2nd Cir. Affirms Medidata’s Spoofing Loss is Covered Under Crime Policy’s Computer Fraud Provision
Time 3 Minute Read
Categories: Cyber

On July 6, 2018, the Second Circuit Court of Appeals affirmed a district court’s summary judgment award in favor of Medidata Solutions, Inc., finding that Medidata’s $4.8 million loss suffered after Medidata was tricked into wiring funds to a fraudulent overseas account, triggered coverage under a commercial crime policy’s computer fraud provision. The decision in Medidata Solutions, Inc. v. Federal Ins. Co., 17-cv-2492 (2d Cir., July 6, 2018), confirms a ruling by District Judge Andrew L. Carter, Jr., in which the district court found that a fraudsters manipulation of Medidata’s computer systems constitutes a fraudulent entry of data into the computer system, since the spoofing code was introduced into the email system.

The lawsuit, discussed in Hunton Andrews Kurth blog posts on August 18, 2016 and July 24, 2017 and July 25, 2017, arose after employees in Medidata’s finance department were deceived into transferring $4.8 million to a Chinese bank account based on emails that falsely appeared to come from a Medidata executive. Federal Insurance Company, a unit of Chubb Corp., insured Medidata under a policy providing coverage for, among other things, computer fraud.  Federal denied coverage for the claim, arguing that Medidata’s claim was not covered because, among other things, there had been no manipulation of Medidata’s computers.  Federal further argued that Medidata did not suffer a “direct loss” as a result of the spoofing attack, since Medidata employees caused the funds to be transferred to the fake bank.

The Second Circuit affirmed the district court’s decision, finding that the entry of data into the computer system squarely satisfied the computer fraud provision, which affords coverage for loss stemming from any “entry of Data into” or “change to Data elements or program logic of” a computer system.  The Second Circuit also rejected Federal’s argument that Medidata’s loss did not result directly from the spoofing attack, which was necessary for a finding of coverage since the policy requires a direct or proximate causal link between the fraudulent activity and the resulting loss.  As the appellate court explained, however, “[i]t is clear to us that the spoofing attack was the proximate cause of Medidata’s losses. The chain of events was initiated by the spoofed emails, and unfolded rapidly following their receipt. While it is true that the Medidata employees themselves had to take action to effectuate the transfer, we do not see their actions as sufficient to sever the causal relationship between the spoofing attack and the losses incurred.”

Medidata confirms the breadth of coverage available to policyholders under their commercial crime policies for social engineering and other computer-related fraud-induced losses. The decision also helps overcome the artificial distinction that insurers have tried to maintain between a computer hack-type event and a social engineering intrusion, both of which necessarily entail accessing the target’s computer systems or data and manipulating those systems in a fraudulent manner.  Finally, the decision illustrates that all policies should be consulted whenever there is a loss, and that policyholders should seek advice from counsel with expertise in this area to make sure they get the policy wording correct.  Doing so may help avoid costly and protracted litigation following a loss.

  • Partner

    Mike is a Legal 500 and Chambers USA-ranked lawyer with more than 25 years of experience litigating insurance disputes and advising clients on insurance coverage matters.

    Mike Levine is a partner in the firm’s Washington, DC ...

You May Also Be Interested In

Time 1 Minute Read

If recent years have taught insurance practitioners anything, it is that the most consequential coverage disputes rarely turn on novelty alone. In 2025, courts continued to resolve high‑stakes insurance disputes by returning to first principles—examining when claims are related, how losses and occurrences are defined and aggregated, and how policy language allocates risk across time and conduct. D&O coverage and other core insurance law issues again occupied center stage, while decisions in property, cyber, and liability disputes reinforced a familiar theme: policy interpretation remains the decisive factor in determining whether coverage is available in an increasingly complex claims environment. As the decisions discussed below demonstrate, 2025 confirmed that even as risks evolve, coverage disputes remain grounded in careful, policy‑specific analysis.

Time 4 Minute Read

In today’s digital world, data breaches due to vendor failures are becoming increasingly common, often resulting in costly fallout. While insurance can provide a safety net, the interaction between cyber insurance and vendor contracts is crucial for effective recovery and risk management. Vendor contracts should not be treated as mere formalities but as vital frameworks that contain specific, detailed provisions regarding data security obligations to ensure accountability and minimize vulnerabilities.

Time 4 Minute Read

In today’s digital world, data breaches due to vendor failures are becoming increasingly common, often resulting in costly fallout. While insurance can provide a safety net, the interaction between cyber insurance and vendor contracts is crucial for effective recovery and risk management. Vendor contracts should not be treated as mere formalities but as vital frameworks that contain specific, detailed provisions regarding data security obligations to ensure accountability and minimize vulnerabilities.

Time 5 Minute Read

Theft in the cargo industry has skyrocketed in recent years. In the first half of 2024, cargo thefts rose 49 percent and the average loss per shipment by 83 percent. Given these dramatic spikes in cargo theft, policyholders whose operations rely on the safe transportation and trade of cargo should take steps to mitigate against the potential losses of a cargo-theft event. We discuss below the insurance coverage options available to policyholders that can help protect against the risks and losses associated with cargo-related theft if such a loss occurs.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page