Ransomware is a type of malware that prevents users from accessing their systems or files absent payment of a ransom, and the attacks have long since stopped discriminating. When Peter Halprin and I examined this landscape in the Journal of Internet Law, 2020 had seen a seven-fold rise in ransomware attacks over the prior year, with reported strikes on school districts, hospitals, and even institutions working on COVID vaccines. For businesses, government entities, and other institutions facing such attacks, insurance may be available to help them through the event and recover income losses. But the coverage is only as good as the insured's understanding of its exceptions and exclusions — and in ransomware, the exclusions are where the disputes live.

First-party, third-party, and the endorsement trap

Start with the structure of the product. Insurance contracts generally divide into first-party coverage, which pertains to loss or damage sustained by the insured to its own property, and third-party coverage, where the insurer's duty to defend and pay runs to claims others bring against the insured. A ransomware event can implicate both at once — the insured's own locked systems and lost income on one side, and the customers, banks, and regulators affected by the breach on the other. Effective cyber insurance therefore has to cover three key types of risk: network security (first party), errors and omissions (third party), and privacy (third party). That is why many stand-alone cyber policies are a hybrid of first- and third-party coverage.

The cheaper alternative — a cyber endorsement bolted onto an existing CGL, professional liability, or property policy — is where insureds most often discover a gap at the worst moment. Camp's Grocery, Inc. v. State Farm is the cautionary tale. After a data breach compromised customer card information, three credit unions sued the Alabama grocer, which turned to the cyber endorsements on its property and casualty policy for defense and indemnity. The federal court held that the endorsement's promise to pay for “accidental direct loss” unambiguously provided first-party coverage only — it imposed no duty to defend the credit unions' third-party claims. The lesson: an endorsement can be a reasonable, lower-cost approach for a company whose primary exposure really is first-party (breach notification, forensics, remediation), but a company that assumes an endorsement works like a stand-alone policy will most likely be left with significant gaps. Cyber insurance is never one size fits all, and with endorsements the devil is in the details.

The war exclusion after NotPetya

One might not expect the “war” exclusion in a property or cyber policy to have any bearing on a malware claim. The issue came into prominence in 2018, when Mondelez International sued Zurich American Insurance Company after suffering losses from the NotPetya malware — an attack whose goal, as reporting at the time put it, was purely destructive: it irreversibly encrypted machines' master boot records, and no key even existed to restore what any ransom payment might have bought. Zurich denied the claim based on an exclusion for “hostile or warlike action.”

The case law counsels against stretching that language. In Universal Cable Productions, Inc. v. Atlantic Specialty Insurance Co., 929 F.3d 1143 (9th Cir. 2019), the Ninth Circuit — construing a war exclusion outside the cyber context — held that “war” in the insurance context is limited to hostilities between sovereigns or entities essentially like governments, and noted the leading treatises' warning that an insurer invoking war and sovereign-act exclusions faces steep factual, legal, and political hurdles. That definitional problem is compounded in cyberspace, where the line between cybercrime, espionage, terrorism, and warfare is genuinely blurry, and where attribution — the thing the exclusion turns on — is often non-existent. Policyholders, brokers, CFOs, in-house counsel, and risk managers should pay close attention to the wording of war exclusions before the claim, not after.

Paying a ransom does not guarantee the return of access to data, it emboldens the attackers — and if the payee is sanctioned, it can violate U.S. law on a strict-liability basis.

The risks of paying

However tempting, paying a ransom is not recommended, for three reasons. First, payment does not guarantee the return of access to data. Second, it emboldens and enables cybercriminals to continue launching attacks. Third, payment can itself be illegal. On October 1, 2020, the U.S. Treasury's Office of Foreign Assets Control issued its Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments. U.S. persons are generally prohibited from transacting with individuals or entities on OFAC's Specially Designated Nationals and Blocked Persons List or covered by country embargoes, under the International Emergency Economic Powers Act and the Trading with the Enemy Act — and facilitating a payment by someone else can be a violation too.

The sharpest edge is strict liability: OFAC can impose civil penalties even where the payer did not know, and had no reason to know, that it was engaging in a prohibited transaction. The practical protocol follows directly. (1) Before any payment is considered, check whether the criminal entity appears on OFAC's lists. (2) Financial institutions and intermediaries should maintain risk-based sanctions-compliance programs that specifically account for ransomware payments touching an SDN or embargoed jurisdiction. (3) Practice caution and cooperate with law enforcement during and after the attack — cooperation is protective in any later enforcement posture. (4) Treat the decision as a cross-functional one: the risk can be mitigated when corporate finance, insurance, legal, operational, and technical professionals work together closely, rather than leaving the decision to whoever is holding the incident bridge line at 2 a.m.

What this means for the coverage fight

Every one of these pressure points — first-party versus third-party characterization, endorsement scope, the war exclusion, the propriety of a payment — is a technical question wrapped in policy language. The disputes turn on what the forensic record shows about what the malware did, who sent it, and what the insured's systems lost. Coverage fights of that shape are well suited to resolution by a neutral who can read both the policy and the record; the alternative is years of motion practice over facts that a technically fluent process could establish in weeks. Read the policy before the incident, question the exclusions before renewal, and check the sanctions lists before anyone pays anything. The time to discover what your cyber insurance actually covers is never the week of the attack.

Adapted from “Placing Ransomware in Context and Avoiding Liability for Paying Ransomware Claims,” Journal of Internet Law (2021), co-authored with Peter A. Halprin, and “Cyber Endorsements: Proceed with Caution” (2017).