Narrow Cyber Coverage Provision Proves Fatal for Law Firm’s Claim

In Gore, Kilpatrick & Dambrino, PLLC v. Spinnaker Ins. Co., No. 4:25-CV-107-DMB-DAS, 2026 U.S. Dist. LEXIS 69567 (N.D. Miss. Mar. 31, 2026), the law firm insured sought coverage after it was defrauded of $158k. A man purporting to be named David Casteel engaged the Gore firm purporting to be a representative of Brooks Machinery, Inc. He sought to secure the firm’s services in collecting a debt owed by Mid-Delta Equipment to Brooks Machinery. Shortly after executing a letter of engagement, the firm received correspondence allegedly from Mid-Delta that included a check for $158k. “David Casteel” instructed the firm to deposit the check, collect its fee from the amount deposited, and wire the balance to him. The firm complied with wiring the money, but the check bounced, leaving the firm at a loss of the wired sum. Upon investigation, it turned out the real David Casteel never contacted the firm and had never done business with Mid-Delta.

The firm filed a claim with Spinnaker Insurance Company (“Spinnaker”) seeking recovery of the funds as a loss resulting from a “Social Engineering Incident.” The policy defined that term as “the intentional misleading of an Insured to transfer Money . . . resulting directly from the Named Insured's employee's good faith reliance upon an instruction transmitted via email, purporting to be from . . . a natural person or entity who exchanges, or is under contract to exchange, goods or services with the Named Insured for a fee . . . but which contained a fraudulent and material misrepresentation and was sent by an imposter.” Id. at 4–5.

The court’s ruling highlighted the gaping omission in this coverage provision:

Here, the real Casteel is not a person who exchanges or is under contract to exchange goods or services with Gore for a fee, because he is not and has never been Gore's client. Accordingly, that the Imposter purported to be Casteel when he gave the instruction to transfer funds does not bring the conduct within the definition of a Social Engineering Incident. Though Gore characterizes the Imposter as its client because the Imposter signed and returned the fee agreement, the Social Engineering Incident provision cannot be reasonably interpreted to cover the fraudulent transaction alleged in the complaint because the instruction to transfer money cannot have been sent by an imposter purporting to be a client if the individual giving the instruction is the client. Id. at 11–12. In short, the policy only covers incidents in which an imposter defrauds the insured based on a legitimate, pre-existing relationship. It offers no protection where, as in the Gore case, the relationship is fraudulent from the start. The court’s interpretation of the policy’s language is difficult to dispute. Thus, this case may have been better formatted a broker negligence claim for failure to secure a policy that provides adequate protection. 

Previous
Previous

Massachusetts Court Properly Applies Narrow Construction to Exclusion

Next
Next

Law Firms Increasingly Targeted by Cyber Attacks