22 ms·
Insurance Company Says NotPetya Is an “Act of War”, Refuses to Pay
- cenal 8y agoIf insurance stops paying out then companies will take data security more seriously. Their very existence will depend on it. Net win for society from my perspective.
- onion2k 8y agoSome might but many wouldn't though, because the risk of a problem occurring is still relatively low. No insurance just means it's worse if it does happen. The company would fail, resulting in a loss of service for their customers and a loss of jobs for all the staff. To use a good old car analogy, if car insurance stopped paying out people wouldn't all immediately become better drivers.
- closeparen 8y agoProduction reliability and user privacy are different goals. It’s true that a generally tighter ship will be better at both, but they are often in direct conflict. “Fail secure” is an outage waiting to happen.
- jimjimjim 8y agoWas there a declaration of war? Did their policy specifically mention 'cyber war'? what a steaming load. insurance companies trying to squirm out of paying something is as certain as the sun rising.
- patio11 8y agoI was offered a rider on my last business insurance policy, for about a 5% premium increase. It was labeled the Terrorism Rider but the legal code was war, acts of state-sponsored violence, etc etc. If you don’t buy that rider, and someone drops a bomb on your building, your claim falls into an exclusion. These exclusions were largely inserted into new policies for risk management after 9/11. If you’re negotiating a 9 figure insurance policy, you have lawyers who read the thing and can debate the issue with the insurance company’s lawyers if there is a dispute over exactly what the bespoke language you signed meant. I’m not unsympathetic to the insurance company here. The intent of this language is “We did not sign up to take on Russia. We are willing to do that, but it isn’t free.” If somebody doesn’t negotiate for that, well, you pays your money and you takes your chances.
- mirimir 8y agoI remember "war not covered" language from home insurance policies, going way back before 9/11. Also exclusion of flood damage, and there are special FEMA-backed policies for that.
- posterboy 8y agoThat's fine, except that the insurer has to prove the state-sponsorship beyond reasonable doubt, no? Exceptional claims ...
- patio11 8y ago“The US government has publicly claimed this was a hostile act by Russia” wins that argument, trivially, in a US courtroom. And it will be a civil trial; the standard will be “preponderance of evidence.”
- posterboy 8y agoI hope you mean officially, because e.g. a public fox news proclamation falls under hear say, IMHO. So much for the court as last instance of truth. So what, do they have to go to the international war courts where genocide is prosecuted instead, to rectify the unfair situation in which the claimant is caught between two hard places and the rock that is burden of proof?
- detaro 8y agoYes, as the article says, that's an official white house statement: https://www.whitehouse.gov/briefings-statements/statement-press-secretary-25/ https://www.whitehouse.gov/briefings-statements/statement-pr...
- posterboy 8y agoBy the way, to get a trial going, you only have to raise reasonable doubt. Getting beyond reasonable doubt is the problem.
- Animats 8y agoSource article from The Register.[1] [1] https://www.theregister.co.uk/2019/01/11/notpetya_insurance_claim/ https://www.theregister.co.uk/2019/01/11/notpetya_insurance_...
- gesman 8y agoIt’s interesting that insurance Co didn’t point to an absence of proper inclusion clause. They tried to find exclusions that may help them to pull the fast one on a customer. Which means the policy wording clearly matched the covered event.
- patio11 8y agoThe insurance company’s argument is “When we gave your lawyers a bespoke contract that said ‘Irrespective of whether a loss would otherwise be covered or not, we will not pay any claim which...’, what precisely did you think we meant?” They quote the language in the policy and quote the national security apparatus as having made a determination that this was hostile action by a foreign government or their affiliates. Contractual disputes are often substantially less well-grounded in assertable facts than this one.
- lota-putty 8y agoInsurance is like a `bottomless wishing-well`, demands regular offerings but return favours during unforeseen emergencies not guaranteed.
- Scoundreller 8y agoThis is why I try to avoid insurance policies wherever possible. It’s still hard to argue with people questioning why I don’t buy insurance for my $25k or so of household contents in a relatively secure building. I don’t care how cheap the policy is, I’m assuming they’re charging more than they payout on average, and I lock my doors consistently.
- sesutton 8y ago>I don’t care how cheap the policy is, I’m assuming they’re charging more than they payout on average. How would an insurance company stay in business if it were any other way?
- maxerickson 8y agoThey make money investing the float (the money they have received but not yet paid out).
- seanlinehan 8y agoInsurance companies make money by investing the premiums. It's possible for an insurance company to make a profit from investment even if they had unprofitable underwriting. From Warren Buffet: > Insurers receive premiums upfront and pay claims later. ... This collect-now, pay-later model leaves us holding large sums -- money we call "float" -- that will eventually go to others. Meanwhile, we get to invest this float for Berkshire's benefit. ... > If premiums exceed the total of expenses and eventual losses, we register an underwriting profit that adds to the investment income produced from the float. This combination allows us to enjoy the use of free money -- and, better yet, get paid for holding it. Alas, the hope of this happy result attracts intense competition, so vigorous in most years as to cause the P/C industry as a whole to operate at a significant underwriting loss. This loss, in effect, is what the industry pays to hold its float. Usually this cost is fairly low, but in some catastrophe-ridden years the cost from underwriting losses more than eats up the income derived from use of float. ...
- lotsofpulp 8y ago
- tudorconstantin 8y agoI wonder how that insurance company expects to continue business. If they don't pay in case of damage, why would anyone buy insurance from them?
- eps 8y agoThat's Zurich, an insurance behemoth, almost half a trillion in assets.
- romanovcode 8y agoI can see why now. Getting money and not paying claims
- patio11 8y agoThe thing you’re buying from an insurance company is “Can you pay me in case of a covered claim?” not “Can you pay me if I need money because something bad happened?” If you buy medical insurance and file a claim because your house burned down, expect not to get money. If you file a claim which falls into the policy exclusions which are briefed at excruciating length and which you had your lawyers review because you are a professional risk manager and know this policy’s value to you is potentially nine figures, expect to not get money. The reason companies with very intelligent risk managers keep paying Zurich money is that Zurich reliably pays out covered claims, as you would expect from a highly-regulated entity. HN’s incredulity about insurance companies routinely paying out claims staggers the imagination. They’re highly regulated publicly traded companies which denominated claims expenses in (in this case) billions of dollars; that isn’t code for “Psych we actually just bought mountains of cocaine and would have successfully hoodwinked all counterparties, regulators, and courts but for the diligence of Internet commenters.”
- chiph 8y agoThe debate here is whether it was a covered claim or not. A reasonable person would certainly think that a policy sold as cyber insurance would cover a cyber attack. And presumably a large multinational like Mondelez would have had the policy reviewed by their legal department before signing and paying the premiums. So far as regulations - in the US standard types of policies (such as auto, home, etc.) are regulated by the states not the feds. A policy that isn't one of those likely has very few regulations around it. In which case the policy language (aka the contract) governs the relationship. If Zurich wanted to limit the total damages, they should have put that in the policy. And then resell some of that risk to a reinsuror. This is going to have to be settled in the courts. But in the meantime, I would be hesitant to purchase any cyber insurance from Zurich (or any other insuror) because of the uncertainty that a claim would be paid that this action introduces.
- ldp01 8y agoI wonder if you can get insurance against insurance companies not paying out?
- wjnc 8y agoYup,that's called legal insurance and is often quite an affordable backstop, at least in the EU. Pro-tip is to get yours at another supplier than your regular insurance to best align incentives. In things like consumer conflicts I've never had to use my legal insurance, just announcing that you'll get them involved usually is met with some kind of compromise.
- ascar 8y agoAbsolutely second the benefits of legal insurance. It clearly shows others you are not afraid to fight this out as the costs are covered. The free legal counseling hotline my insurance provides helps me at least twice a year with the right approach to tackle problems. And they have such a large network of lawyers that I'm always speaking to a specialist in my problem's area. The combination of legal counseling and the simple fact that I had legal insurance helped me compromising in my favor or outright win all legal disputes I had since buying the insurance without actually using it. Legal insurance is also probably a very lucrative insurance model. They avoid a lot of cases for their customers by their pure display of power and can advise their clients about which battles are worth fighting for in the first place. Furthermore (afaik) the losing side pays most of the legal fees of both parties.
- roel_v 8y agoThat's not the same. What you are talking about is an 'insurance' where you, when you get into legal trouble, are reimbursed for (some of) your legal costs. That's not what the GP meant.
- deleted 8y ago[deleted]
- wjnc 8y agoWhat the GP meant is literally quite strange. You get reimbursed re conditions of the contract, period. If the insurer doesn't pay it's either a legally correct action or not. If legally correct you get what you paid for. If incorrect you need legal recourse. The only type of insurance possible against an insurer not paying is legal insurance. Otherwise you are asking for an insurance for you not understanding the terms and conditions. That's typical.
- bredren 8y agoIt takes two to tango. If a cyber war is ongoing, then I think the insurance company should cite retaliatory action in the war as evidence. From what I can tell western governments do not generally publicize any specifics of effective cyber operations. So i wonder if this puts insurance companies in a position where they benefit from classified operations are outed to bolster the case that this was indeed an act of war.
- NeedMoreTea 8y agoWar, hostilities, civil unrest and acts of god have been standard exclusions in insurance policies, well, forever. I'm not sure why this would be any different, but for the "cyber" that gives HN something to talk about. After all, a bloodless coup or invasion would be an act of war without retaliation. Normal civil standards of proof would be all that's needed.
- bredren 8y agoThose would be but there is clear precedent those are war-like actions. There is not president that ransomware is cyberwarfare.
- tgsovlerkhgsel 8y agoI thought that retaliatory action would be a good indicator, so I took a look, and I'd say this supports Zurich's decision: https://techcrunch.com/2018/03/15/russian-sanctions-treasury-ira-notpetya/ https://techcrunch.com/2018/03/15/russian-sanctions-treasury... Others cited the exclusion to be worded as "hostile or warlike action in time of peace or war", further tilting the scales in the insurance's favor.
- bredren 8y agoThe sanctions as retaliatory? I’d agree the are but I was thinking more of a cyber counter offensive.
- wjnc 8y agoThis would be a massively interesting suit, if fought out to conclusion. Looking for a proper definition of war, you might even go back to the Hague Conventions or some historical precedents in common law. Probably the terms and conditions do not further specify 'war', let alone 'cyber war'. But if it would be an easy case, the insurer wouldn't take on Mendelez, unless perhaps as long shot to prevent ruin.
- mikkom 8y agoGood luck proving conclusively in court that russia was behind the software
- ceejayoz 8y agoIn civil suits, the standard is a preponderance of the evidence. That makes this pretty hard to surmount: > Zurich American Insurance Company points to the official statements of national security officials from the UK, Canadian and Australian governments, all of which blamed Russia for the cyber attack in February 2018. Even the White House in the United States said the cyber attack was part of Kremlin efforts to destabilize the Ukrainian government.
- aritmo 8y agoThat's a sleazy insurance company. They use a lame excuse to avoid paying.
- ascar 8y ago> "hostile or warlike action in time of peace or war" A lot of comments jump on the war and cyber war definitions, but the article states the exclusion is based on a "hostile or warlike action", which is a much looser definition. Based on the announcement of multiple governments that this attack is from Russian origin this exclusion might very well be justified.
- OkGoDoIt 8y agoCouldn’t most hacking attempts be defined as “hostile actions”? And the second part “at a time of peace or war” effectively means all the time. Seems like an extremely broad exclusion.
- ascar 8y agoYea, I thought that too. I imagine either the "or warlike" part or additional text that was not quoted narrows it down to state actors or state-like actors (e.g. terror groups like ISIS or al-Qaida). Would still be a very broad definition.
- mannykannot 8y agoI have no idea how the law would interpret it, but while 'hostile warlike act' might narrow the scope as you suggest, 'hostile or warlike act' would seem to widen the scope to any hostile act, warlike or not. (Are there any non-hostile warlike acts? Accidents such as so-called 'friendly fire' incidents might fit...)
- int_19h 8y agoI think the implication here is that it must be carried out by a state agent.
- mcguire 8y agoThere seem like two possible outcomes: 1. Insurance that covers nation-backed cyber attacks becomes very expensive, or 2. Countries start treating nation-backed cyber attacks as actual acts of war.
- taspeotis 8y agoI would kind of expect the argument about not paying out to be one of negligence on behalf of Mondelez. NotPetya uses the EternalBlue exploit which Microsoft patched in March 2017, NotPetya was late June 2017. Don't install security patches on 1,700 servers and 24,000 laptops for four months? Don't get an insurance payout.
- zapdrive 8y agoI'm sure negligence is covered under insurance, that's why Zurich made a claim of "cyber war", which is harder to prove than negligence. Also if negligence wasn't covered, almost everything can be claimed as negligence. For example, fire started due to electric short circuit: negligence, you should have got everything inspected every x months/years. Theft: negligence, you should have x number of security guards. You see where I'm going?
- thaumasiotes 8y agoIn my mind, the usual handling of negligence is that your insurance contract may specify steps that you're required to take in order for any eventual claim to be valid. For example, a policy insuring your car against theft may specify that you keep your car parked in the garage and not on the street. If your car is stolen off the street in front of your house, you're not going to get anything. Conceptually, such a clause represents you guaranteeing a particular standard of non-negligence in exchange for lower premiums.
- tomjen3 8y agoSure, but not in the right direction. They wouldn't have an argument for negligence because of a short circuit if you followed the official rules for inspections.
- cwilkes 8y agoThat’s an interesting point. Just as there are financial auditors for investors do cyber insurance companies actually do any auditing of their clients? It would be in both of their best interests to do so. Mondelez would see that they need to get their security house in order and Zurich would gain some expertise in what to look for in their clients.
- bertil 8y agoI’m curious how much the insurance thinking was: if we pay this, more companies will maintain bad security, pay bribes and we’ll be left to foot the bill. In addition to more victims, the second compounding effect of this would be that giving money to hacker groups means they would become bolder. That might even mean they’d potentially blur the line from State-sponsored to something that outgrows even the authority of a (rogue) State.
- dgzl 8y agoInsurance companies live in the weird realm of customer service up front, and financial defense when the whistle is blown.
- DevX101 8y agoCompanies won't take security seriously until there are real costs to losing customer data. Right now, they can just send out an apologetic press release after getting attacked due to their shoddy security and that's it.
- retrogradeorbit 8y agoAnd that's the last time anyone buys cyber insurance from Zurich. What's the point of cyber insurance that doesn't cover ransom wear? Just a useless waste of money.
- detaro 8y agoThey aren't not covering ransomware. I suspect future buyers are going to re-evaluate if they really don't need coverage against being casualties of nation-state attacks though.
- closeparen 8y agoInsurance against war related damage is called reparations.
- detaro 8y agoNot really, no. It's got little to do with the idea of insurance.
- closeparen 8y agoProperty insurance industry works with the security community to develop and enforce standards for security operations, safes, locks, alarm systems, etc. that reduce theft, and employs investigators to recover stolen high-value goods. Auto insurance industry works with the automakers and regulators to develop and enforce standards for crash safety, airbags, crumple zones, collision avoidance systems, etc. and employs litigators to recover damages from the at-fault party. Insurance companies aren't just professional gamblers. They are risk managers. You pay them to deal with the nitty gritty of risk mitigation in whatever domain because it's not your speciality. How are you going to manage the risk of enemy damage in war? You're going to wield more violence than the threat, and seize its assets to make yourself whole. Instead of settlement or recovery, we call it reparations.
- 8y ago
- stevespang 8y agoObviously Zurich took the lower road, deciding that litigation would be less costly than an honest payout. I hope it's a jury trial and the jury puts Zurich out of business, that'll send a message.
- qaq 8y agoSo what is the standard of evidence for something like this? The fact that say top security outfits did attribution to APT-blah or APT some blahBear and there is some level of confidence that the groups might be state actors is it really enough?
- toss1 8y agoNot entirely surprising that insurance company is attributing this to an Act of War. * Russia is actively pursuing an Active Measures (активные мероприятия [1]) political war against the west * Russian companies & persons charged by Mueller have actively used the defense in filing that their actions were Acts of War, and so not illegal. These defense claims have not yet been ruled upon, AFAIK. * The Russian govt, former KGB organization, Oligarchs, Russian Mob, and hacker community have effectively morphed into a single operation entity. Nevertheless, it is a bit of a stretch to consider a specific hacking event as part of the Active Measures war. Not that it is surprising that the insurance company tries it. They'll st least delay any payments. This may, interestingly, raise the stakes on any cooperation with such operations (e.g., being a funds conduit, renting out a botnet to deploy the malware) from standard criminal conspiracy charges right up to treason. Not sure if it will play out that way, but I wouldn't want to be the one testing the prosecutors' discretion, or the inclination of the NatSec organizations to get involved. Totally changes the risk profile of getting involved for those inclined to play around the edges. [1] https://en.wikipedia.org/wiki/Active_measures https://en.wikipedia.org/wiki/Active_measures
- jopsen 8y agoWhy should "act of war" not be covered? If I'm going broke because of a war, why shouldn't my insurance company? Similar, with natural disasters, those should be covered by default -- insurance companies can easily spread the risk geographically.. These exceptions feels like legacy from the "good" old days when wars were common and globalization limited.
- CPLX 8y agoBecause insurance companies are generally in the business of insuring unsystemic risk. The entire model breaks down in cases of systemic risk, unless that has been accounted for and dealt with. Which is why it's a major element of insurance policies.
- daniel-cussen 8y agoIn Chile the insurance companies have fine print saying they won't cover injuries resulting from paramilitary activities (reasonably sensible, OK) or anything nuclear, right down to a nuclear bomb.
- jhbadger 8y agoEven in the US it is common for home insurance to not cover nuclear war -- mine specifically says it doesn't for example. Although I suspect not getting an insurance settlement would be the least of my concerns in that event.
- jopsen 8y agoToday you can insure against systemic risk through re-insursnce in other countries.. this should be a benefit from globalization, right? So why we keep allowing insurance companies to make these exclusions? If there is systemic risks to the entire planet, then an insurance company should just go bankrupt.. I mean the survival of a company isn't very important if we talking about the apocalypse :)
- edanm 8y ago
- mark_l_watson 8y agoI wonder what the long tail costs are for not paying the claim? If I had any insurance policies with this company I would cancel and look elsewhere. The insurance company must have modeled both scenarios.
- deleted 8y ago[deleted]
- mnm1 8y agoIf they can't pay out in a case like this, they shouldn't be in business. I hope the affected insureds sue this scumbag insurance company into the bankruptcy it deserves. And if the whole cyber attack insurance industry goes belly up, it sounds like a win for society: maybe these other idiot companies will start to take security seriously rather than just trying to collect money for their insurance companies.
- shard972 8y agoJust subpoena the intel agencies? Just because they haven't released the evidence publicly doesn't mean it wouldn't seem reasonable for the intel agencies to assist the case.