Gaps in Grocer's Insurance Program Jeopardize Coverage for Cyber Breach
Time 3 Minute Read
Categories: Cyber

As reported in the Hunton Retail Law Resource blog, a federal judge in Alabama ruled Tuesday that a grocer could not rely on its legacy business insurance policies – including an "electronic data" coverage extension – to protect against third-party claims after customer data was compromised by a point-of-sale cyberattack. The decision in Camp's Grocery, Inc. v. State Farm Fire and Casualty Company is yet another reminder to policyholders to ensure that their cyber security programs include both adequate cyber security safeguards and appropriate first-party and third-party cyber/crime insurance coverages. Failure to maintain either may jeopardize coverage for resulting cyber losses.

In Camp's Grocery, three credit unions sued a Piggly Wiggly franchisee after they suffered losses on their cardholders' accounts when hackers stole card information from the grocer's computer network. The losses included costs associated with the reissuance of cards, reimbursement of their customers for fraud losses, lost interest and transaction fees, lost customers, diminished good will, and administrative expenses associated with investigating, correcting, and preventing fraud. Camp's had a business insurance package through State Farm, including property and liability coverages and an inland marine computer property form which covered, among other things, "accidental direct loss" to "electronic data," including some types of customer data. Camp's sought coverage under the policy's third-party liability coverage and the inland marine form.

The court rejected Camp's argument that the inland marine form would cover the credit unions' suit, holding that the form only provided "first-party" coverage for loss or damage to the insured itself. In support, the court relied on the policy language (which required "direct . . . loss to" the insured), and the absence in the inland marine form of any explicit duty to defend or indemnify. The court also rejected Camp's argument that the credit unions' replacement of the physical debit cards constituted third-party "property damage" under Camp's business liability form. The court held that the underlying suit did not allege physical harm or damage to the cards themselves, but rather compromise of "intangible electronic data" on the cards – which was not "physical damage" and also fell squarely within the "electronic data" exclusion in the third-party coverage form.

Camp's Grocery is another example of the gaps that can exist in traditional "legacy" coverages when it comes to cyber-type losses. The decision is also an example of the gaps in endorsements that purport to cover those losses. As we have seen through our cyber policy review and counseling program, these tacked-on forms rarely cover the range of hardware, software, data and risks needed to address policyholders' basic cyber liabilities. Policyholders should therefore consult with knowledgeable cyber insurance coverage professionals to ensure that their insurance programs are adequately drafted and adequately tailored to protect against their particular cyber risks and exposures.

  • Partner

    Mike is a Legal 500 and Chambers USA-ranked lawyer with more than 25 years of experience litigating insurance disputes and advising clients on insurance coverage matters.

    Mike Levine is a partner in the firm’s Washington, DC ...

You May Also Be Interested In

Time 5 Minute Read

Theft in the cargo industry has skyrocketed in recent years. In the first half of 2024, cargo thefts rose 49 percent and the average loss per shipment by 83 percent. Given these dramatic spikes in cargo theft, policyholders whose operations rely on the safe transportation and trade of cargo should take steps to mitigate against the potential losses of a cargo-theft event. We discuss below the insurance coverage options available to policyholders that can help protect against the risks and losses associated with cargo-related theft if such a loss occurs.

Time 4 Minute Read

Last week, just before Hurricane Milton made landfall, Florida state officials issued an emergency decree to all licensed insurance adjusters in the state to protect homeowners against “unfair and deceptive acts” and “post-storm fraud” by insurance carriers. According to The Washington Post, the Florida Department of Financial Services is requiring that all claim adjusters provide an explanation for each change they make to a consumer’s loss estimate, document those changes, and retain all versions of the estimate and identify who made those revisions. When processing claims, adjusters must also use an electronic estimating system that provides an itemized report of all damage, as well as labor, materials, equipment and supplies. Those costs should be consistent with what a contractor or a repair company in that particular area would charge.

Time 3 Minute Read

Trading on New Zealand’s stock exchange was disrupted last week, following four straight days of repeated cyberattacks that resulted in outages affecting debt, equities, and derivatives markets.  The DDoS attack, which is said to have originated offshore, is allegedly part of a global extortion scheme that has also targeted companies like PayPal and Venmo.  With this type of cyberattack becoming only more common and sophisticated, it is vital for policyholders to focus on the host of available insurance coverage options to protect against and maximize their insurance recovery following losses from a cyberattack.

Time 4 Minute Read

On December 9th, the Eleventh Circuit held that a loss of over $1.7 million to scammers was covered under a commercial crime insurance policy’s fraudulent instruction provision.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page