: Insurers globally were forced to rewrite standard property/casualty policies and introduce specific cyber war clauses (e.g. Lloyd's LMA5564-LMA5567) explicitly defining state-backed cyber operations.
Mondelez International, Inc. v. Zurich American Insurance Co.
Judicial Ruling & Findings: The food conglomerate sued Zurich for denying coverage of $100M in hardware replacement and unfulfilled orders caused by NotPetya. Zurich argued that western intelligence attribution to Russia triggered the war exclusion. The case settled on confidential terms after the court indicated the exclusion was ambiguous.
Underwriting & Risk Implications: Demonstrated that insurers face extreme evidentiary hurdles when attempting to prove nation-state attribution in civil litigation without disclosing classified intelligence.
National Ink & Stitch, LLC v. State Auto Property & Casualty Insurance Co.
Judicial Ruling & Findings: The insurer argued that because server physical hardware was intact and could be rebooted, no "physical damage" occurred. The federal court rejected this argument, ruling that loss of system reliability, operational utility, and data integrity constitutes physical damage.
Underwriting & Risk Implications: Established critical precedent that ransomware and data destruction meet traditional commercial property policy definitions of physical loss.
G&G Oil Co. of Indiana v. Continental Western Insurance Co.
Judicial Ruling & Findings: The insurer argued the payment of Bitcoin was a "voluntary transfer" rather than theft. The Indiana Supreme Court held that transferring cryptocurrency under digital duress to regain access to operational computers constituted a covered computer fraud loss.
Underwriting & Risk Implications: Clarified that extortion payments compelled by malicious encryption are involuntary losses directly resulting from computer hacking.
Travelers Property Casualty Co. v. International Control Services, Inc.
Judicial Ruling & Findings: Travelers sued to rescind an entire cyber policy after discovering the insured had answered "Yes" to an application question asking if multi-factor authentication was required on all administrative access, when in fact MFA was only enabled on email accounts, not firewalls or servers.
Underwriting & Risk Implications: Serves as the leading industry warning that inaccurate representations on underwriting security control questionnaires will void cyber coverage entirely.
Fishbowl Solutions, Inc. v. The Hanover Insurance Co.
Judicial Ruling & Findings: Threat actors compromised an executive email account and altered wire instructions sent to a customer. The court strictly enforced policy wording distinguishing between direct system manipulation and deceptive social engineering communications.
Underwriting & Risk Implications: Highlights the critical importance of reviewing separate sub-limits for social engineering and funds transfer fraud within cyber policies.