small accounting firm (8 employees) hit with ransomware in march - paid $47k to recover client data. travelers cyber policy has $250k limit but theyre invoking the "act of war" exclusion because the ransomware variant has alleged russian nation-state attribution. they want to apply a $10k sublimit instead of the $250k policy limit. how do i fight an attribution-based war-exclusion denial on a commercial cyber claim?
this is unbelievable. small firm, paid the premium for years, finally had the kind of incident that the policy is supposed to cover, and now the carrier is doing acrobatics to avoid paying. need help understanding what is actually defensible here.
quick background. small CPA firm in a midsize midwest city. 8 employees, full-service accounting, mostly small-business and high-net-worth-individual tax and bookkeeping clients. been in business 19 years. annual gross revenue around $1.4M. cyber risk is real - we handle a lot of sensitive client data (tax returns, financial statements, banking detail) and we have a meaningful target profile for ransomware actors.
policy. Travelers CyberRisk Tech policy with $250k aggregate limit, written for the firm specifically. covers ransomware (extortion payment, restoration cost, business interruption, breach response, regulatory defense). premium runs about $4,200 per year. we have had the coverage since 2019 and renewed every year. policy was active and in force at the time of the incident.
incident. march 2026, sunday afternoon. one of our staff CPAs clicked a phishing email at home on a personal device that had VPN access to the firm's file server. ransomware deployed Saturday night through the VPN tunnel and encrypted approximately 60% of our shared drive (client work papers, prior-year returns, source documents). the ransomware variant was identified by the IR firm as a variant of "BlackPaw" (note: name changed slightly here to avoid identification of the specific strain that we were hit with).
response. immediately engaged the incident response firm on the Travelers approved-vendor list. they isolated the affected systems, attempted decryption (no decryptor available for this variant), evaluated backups (partial backups available, last full backup was 14 days old, so significant data loss exposure on recent client work). the IR firm advised that ransom payment was the fastest path to recovery given the time-sensitivity of in-progress tax returns. we engaged the breach coach (also Travelers approved-vendor) who validated the ransom payment approach as commercially reasonable.
ransom payment. negotiated down from initial $85k demand to $47k via the ransom negotiator (also Travelers approved-vendor). paid in Bitcoin through the standard process. received decryption key within 4 hours. full data restoration completed over the following 3 days. business interruption losses approximately $32k (3 weeks of reduced productivity during recovery). total incident cost: $47k ransom + $32k BI + $18k IR firm fees + $12k breach coach fees + $8k forensic investigation = $117k total claim against the $250k policy limit.
submitted the claim through Travelers' cyber claims process. provided full documentation of the IR investigation, the ransom negotiation, the payment trail, the recovery timeline, and the business interruption losses. claim manager initially assigned, responsive for the first 6 weeks.
here is where it gets bad. four weeks ago, claim handler escalated the file to Travelers' "cyber war coverage analysis" team. last week, we received a 14-page coverage analysis letter stating that:
(a) Travelers' forensic team has "attributed" the ransomware variant to "a threat actor with known affiliations to the Russian Federation," specifically citing public reporting and Treasury sanctions designations against the parent ransomware-as-a-service operator.
(b) the policy's "war and hostile acts exclusion" applies because the attack is "an act of war or hostile act by a sovereign-affiliated actor."
(c) ALTERNATIVELY, the policy's "Cyber Operations Sub-limit" of $10,000 applies to "any incident involving a state-affiliated threat actor or originating from a sanctioned jurisdiction."
(d) Travelers will pay $10,000 (the sub-limit) "as a goodwill resolution," subject to a release of all further claims under the policy.
so out of $117k of documented losses against a $250k policy, they are offering $10k.
i was sitting in my office reading this letter trying to figure out if it was a joke or if some intern had stapled the wrong cover sheet. it was not a joke. they have created a legal theory that any ransomware attack with any plausible Russian connection is now a "war" event and excluded or sub-limited under the policy.
specific issues with the denial that seem obvious to me:
(1) the attribution is speculative at best. "known affiliations" is not the same as "a sovereign-directed military operation." ransomware-as-a-service operators are criminal enterprises that operate for profit, not sovereign military operations. multiple federal court decisions in commercial insurance cyber-war exclusion cases (Merck v. Ace, Mondelez v. Zurich) have rejected the broad-scope application of war exclusions to criminal cyber incidents.
(2) the "Cyber Operations Sub-limit" was NOT highlighted at policy inception or any subsequent renewal. i went back through every policy document we received from 2019 through 2026 and the sub-limit appears as a single line on page 47 of the 64-page policy document, in the same font and size as standard policy language. no separate endorsement, no Renewal Disclosure Statement highlighting the sub-limit, no email communication identifying the sub-limit applicability. this is functionally a hidden sub-limit that was never disclosed in a meaningful way.
(3) the sub-limit's triggering criteria are written so broadly that virtually any ransomware incident would qualify. "any incident involving a state-affiliated threat actor or originating from a sanctioned jurisdiction" captures essentially all commercially significant ransomware activity because the major ransomware-as-a-service operators all have some level of nexus to sanctioned jurisdictions (Russia, North Korea, Iran). the sub-limit functionally negates the cyber coverage.
(4) the "war and hostile acts exclusion" was developed for kinetic warfare and politically-directed military operations. applying it to a profit-motivated criminal ransomware attack is exactly the kind of overreach that the Merck and Mondelez decisions rejected. Travelers' own internal guidance to underwriters (per public industry reporting) acknowledges that war exclusions should not apply to criminal ransomware activity. and yet here we are.
(5) Travelers approved every step of our incident response. their approved-vendor IR firm advised the ransom payment. their approved-vendor breach coach validated the response. their approved-vendor ransom negotiator handled the payment. now they are denying coverage for the very response they approved. this feels like a textbook bad-faith claims-handling fact pattern.
questions for the community on what to actually do:
(1) Merck and Mondelez precedent - both decisions rejected broad war exclusions in commercial cyber contexts. are these decisions binding in my jurisdiction or merely persuasive authority? what is the current state of the law on cyber-war exclusion challenges in 2026?
(2) the attribution problem - Travelers is treating "alleged Russian nexus" as established fact. what is the actual evidentiary standard for invoking a war exclusion? do they need to prove the attack was state-directed (a higher bar) or merely state-affiliated (a much lower bar)?
(3) the sub-limit disclosure problem - is there a "reasonable expectations" doctrine argument here that the hidden sub-limit should not be enforceable because it was never highlighted at sale or renewal? does the contra-proferentem doctrine help on the ambiguity in the sub-limit triggering language?
(4) bad faith claim - Travelers approved every response step and then denied coverage on the response they approved. is this a viable bad-faith claim under my state's bad-faith statute? what would the recovery look like (extra-contractual damages, attorney fees, treble damages)?
(5) policyholder coverage counsel - on a $117k claim that Travelers wants to pay $10k on, when is it worth engaging a policyholder-side coverage attorney? what is the typical fee structure (hourly $500-$700, contingency, hybrid)?
(6) the breach coach conflict - the breach coach is on Travelers' approved-vendor list, paid by Travelers, and now apparently working both sides of the dispute. is the breach coach communication with us privileged? are their work product and recommendations discoverable in coverage litigation?
(7) DOI complaint - we are in a state with an active DOI cyber-insurance enforcement program. is filing a DOI complaint in parallel with the coverage dispute helpful or counterproductive?
(8) the bigger picture - are carriers across the industry coordinating on a "cyber war exclusion" denial strategy against small commercial policyholders? we are not the only firm in our network that has been hit with this exact denial pattern in 2026. this feels orchestrated.
(9) the long-term coverage question - if Travelers can deny on attribution alone, then commercial cyber insurance is effectively useless because the major ransomware groups all have some level of attribution to sanctioned jurisdictions. how should small commercial policyholders be thinking about their cyber risk going forward when carriers can deny on this basis?
we are not a sophisticated insured. we are a small accounting firm that bought a cyber policy because we knew we had ransomware risk. the carrier is now exploiting policy language in a way that effectively negates the coverage we paid premium for. need to figure out the path forward and make sure other small businesses do not get the same treatment.
any guidance on the specific procedural moves and the realistic recovery path appreciated. happy to update once this resolves.
Loading comments...