Security

Cyber-insurance shock: Zurich refuses to foot NotPetya ransomware clean-up bill – and claims it's 'an act of war'

Snack company client disagrees, sues for $100m


US snack food giant Mondelez is suing its insurance company for $100m after its claim for cleaning up a massive NotPetya ransomware infection was rejected – for being "an act of war" and therefore not covered under its policy.

Zurich American Insurance Company has refused to pay out on a Mondelez policy that explicitly stated it covered "all risks of physical loss or damage" as well as "physical loss or damage to electronic data, programs, or software, including loss or damage caused by the malicious introduction of a machine code or instruction."

The claim stems from the 2017 NotPetya cyberattack: a Windows-based piece of ransomware that encrypted a hard drive's file system table and prevented the system from booting. The code then demanded that a Bitcoin payment be made to regain access. Mondelez says it lost 1,700 servers and 24,000 laptops as a result of the malware.

Security experts – and the UK government – have pinned the blame for NotPetya on Russian hackers trying to damage the Ukrainian government, but the Russian government has formally denied any responsibility.

Insurance companies would probably have to shell out over $80bn as a result of the attack, warned one survey – more than 2012's Hurricane Sandy. Shipping giant Maersk said it had lost $300m as a result of the ransomware; FedEx said it has lost the same.

So, it's a no from us

After reviewing Mondelez's $100m claim, Zurich did what all insurance companies do and investigated with an eye to reducing the payout.

But despite offering an initial payment of $10m, the company then rejected the claim altogether claiming an exclusion for "hostile or warlike action in time of peace or war" by a "government or sovereign power."

In effect, it argued that the losses had been suffered through a Russian government hostile action – an act of war.

That is a very unusual position to take – Mondelez called it "unprecedented" in court papers – since the insurance company will be obliged to prove that it was in fact the Russian government that had carried out the attack as a hostile action. It is notoriously difficult to pin cyberattacks on specific groups, governments or organizations.

If Zurich does succeed in arguing in case in court and wins, it would have an immediate impact, causing all large companies to review their policies and most likely creating a new market in cyberattack insurance almost overnight. The case, lodged in Illinois court (2018-L-011008) is being watched keenly as a result. ®

Send us news
48 Comments

Farewell .NET 7, support ends in May - we hardly knew you

Standard Term Support means only 18 months before retirement

Amazon fined in Europe for screwing shoppers with underhand dark patterns

E-commerce titan to appeal sanction amounting to three hours of annual profit

Do not touch that computer. Not even while wearing gloves. It is a biohazard

PLUS: Dodging rats the size of cats while repairing chewed-through cabling

Microsoft rolls out safety tools for Azure AI. Hint: More models

Defenses against prompt injection, hallucination arrive as Feds eye ML risks

Hillary Clinton: 2024 will be 'ground zero' for AI election manipulation

2016 meddling was 'primitive' compared to what's ahead

Cloud server host Vultr rips user data ownership clause from ToS after web outrage

We know the average customer doesn't have a law degree, CEO tells us

HPE bakes LLMs into Aruba as AI inches closer to network takeover

But don't worry, the models are here to help summarize technical docs and answer your questions ... for now

Pressuring allies not to fulfill chip kit service contracts with China now official US policy

Xi Jinping warns 'no force' can stop country's science and tech progress

JetBrains keeps mum on 26 'security problems' fixed after Rapid7 spat

Vendor takes hardline approach to patch disclosure to new levels

University of Washington's Workday woes leave research grants in limbo

$340M finance upgrade still working out the kinks

FTX crypto-crook Sam Bankman-Fried gets 25 years in prison

Could have been worse: Prosecutors wanted decades more

Nvidia's newborn ChatRTX bot patched for security bugs

Flaws enable privilege escalation and remote code execution