Ontario Court Rules on Ransomware Coverage in Panasonic Case
Article Content
- •The Ontario Court of Appeal ruled that ransomware endorsements govern claims from ransomware attacks.
- •Panasonic incurred $2 million in costs due to a ransomware attack but did not pay a ransom.
- •The ruling reversed a lower court decision, emphasizing the need to interpret endorsements alongside the entire policy.
The Ontario Court of Appeal ruled in Panasonic Canada Inc. v. XL Specialty Insurance Company that a ransomware endorsement applies to losses from a ransomware attack, even if the insured claims under a different coverage provision. The case arose from a February 2022 ransomware incident where Panasonic incurred approximately $2 million in response costs after attackers accessed their network and exfiltrated confidential data. Panasonic did not pay a ransom but sought coverage under its cyber policy, which included a $1.5 million retention in the base policy and a $3 million retention under the ransomware endorsement. The lower court sided with Panasonic, but the Court of Appeal reversed this decision, stating that the endorsement's definitions must be read in conjunction with the entire policy. This ruling emphasizes the importance of understanding policy wording and its implications for claim recovery strategies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What was the nature of the ransomware attack?
What did the court decide regarding the insurance coverage?
What are the financial implications for Panasonic?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…