Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup
- Reference: 1667374145
- News link: https://www.theregister.co.uk/2022/11/02/mondelez_zurich_notpetya_settlement/
- Source link:
The years-long legal battle over the claim has been closely watched by cyber-insurance and legal experts. It has helped fuel an ongoing debate over what constitutes an act of war — which even in cyberspace could invalidate an insurance claim – and whether insurance companies should pay damages caused by network intrusions supported or organized by nation states.
Mondelez, which owns Oreo cookies, Sour Patch Kids candy, Ritz crackers, and dozens of other brands, declined to comment on the settlement. A Zurich American spokesperson, however, told us "the parties have mutually resolved the matter." Details of the deal have not been disclosed.
[1]
While this makes it difficult to comment on, "I would be willing to bet a lot that, especially the carrier, did not want to publicly reveal what their settlement position is on the applicability of war exclusions, and particularly both sides wanted to avoid a judge making a definitive ruling on that," said Bryan Cunningham, an attorney and advisory council member at Theon Technology.
[2]
[3]
"If a judge, or five or six judges in different jurisdictions were to actually start saying if a cyberattack can reasonably be attributed to a nation state and therefore be excluded, that would upend the entire cyber-insurance ecosystem and make it almost impossible to get meaningful cyber coverage," he told The Register .
Mondelez sued Zurich in 2018 after the insurance biz [4]refused to cover damages that the cookie corporation incurred as a result of [5]NotPetya , a fast-spreading strain of file-trashing malware that some say caused more than $10 billion in damage worldwide and was later [6]attributed to the Russian military. NotPetya notably used [7]EternalBlue , a stolen and publicly leaked NSA exploit, to move from vulnerable Windows machine to vulnerable Windows machine.
[8]
The grub goliath said after NotPetya got into its network, it was left unable to use 1,700 of its servers and 24,000 laptops.
"As a result of the damage caused both to its hardware and operational software systems, MDLZ incurred property damage, commercial supply and distribution disruptions, unfulfilled customer orders, reduced margins, and other covered losses aggregating well in excess of $100,000,000," according to court documents
[9]PDF
filed by Mondelez.At the time, Mondelez's property and casualty insurance covered "all risks of physical loss or damage" as well as "physical loss or damage to electronic data, programs, or software, including loss or damage caused by the malicious introduction of a machine code or instruction."
That's the way the cookie crumbles
Zurich, however, denied the claim, citing an exclusion in the fine print for "hostile or warlike action in time of peace or war" by a "government or sovereign power," effectively arguing that the NotPetya losses were the result of a Russian act of war. And in which case, Zurich would not cough up of the money, leading to a lawsuit over the matter to extract the cash, and a settlement.
The Mondelez-Zurich face-off follows a similar legal battle between pharma giant Merck and its insurer, ACE American Insurance Company. Like Mondelez, Merck sued the insurance company for damages related to NotPetya. In January, the Superior Court of New Jersey [10]ruled the act of war exclusion only applied to the more traditional, physical armed force, and ordered the insurer to pay Merck $1.4 billion.
[11]
The Mondelez lawsuit is "very similar to the Merck situation, in that this is a cyber-related incident falling for consideration under a property insurance policy," said Peter Hawley, director of insurance solutions in Europe for SecurityScorecard.
"The claim itself would, on the face of it, be properly made in that the circumstances broadly are afforded coverage save for the application of the war exclusion clause," he told The Register . "What unfortunately seems to have happened is that there was a break in communication between the customer, their broker, and the insurance carrier, as to what was intended to be covered, or not covered, and hence the dispute which followed."
[12]Cyber-insurance shock: Zurich refuses to foot NotPetya ransomware clean-up bill – and claims it's 'an act of war'
[13]Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
[14]Lloyd's to exclude certain nation-state attacks from cyber insurance policies
[15]Higher risks and premiums are creating critical gap in cyber insurance
The settlement also comes as Lloyd's of London insurance policies will [16]soon stop covering losses from certain nation-state cyber attacks and those that happen during wars, declared or not, beginning April 1, 2023.
"I think Lloyd's also recognizes that, up until a year or so ago, cyberinsurance policies have been ridiculously underpriced because all of the companies wanted to get into the market," Cunningham said. "Now that we've seen the risk of truly catastrophic, I mean trillion-dollar-cyber events, that could bankrupt the global cyber insurance and reinsurance industry, these companies are scrambling to figure out ways to limit their exposure."
Cunningham predicts that as a result of, for instance, Lloyd's nation-state exclusion, governments will step in and provide some type of cyber insurance program, or there will be reforms related to insurance policies and cyber attribution.
Just last month the US Treasury [17]published a request for comment on questions related to cyberinsurance and catastrophic cyber incidents.
Government policy measures could include a backstop program for cyber-insurance risk along the lines of America's [18]Terrorism Risk Insurance Program , created after 9/11, to help property insurance policies include coverage for damage caused by acts of terrorism, Cunningham said.
"It's highly likely that there will eventually be some catastrophic cyber event that will start bankrupting insurance companies," he said. "Hopefully we will have government reform before the event." ®
Get our [19]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2JN0QEd1Q5ix1lK-w05NAAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2JN0QEd1Q5ix1lK-w05NAAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2JN0QEd1Q5ix1lK-w05NAAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2019/01/11/notpetya_insurance_claim/
[5] https://www.theregister.com/2017/06/28/petya_notpetya_ransomware/
[6] https://www.theregister.com/2020/10/19/russians_charged_olympics/
[7] https://www.theregister.com/2017/04/14/latest_shadow_brokers_data_dump/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2JN0QEd1Q5ix1lK-w05NAAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://regmedia.co.uk/2022/11/02/pacer_mondelez_zurich_complaint.pdf
[10] https://www.bloomberglaw.com/public/desktop/document/MerckCoIncvsAceAmericanInsuranCeDocketNoL00268218NJSuperCtLawDivA?1642788257
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2JN0QEd1Q5ix1lK-w05NAAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2019/01/11/notpetya_insurance_claim/
[13] https://www.theregister.com/2022/09/06/lloyds_cyber_insurance_policy/
[14] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[15] https://www.theregister.com/2022/08/11/insurance_ransomware_blackberry/
[16] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[17] https://www.federalregister.gov/documents/2022/09/29/2022-21133/potential-federal-insurance-response-to-catastrophic-cyber-incidents
[18] https://home.treasury.gov/policy-issues/financial-markets-financial-institutions-and-fiscal-service/federal-insurance-office/terrorism-risk-insurance-program
[19] https://whitepapers.theregister.com/
Privatize profits - outsource risk to public
cyberinsurance policies have been ridiculously underpriced because all of the companies wanted to get into the market
and now that those insurance companies realize they could be liable to pay real money in case of big cyber incidents they want to outsource their risk to the tax payer?
What is their idea, if it worked out for banks to privatize their profits and get the public to pay in a crisis why would it not work for insurance companies?
"a stolen and publicly leaked NSA exploit"
Thank you, NSA, for your contribution to criminal organizations everywhere.
Putin must be laughing his ass off.
Meanwhile, instead of suing Zurich, Mondelez should sue Washington DC.
And, while I'm at it, there should be a law stating that a company that holds more than one brand should have its name on the packaging of every product it sells.
That way, people will know who it is they're buying from.
Re: "a stolen and publicly leaked NSA exploit"
You haven't actually looked at a Ritz cracker box in the last month, have you? The box in my pantry says Mondelez Global on the label.
Also, why would I care which company produces the foodstuffs that I enjoy? If I like it, I'm going to buy it, even if its made by Hitler's Bakery GmbH.
NotPetya was a hardware killer?
"The grub goliath said after NotPetya got into its network, it was left unable to use 1,700 of its servers and 24,000 laptops."
I get that they would have been unable to use the hardware immediately after the attack, but once it's all been scrubbed clean, surely it's still usable and redeployable? Why would they add the cost/value of the hardware itself, as opposed to the cost of the clean up?
If someone with greater knowledge of IT security can illuminate me on the vagaries of a situation like this, it would be appreciated, but that smells like an excuse to replace an ageing hardware fleet, no?
Re: NotPetya was a hardware killer?
It was just bad reporting. They said they suffered losses due to being unable to use/access the machines - the trivial part being the cost of fixing the laptops and so-on, the bigger part being the loss of business.
Summary of current state of cyberinsurance
If you can afford lawyers, your losses will be ?mostly covered.
If you can't: fuck off.
Insurance companies
Always remember that insurance companies are in the business of taking money, not paying out money. They will do whatever it takes to minimize or even eliminate the paying out part. And when must use them, your rates will increase, even if you were not at fault and there was nothing you could have done to prevent the incident.
We would have paid up
but you opted for our "never claim" policy ....