P.F. Chang's Cyber Coverage – Not As Expected?
Time 3 Minute Read
Categories: Cyber

In a May 31, 2016 decision, a federal court in Arizona rejected P.F. Chang's attempt to recover an additional $2 million it paid following a 2013 breach in which hackers obtained and posted on the Internet approximately 60,000 credit card numbers belonging to P.F. Chang's customers.  P.F. Chang's was insured under a "CyberSecurity by Chubb Policy," which it had purchased from Federal Insurance Company for an annual premium of $134,000.  On its website, Federal marketed the policy as "a flexible insurance solution designed by cyber risk experts to address the full breadth of risks associated with doing business in today's technology-dependent world" including "consequential loss resulting from cyber security breaches."

After the 2014 breach, Federal agreed to reimburse P.F. Chang's nearly $1.7 million for valid claims brought by injured customers and Issuers.  However, when P.F. Chang's sought reimbursement from Federal for an additional $2 million in fees and assessments that were charged back to P.F. Chang's by its credit card service providers.  Federal refused to pay contending, among other things, that P.F. Chang's had no reasonable expectation of coverage for these amounts.  P.F. Chang's filed suit.

The court granted summary judgment in favor of Federal.  In doing so, the court determined that the record did not support P.F. Chang's argument that it reasonably expected the policy's broad cyber coverage would extend to the imposed fees and assessments.  But, this aspect of the decision ignores the very essence of Federal's cyber policy, which was marketed by Federal as comprehensive coverage designed "to address the full breadth of risks associated with doing business in today's technology-dependent world."

The court noted that Federal had not outright denied coverage in its entirety as it had acknowledged coverage under its CyberSecurity policy for multimillion dollar losses relating to other valid claims brought by injured customers and issuers.  The decision underscores, however, the critical importance of knowing the scope of your cyber coverage before purchasing the policy and before a breach occurs.  The decision also serves as a reminder that unlike with standard property and general liability forms, today's cyber products are still rapidly evolving, causing market products and coverages to be inconsistent and varied.  What may be covered under one policy very well may not be covered under another – there is no "one size fits all."  Policyholders, therefore, should engage knowledgeable brokers and coverage counsel to assist with their policy procurement or reviews of coverage that is already in place.  Hunton & Williams' insurance lawyers can assist in that regard.

  • Partner

    Mike is a Legal 500 and Chambers USA-ranked lawyer with more than 25 years of experience litigating insurance disputes and advising clients on insurance coverage matters.

    Mike Levine is a partner in the firm’s Washington, DC ...

You May Also Be Interested In

Time 5 Minute Read

In the rarely litigated space of cyber insurance, the Northern District of Texas issued a win for cyber policyholders this week, offering a clear reminder to insurers that if they want to restrict coverage, they must draft the policy to clearly do so.

Time 2 Minute Read

On December 16, 2025, the Federal Trade Commission announced an enforcement action against Illusory Systems Inc., a Utah-based company doing business as Nomad, following a major data breach in which hackers stole $186 million from consumers.

Time 3 Minute Read

On November 12, 2025, the UK government introduced the draft Cyber Security and Resilience (Network and Information Systems) Bill to the UK Parliament.

Time 3 Minute Read

On October 28, 2025, the Cyberspace Administration of China issued important amendments to the Chinese Cybersecurity Law, which will take effect on January 1, 2026.  

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page