Insurers Failing to Provide Full Benefits under Cyber Policies

By David A. Gauntlett*

 

Introduction

Cyber policies have become an increasingly important part of the prudent business’s coverage package. This is, in large part, due to the rapidly increasing number of ransomware attacks. As with most policies, Cyber coverage is often misinterpreted by insurance companies hoping the policyholder lacks the knowledge or means to contest any shortchanging of benefits due.

Recent Illinois Case Seeks $5M in Unpaid Benefits

In Carnelian Point Holdings, L.P. v. Coalition Inc., et al., Case No. 2025 L 010267, Circuit Court of Cook County, Illinois, the court held that Carnelian Point Holdings LP, doing business as Crash Champions, adequately pleaded breach of contract and “vexatious and unreasonable delay” claims under Section 155 of the Illinois Insurance Code against Coalition Insurance Solutions Inc. (“CIS”), allowing those claims to proceed. The dispute arises from a May 2023 ransomware attack that caused business-interruption losses, for which Crash Champions sought coverage under a $10 million cyber policy. Although Coalition paid more than $5 million, Crash Champions alleged that approximately $4.89 million in additional covered losses remained unpaid. CIS argued that it could not be liable because the policy identified reinsurers that had agreed to bear specified percentages of the loss. Judge James E. Hanlon Jr. rejected that argument at the pleading stage, emphasizing that CIS itself signed the policy and that the signature page described the policy as the entire contract between the insurer and the insured. While the judge acknowledged that a signature alone cannot create obligations that the policy does not impose, he found the signature to be significant evidence that CIS was a contracting party.

The judge also found ambiguity in the policy’s description of who was obligated to pay covered losses. Although the policy allocated percentages of loss among reinsurers, it did not expressly state that those reinsurers, rather than CIS, were responsible for payment. Instead, the policy promised that “we” would pay covered losses, defining “we” as “the company providing this policy,” without clearly identifying that company. Judge Hanlon concluded that Crash Champions’ interpretation that “the company” meant the entity named on the policy, signature page, and claims mailbox was reasonable. CIS’s own conduct also undermined its argument that it had no contractual role: it accepted the claim, participated in the adjustment process through forensic accountants, and sought a release in its own name before making payments. Those actions did not conclusively establish contractual liability, but they made CIS’s contrary interpretation insufficiently clear to justify dismissal. Because CIS had not shown that it was a stranger to the policy, the Section 155 claim likewise survived and would rise or fall with the contract claim.

By contrast, Judge Hanlon dismissed all claims against Coalition Inc. because the complaint did not identify any policy that Coalition Inc. itself signed, any promise it made, or any loss it agreed to bear. He also dismissed Crash Champions’ consumer-fraud claim because the alleged damages (delayed access to insurance proceeds and resulting cash-flow and operational problems) were merely the contractual losses caused by the alleged failure to pay, rather than independent damages caused by deception. The dismissals were without prejudice, giving Crash Champions an opportunity to amend and, for any renewed consumer-fraud claim, identify specific non-contract damages caused by the alleged deceptive conduct.

The Growing Expense and Risk of Ransomware 

Ransomware addresses a breach in network security through viruses or other malware to infect a computer system. Even more dangerous is the manner in which malware can manipulate computer functionality. Ransomware attacks extort monies from businesses and typically demand payment in forms of cryptocurrency, making attacks more difficult to track.

Insurers often deny coverage to claims results from ransomware attacks especially where numerous claims can be involved such as system damages, reputation loss, business interruption, data breach and loss, as well as cyber extortion loss.[1]

For example, a Connecticut district court, in New England Sys. v Citizens Ins. Co. of Am.[2] determined that in denying coverage to New England for business interruption claims after a ransomware attack, Citizens engaged in bad faith under the policy provision “Cyber Business Interruption and Extra Expense.” The court reasoned that “Citizens intentionally misrepresented pertinent policy provisions when it allowed NSI to undertake self-repair work without disclosing that Citizens knew it would consider NSI ineligible for business-interruption coverage if it performed such work . . . [and] engaged in no investigation of its claims whatsoever.”[3]

Insurers have also attempted to deny coverage to claims resulting from ransomware attacks by applying the “war and terrorism” exclusion contending that ransomware attacks are forms of cyber terrorism that fall within the scope of this exclusion.[4] For example, in Merck & Co., Inc. v. Ace Am. Ins. Co.,[5] a New Jersey court analyzed Ace’s denial of coverage for Merck & Co.’s claims resulting from a NotPetya ransomware attack in 2017. Ace contended that Merck & Co.’s claims fall within the scope of the policy’s war-risk exclusionary clause and relied on a broad definition of “terrorism” and terms related to terrorism to deny coverage.[6] In contrast, Merck asserted that the “all risks” policy covers all risks to property damage “including destruction, distortion, or corruption of computer data, coding, program, or software.”[7]

The court first noted that no case in the country had determined that a “war and terrorism” exclusion had been applied to facts remotely similar to those at issue.[8] The court went on to conclude that the term “act of war” in the war-risk exclusion as applied to cyber attacks is ambiguous and applying it to the NotPetya event would disappoint the reasonable expectations of Merck.[9] The court properly noted that the onus is on the insurer to update its policy language if it wishes to exclude newly developed threats.[10]

 

“Business Interruption Loss” Is Naturally Implicated by Ransomware Attacks

Given the reliance that most modern businesses have on access to their computer systems and online networks, a ransomware attack often results in a crippling interruption for a business that prevents any ordinary operations. Luckily, cyber policies typically include coverage for “Business Interruption Loss,” defined as “Income Loss and Extra Expense incurred by the Insured Organization during the Period of Recovery which exceeds the Waiting Period, due to an Interruption of Service as a result of a Network Security Incident.”

Despite this clear path to coverage, insurers are often quick to deny claims by reflex. The recently filed case of DeVaughn James, LLC v. Palomar Excess and Surplus Ins. Co.[11] is illustrative. There, the insured was a “paperless” law firm where “client files, case documentation, legal work, and communications are maintained, processed, and transmitted digitally.”[12] Because the law firm operates in that manner, a ransomware attack compromised many of the firm’s critical systems.

According to the complaint, “they were essentially unusable from Monday, August 4, 2025, through Friday, August 8, 2025. Plaintiff’s computer system was only partially operational on Monday, August 11 and Tuesday, August 12, 2025.”[13] Despite the firm’s complete shutdown for an entire week and reduced capacity for two additional days, the insurer maintained that the firm “suffered absolutely no loss of profit.”[14]

Conclusion

With the always increasing reliance on computer technology for day-to-day business functions and cloud-based storage for recordkeeping, ransomware attacks represent a greater risk than ever. The only reasonable response to this simple reality is securing appropriate cyber coverage to mitigate the harm of any such incident. These policies offer robust coverage, though insurers will often deny claims no matter how clearly covered they are. In such cases, coverage counsel can assist in securing the policy benefits you are owed, including potential damages for bad faith if the insurer’s conduct meets the jurisdictional standard.

*David A. Gauntlett is a principal of Gauntlett Law and represents policyholders in insurance coverage disputes regarding intellectual property, antitrust, and business tort claims, as well as in the underlying actions. Mr. Gauntlett can be reached at (949) 514-5662 or dag@gauntlettlaw.com. For more information, visit Gauntlett Law at www.gauntlettlaw.com.

[1] See National Ink & Stitch, LLC v. State Auto Prop. & Cas. Ins. Co., 435 F. Supp. 3d 679, 684–85 (D. Md. 2020) (“[A]lthough the intended use of the software might sever it from the tangible form in which it was originally transmitted…Maryland courts would find physical damage to Plaintiff's computer software, despite its installation on Plaintiff's computer system, because the software was rendered entirely unusable by the ransomware attack.”)

[2] New England Sys. v. Citizens Ins. Co. of Am., No. 3:20-cv-01743 (JAM), 2021 U.S. Dist. LEXIS 93601 (D. Conn. May 17, 2021).

[3] Id. at *11.

[4] See Mondelēz Int’l, Inc. v. Zurich Am. Ins. Co., No. 2018-L-011008 (Ill. Cir. Ct. Oct. 10, 2018).

[5] Merck & Co. v. Ace Am. Ins. Co., 2021 N.J. Super. Unpub. LEXIS 4566.

[6] Id. at *2–3.

[7] Id. at *2.

[8] Id. at *13.

[9] Id.

[10] Id. at *14.

[11] DeVaughn James, LLC v. Palomar Excess and Surplus Ins. Co., Case No. 2:26-cv-02064 (D. Kan., filed Feb. 2, 2026).

[12] Complaint, ¶ 19.

[13] Complaint, ¶ 18.

[14] Complaint, ¶ 25.

Next
Next

Recent Minnesota Case Examines the Scope of Insureds’ Independent Counsel Rights