The Seventh Circuit affirmed the district court’s decision that coverage for cyber coverage was precluded by an exclusion. Office of the Special Deputy Receiver v. Hartford Fire Ins. Co., 2026 U.S. App. LEXIS 17778 (7th Cir. June 18, 2026).
The Office of Special Deputy Receiver (OSD) was an Illinois corporation that administered estates for insolvent or financially troubled insurance companies. OSD purchased a Financial Institution Bond for Insurance Companies policy from Hartford.
RIder 13 of the policy provided coverage for computer systems fraud. It stated Hartford would cover “Loss resulting directly from a fraudulent . . . entry of Electronic Data or Computer program into . . . any Computer System operated by [OSD]. . . provided that the entry . . . causes . . .Property to be transferred, paid or delivered.”
Rider 17 provided coverage for Electronic Mail Initiated Transfer Fraud. The Rider promised that Hartford would cover “[loss] resulting directly from [OSD] having . . . delivered Funds . . . in reliance upon a fraudulent instruction sent to [OSD] through electronic mail, and . . . which fraudulent instruction purports and reasonably appears to have originated from [a Customer or Employee] acting on instructions of such Customer, but in fact was not originated by [such party].”
Rider 17 also excluded the following: ‘loss resulting directly or indirectly from [OSD] having . . . transferred . . Funds . . . in reliance upon a fraudulent instruction sent to [OSD] through electronic mail, except when covered [by Rider 17’s affirmative coverage, as noted above].”
Fraudsters outside OSD gained access to the CFO’s email account. Impersonating the CFO and using his email account, the fraudsters sent emails to other OSD employees, instructing them to transfer assets to fund new investments. The hackers changed the settings within the CFO’s email account so that they could respond to questions about the transfers. OSD’s staff wired the money as requested, and over the course of a few weeks OSD lost nearly $7 million (of which it later recovered about $3 million).
ODS filed a claim with Hartford, who denied coverage based primarily on Rider 17. OSD filed suit. The district court granted Hartford’s motion to dismiss. OSD appealed.
The Seventh Circuit noted it was undisputed that OSD’s claims did not fall within Rider 17’s affirmative coverage. The issue was whether an email sent from a hacker posing as one OSD employee to another OSD employee was “a fraudulent instruction sent to” OSD? If the answer was yes, Rider 17’s exclusion applied and dismissal was appropriate.
The Exclusion in Rider 17 did not include all emails. It was limited to the subset of messages sent to one particular recipient, OSD. In other words, losses resulting from an emailed, fraudulent instruction sent to OSD (but not other recipients) fell under the exclusion and were not covered. While the exclusion was restricted by recipient, it said nothing about any limit based on a message’s sender. For example, the exclusion did not say that messages originating only from senders outside OSD triggered the exclusion. Rather, it simply said messages sent to OSD qualify. In this case, the emails in question were sent to OSD employees. They included a fraudulent instruction that led to a loss. The exclusion applied.
OSD bargained for email fraud coverage that met specific criteria. The parties agreed in the exclusion that email fraud that did not meet that criteria was not covered. While the parties elsewhere in the policy drew lines between communications from outside OSD and messages sent from one part of OSD to another, that did not mean they were required to use the same level of specificity or necessarily intended such restriction in Rider 17.