Fifth Circuit Says "Computer Fraud" Requires More Than "Incidental" Use Of A Computer
Time 2 Minute Read
Categories: Cyber

In a seemingly illogical decision, the Fifth Circuit Court of Appeals ruled in Apache Corp. v. Great American Ins. Co., No 15-20499 (5th Cir. Oct. 18, 2016), that loss resulting from a fraudulent e-mail did not trigger coverage under a crime policy's "computer fraud" coverage because the loss was not the "direct result" of computer use.

Apache involved a fraudulent inducement of the policyholder, Apache Corporation, to wire $7 million in invoice payments to a fraudulent bank account under the belief that the account was that of a vendor, Petrofac. The inducement was precipitated by a phone call and confirmed with a fraudulent e-mail that purported to be on Petrofac letterhead. The fake letter also included a phony telephone number, which Apache personnel used to confirm the change request. Shortly after the transfers, Apache was notified that Petrofac had not received its payments that had been made to the new, and fraudulent, bank account. Apache recouped a portion, but not all, of the payments. Apache sought to recover the balance from its insurer.

The district court awarded summary judgment in favor of Apache. On appeal, the Fifth Circuit reversed finding that the loss did not result directly from the use of any computer. Rather, as the court explained, the email was part of the scheme, but, the email was merely incidental to the occurrence of the authorized transfer of money. Thus, the court concluded that to interpret the computer-fraud provision as reaching any fraudulent scheme in which an email communication was part of the process would convert the computer-fraud provision to one for general fraud.

Not only is Apache indicative of the ease by which imposters can fraudulently induce payment of millions of dollars by unwary policyholders, but the decision is illustrative of the significant gaps in coverage that still exist for cyber and other technology-related losses. A review of Apache's so-called computer fraud coverage by experienced coverage counsel would likely have identified that Apache's narrow coverage applied only where the loss resulted directly from the use of a computer, thus affording Apache an opportunity to negotiate a broadening of its coverage so that it actually protected its accounts payable operations.

  • Partner

    Mike is a Legal 500 and Chambers USA-ranked lawyer with more than 25 years of experience litigating insurance disputes and advising clients on insurance coverage matters.

    Mike Levine is a partner in the firm’s Washington, DC ...

You May Also Be Interested In

Time 1 Minute Read

If recent years have taught insurance practitioners anything, it is that the most consequential coverage disputes rarely turn on novelty alone. In 2025, courts continued to resolve high‑stakes insurance disputes by returning to first principles—examining when claims are related, how losses and occurrences are defined and aggregated, and how policy language allocates risk across time and conduct. D&O coverage and other core insurance law issues again occupied center stage, while decisions in property, cyber, and liability disputes reinforced a familiar theme: policy interpretation remains the decisive factor in determining whether coverage is available in an increasingly complex claims environment. As the decisions discussed below demonstrate, 2025 confirmed that even as risks evolve, coverage disputes remain grounded in careful, policy‑specific analysis.

Time 4 Minute Read

In today’s digital world, data breaches due to vendor failures are becoming increasingly common, often resulting in costly fallout. While insurance can provide a safety net, the interaction between cyber insurance and vendor contracts is crucial for effective recovery and risk management. Vendor contracts should not be treated as mere formalities but as vital frameworks that contain specific, detailed provisions regarding data security obligations to ensure accountability and minimize vulnerabilities.

Time 4 Minute Read

In today’s digital world, data breaches due to vendor failures are becoming increasingly common, often resulting in costly fallout. While insurance can provide a safety net, the interaction between cyber insurance and vendor contracts is crucial for effective recovery and risk management. Vendor contracts should not be treated as mere formalities but as vital frameworks that contain specific, detailed provisions regarding data security obligations to ensure accountability and minimize vulnerabilities.

Time 5 Minute Read

Theft in the cargo industry has skyrocketed in recent years. In the first half of 2024, cargo thefts rose 49 percent and the average loss per shipment by 83 percent. Given these dramatic spikes in cargo theft, policyholders whose operations rely on the safe transportation and trade of cargo should take steps to mitigate against the potential losses of a cargo-theft event. We discuss below the insurance coverage options available to policyholders that can help protect against the risks and losses associated with cargo-related theft if such a loss occurs.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page