Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAbout UsContactSubscribeSupport
Book a Demo
Search
Close

Merck-Settlement of $1.4 Billion Coverage Dispute Over NotPetya Cyberattack Places Renewed Spotlight on War Exclusions in 2024

By Shelby Guilbert & McGuireWoods LLP on January 9, 2024
Email this postTweet this postLike this postShare this post on LinkedIn

Last week, Merck & Co. filed documents with the Supreme Court of New Jersey indicating that it reached a settlement with its “all risk” property insurers in a long-running coverage dispute involving over $1.4 billion in losses stemming from a 2017 NotPetya cyberattack that impacted tens of thousands of Merck computers. The coverage litigation, Merck & Co. v. ACE American Insurance Co., focused on the key question of whether the policies’ “hostile/warlike” exclusion applied to the NotPetya attack, which some intelligence agencies have attributed to Russian government attempts to destabilize Ukraine. The settlement was announced just a few days before the New Jersey Supreme Court was set to hear oral arguments during an appeal of the New Jersey state appeals court’s affirmance of a 2021 trial court ruling in Merck’s favor. Merck’s insurers had argued that Merck’s losses were barred by a war exclusion, but the New Jersey trial court found that the exclusion did not apply to malware and cyberattacks and instead was intended to apply only to physical acts of warfare between the armed forces of two or more countries. The terms and the amount of the settlement have not yet been disclosed.

While this significant settlement puts an end to the six-year battle for coverage for the pharmaceutical company, there are several key takeaways regarding coverage for cyberattacks that in-house counsel and risk managers should consider in 2024:

  • Although the details of the Merck settlement remain unknown, it is noteworthy that Merck obtained coverage for the cyberattack under a property policy. After any cyber incident affecting a company’s business operations, it is important to consider all lines of coverage – not just cyber-specific insurance policies. First party policies may respond to certain types of cyber incidents that damage company infrastructure or interfere with ongoing business operations. Third party policies like CGL, D&O, and professional liability policies may also respond to claims or regulatory investigations arising from a cyber incident. All lines of coverage should be carefully considered after a cyber incident.
  • Cyber incidents are sometimes perpetrated by foreign governments or quasi-state actors that may be engaged in armed conflict halfway around the globe. Policyholders should not assume that traditional “war” exclusions drafted during the Cold War necessarily bar coverage for twenty-first century attacks in cyberspace. In light of the New Jersey trial court and intermediate appellate court ruling, policyholders should work with coverage counsel to evaluate and respond to insurer arguments that war or state actor exclusions apply to cyber incidents.
  • In response to the Merck litigation and other NotPetya related coverage disputes, the insurance industry continues to add new exclusions to limit their exposure to cyberattacks perpetrated by state actors or in connection with warlike conduct. As we discussed in https://www.propolicyholder.com/2023/02/new-exclusions-limit-insurance-coverage-cyber-attacks/, as of March 2023, Lloyds of London insurers mandated several new exclusions designed to cover cyberattacks, and U.S.-based insurers are increasingly following suit, either through new war or state-actor exclusions specifically addressing cyber exposures, or other language aimed at ringfencing exposure for widespread cyber events. This language is often negotiable.
  • Although the terms and conditions of cyber policies vary widely, the threat landscape continues to evolve. Policyholders should carefully review their coverages every year with their brokers and coverage counsel to obtain the broadest coverage possible to mitigate against the risk of catastrophic cyber-attacks.
Photo of Shelby Guilbert Shelby Guilbert
Read more about Shelby GuilbertEmail
McGuireWoods LLP

At McGuireWoods, we deliver quality work, personalized service and exceptional value. We use technology to provide efficient legal solutions and employ a diverse workforce to bring real-world and innovative perspectives to meeting our clients’ needs. With 1,100 lawyers and 21 strategically located offices…

At McGuireWoods, we deliver quality work, personalized service and exceptional value. We use technology to provide efficient legal solutions and employ a diverse workforce to bring real-world and innovative perspectives to meeting our clients’ needs. With 1,100 lawyers and 21 strategically located offices worldwide, McGuireWoods uses client-focused teams to serve public, private, government and nonprofit clients from many industries, including automotive, energy resources, healthcare, technology and transportation.

Email
Show more Show less
  • Posted in:
    Financial, Insurance
  • Blog:
    Pro Policyholder
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • Resource Center
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center
  • Blogging 101

New to the Network

  • Tennessee Insurance Litigation Blog
  • Claims & Sustains
  • New Jersey Restraining Order Lawyers
  • New Jersey Gun Lawyers
  • Blog of Reason
Copyright © 2025, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo