Security

Cyber-insurance shock: Zurich refuses to foot NotPetya ransomware clean-up bill – and claims it's 'an act of war'

Snack company client disagrees, sues for $100m

By Kieren McCarthy in San Francisco

48 SHARE

US snack food giant Mondelez is suing its insurance company for $100m after its claim for cleaning up a massive NotPetya ransomware infection was rejected – for being "an act of war" and therefore not covered under its policy.

Zurich American Insurance Company has refused to pay out on a Mondelez policy that explicitly stated it covered "all risks of physical loss or damage" as well as "physical loss or damage to electronic data, programs, or software, including loss or damage caused by the malicious introduction of a machine code or instruction."

The claim stems from the 2017 NotPetya cyberattack: a Windows-based piece of ransomware that encrypted a hard drive's file system table and prevented the system from booting. The code then demanded that a Bitcoin payment be made to regain access. Mondelez says it lost 1,700 servers and 24,000 laptops as a result of the malware.

Security experts – and the UK government – have pinned the blame for NotPetya on Russian hackers trying to damage the Ukrainian government, but the Russian government has formally denied any responsibility.

Insurance companies would probably have to shell out over $80bn as a result of the attack, warned one survey – more than 2012's Hurricane Sandy. Shipping giant Maersk said it had lost $300m as a result of the ransomware; FedEx said it has lost the same.

So, it's a no from us

After reviewing Mondelez's $100m claim, Zurich did what all insurance companies do and investigated with an eye to reducing the payout.

But despite offering an initial payment of $10m, the company then rejected the claim altogether claiming an exclusion for "hostile or warlike action in time of peace or war" by a "government or sovereign power."

In effect, it argued that the losses had been suffered through a Russian government hostile action – an act of war.

That is a very unusual position to take – Mondelez called it "unprecedented" in court papers – since the insurance company will be obliged to prove that it was in fact the Russian government that had carried out the attack as a hostile action. It is notoriously difficult to pin cyberattacks on specific groups, governments or organizations.

If Zurich does succeed in arguing in case in court and wins, it would have an immediate impact, causing all large companies to review their policies and most likely creating a new market in cyberattack insurance almost overnight. The case, lodged in Illinois court (2018-L-011008) is being watched keenly as a result. ®

Sign up to our NewsletterGet IT in your inbox daily

48 Comments

More from The Register

Swiss wheeze: Microsoft reseller titan SoftwareONE plots IPO on Zurich exchange

If that floats your boat

5G is Chinese firms' foot in the door to Europe as Oppo launches flagship Reno mobe in Zurich

Huawei was just the beginning

Google Research opens machine intelligence base in Zurich

'Mountain Views of a different kind' quips gros fromage

IBM Zurich wants to spice up your life with SALSA translation layer

Storage boffins get flash and disk dancing together

Cyberlaw wonks squint at NotPetya insurance smackdown: Should 'war exclusion' clauses apply to network hacks?

Analysis When UK and US said it was Russia, they weren't thinking of the litigators!

ProtonMail filters this into its junk folder: New claim it goes out of its way to help cops spy

Updated Secure comms biz says it simply follows the law – plus, there's always Tor

Cambridge boffins and Google unveil open-source OpenTitan chip – because you never know who you can trust

RISC-V-based blueprints available for all to freely use

Yorkshire bloke's Jolly Roger flag given the heave-ho after council receives one complaint

Scupper that, a real pirate would've manned the cannons

It's 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump

20 WebKit flaws among latest batch of bug fixes

Swiss cheesed off after Apple store iPhone does Samsung Galaxy Note 7 impersonation

Hard to remain neutral on this one

Whitepapers

Endpoint Protection Buyers Guide

According to the 2018 SANS Endpoint Security Survey, more than 80 percent of known breaches involve an endpoint.

Detecting cyber attacks as a small to medium business

If security by obscurity is no longer an option, and inaction is a risk in itself, what can smaller enterprises do to protect themselves? Endpoint Detection and Response (EDR) solutions can go a long way towards minimising the level of threat, but they need to be chosen and used in the right way.

Evolving Datacenters without Complexity

In this session, we’ll talk about how IT leaders are advancing the capabilities of their datacenters to rise to today’s challenges. Our guest speaker, Chris Bradford, Product Manager at DataStax will bring first-hand expertise to a discussion with The Register host Elena Perez.

Requirements-driven software development and quality management

A shift is underway in many development teams from traditional delivery models to Agile methods.