Aqua Star: U.S. District Court applies “Authorized Entry” Exclusion to claim under Computer Fraud Coverage

On July 8, 2016, the U.S. District Court for the Western District of Washington released its decision in Aqua Star (USA) Corp. v. Travelers Casualty and Surety Company of America.  The decision offers guidance to fidelity insurers with respect to the application of the “authorized entry” exclusion found in the base wording of many commercial crime policies (sometimes referred to as the “authorized access” exclusion), and illustrates how this exclusion may operate in the context of a social engineering fraud loss.

The Facts

The insured, Aqua Star (USA) Corp. (“Aqua Star”), is a seafood importer that had a pre-existing relationship with a legitimate vendor, Zhanjiang Longwei Aquatic Products Industry Co. Ltd. (“Longwei”).  In the summer of 2013, Longwei’s computer system was hacked.  The hacker apparently monitored email exchanges between an Aqua Star employee and a Longwei employee before intercepting those email exchanges and using “spoof” email domains to send fraudulent emails to the Aqua Star employee.  In the spoofed emails, the hacker directed the Aqua Star employee to change the bank account information Aqua Star had on record for Longwei for future wire transfer payments.

The Aqua Star employee inserted the revised banking information into Aqua Star’s computer system.  This revised information was then used to create Wire Confirmation Detail instructions that were transmitted to Aqua Star’s bank, the Bank of America.  As a result, $713,890 was wired to the hacker’s account before the fraud came to light.

The Travelers Coverage

Aqua Star maintained a Wrap+ Crime Policy with Travelers.  The policy covered Aqua Star for its “direct loss of, or direct loss from damage to, Money, Securities, and Other Property directly caused by Computer Fraud”, as defined.  Travelers relied on Exclusion G to the policy, which provided that the policy:

will not apply to loss resulting directly or indirectly from the input of Electronic Data by a natural person having the authority to enter the Insured’s Computer System. 

As a general observation, this type of exclusion is intended to encompass (among other things) social engineering fraud losses.  At present, social engineering fraud coverage is typically added to commercial crime policies by endorsement, with the endorsement providing that the exclusion in the base wording does not apply in respect of coverage afforded by the endorsement.  The intent is to reinforce that only social engineering fraud coverage, and not the “traditional” computer or funds transfer fraud coverages, responds to social engineering fraud losses.

It is not clear from the Court’s decision whether Aqua Star also maintained social engineering fraud coverage.

The Decision

On the parties’ cross-motions for summary judgment, the Court confined itself to the question of whether Exclusion G applied to the loss, and did not opine on whether the loss fell prima facie within coverage.  The Court held that, on its face, Exclusion G clearly applied to the facts.  The “revised” banking details were information, which fell within the meaning of “Electronic Data”.  The employee in question was a natural person and had the authority to enter banking details into Aqua Star’s computer system.  As a result, the exclusion applied.

Aqua Star advanced two substantive arguments in an effort to avoid the application of the exclusion.  First, Aqua Star asserted that the exclusion did not apply because, in order to initiate the wire transfers, an Aqua Star employee had to enter data into the computer system of a third party (i.e., its bank, the Bank of America).  The Court rejected this contention, observing that:

Although entering data into a third party’s computer system may have been the final step that led to Aqua Star’s loss, necessary intermediate steps prior to the transfer involved entering Electronic Data into Aqua Star’s own Computer System. Aqua Star does not explain why the involvement of a third party computer system would render Exclusion G inapplicable.

Second, Aqua Star contended that Exclusion G was actually intended to preclude coverage where a fraud is perpetrated by an authorized user of an insured’s computer system, such as an employee or legitimate customer.  The Court did not accept this argument either, but did note that:

the clear language of the policy does not limit the exclusion to fraud perpetrated by an authorized user, although … it certainly could apply in that situation [as well]. 

As a result, Exclusion G applied to the loss.

Conclusion

In providing a detailed analysis of Exclusion G to the Travelers Wrap+ policy, Aqua Star reflects the intended boundary between social engineering fraud coverage and “traditional” computer fraud and funds transfer fraud coverages.  Courts have generally interpreted the computer fraud coverage as being intended to cover loss due to unauthorized hacking by third parties (see, for example, Pestmaster, which we discussed in our January 6, 2015 post), not employees’ authorized entries of data that are induced by external fraud.

To address this perceived gap, many insurers have introduced social engineering fraud endorsements to respond to the latter scenario.  The “authorized entry” exclusion reinforces insurers’ intent that the two coverages respond to different loss scenarios.  In our view, it is appropriate to keep this context in mind in assessing both the applicability of “authorized entry” exclusions and the dividing line between social engineering fraud coverage and other coverages.

Aqua Star (USA) Corp. v. Travelers Casualty and Surety Company of America, 2016 WL 3655265 (W.D. Wash.)

Fidelity Blog

Gore, Kilpatrick & Dambrino PLLC: U.S. District Court finds No Social Engineering Fraud Coverage in Phony Debt Collection Fraud

On March 31, 2026 the U.S. District Court for the Northern District of Mississippi released its decision in Gore, Kilpatrick & Dambrino PLLC v. Spinnaker Ins. Co.  The Court interpreted the requirements of a Social Engineering Fraud (SEF) insuring agreement in a cyber policy in the context of a phony debt collection fraud perpetrated on … Continued

by

Westlake Chemical: Texas Court of Appeals applies Authorized Representative Exclusion in finding No Coverage under Crime Policy for Phony Invoicing Scheme

On May 25, 2023, the Texas Court of Appeals released its decision in Westlake Chemical Corporation v. Berkley Regional Insurance Company.  The Court affirmed the District Court’s summary judgment in favour of the insurers on the basis that the Authorized Representative Exclusion applied.  The Court’s decision is notable in finding that the exclusion does not require … Continued

by

Cachet Financial Services: U.S. District Court finds No Coverage under Commercial Crime Policy for Alleged ACH Kiting and Related Frauds

In the recent decision of Cachet Financial Services v. Berkley Insurance Company, the United States District Court for the Central District of California found no coverage under a commercial crime policy in respect of several alleged frauds involving a payroll processor. The decision is instructive for fidelity claims professionals as to the meaning of “alteration” in … Continued

by

Star Title Partners: Eleventh Circuit finds No Coverage for Social Engineering Fraud Loss under Cybercrime Endorsement to Cyber Protection Policy

On September 6, 2022, the Eleventh Circuit Court of Appeals released its decision in Star Title Partners of Palm Harbor, LLC v. Illinois Union Insurance Company.  In deciding that a social engineering fraud (SEF) loss did not fall within the coverage afforded under a Deceptive Transfer Fraud insuring clause, the Court construed the terms “employee,” “customer,” … Continued

by

Mississippi Silicon: Fifth Circuit finds No Coverage for Social Engineering Fraud Loss under Crime Policy’s Computer Fraud Coverage

On February 4, 2021, the Fifth Circuit Court of Appeals released its decision in Mississippi Silicon Holdings, LLC v. AXIS Insurance Company. In affirming the lower court’s grant of summary judgment in favour of AXIS, the Fifth Circuit made important findings regarding the proper scope of the Computer Fraud coverage; whether a fraudster’s opening of a … Continued

by

All Fidelity Blog Posts