Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsMerck settled its NotPetya insurance dispute with its insurers on January 3, 2024, before the New Jersey Supreme Court could hear the case. The settlement terms were confidential. Merck had already won an appellate ruling that the warlike-action exclusion in the property policies at issue did not bar its claim, but the settlement produced no Supreme Court decision—and does not establish a universal rule for cyber insurance.
What Merck’s NotPetya insurance case decided
NotPetya struck Merck in 2017. Bloomberg Law reported that about 40,000 of the company’s computers were affected. Merck sought coverage under “all risks” property policies after alleging $1.4 billion in losses. Its insurers relied on a hostile- or warlike-action exclusion.
The New Jersey trial court found that the exclusion did not bar coverage, and the Appellate Division affirmed. In its account of the trial ruling, the appellate opinion quoted the court: “Given the plain meaning of the language in the exclusion, together with the foregoing examination of the applicable caselaw, the court unhesitatingly finds that the exclusion does not apply.” The reasoning centered on the wording before the court: it did not reasonably notify the policyholder that cyberattacks were excluded and was understood to address traditional forms of warfare.
That was an interpretation of the language and record in Merck’s case—not a decision that every cyberattack, or every state-linked attack, is covered by every insurance policy.
How much did Merck receive?
The settlement amount and terms were not disclosed. Bloomberg Law reported that roughly $700 million in claims were at issue in the insurers’ appeal; that figure is not the settlement payment. The $1.4 billion was Merck’s alleged loss, not a public valuation of the settlement.
The parties settled on January 3, 2024, shortly before scheduled oral argument in the New Jersey Supreme Court. Because the dispute ended before argument, the state’s highest court issued no ruling in the case. The Appellate Division’s decision remained in place, but it was not turned into a New Jersey Supreme Court precedent.
Merck and Mondelez were separate NotPetya cases
Mondelez International’s dispute with Zurich American Insurance also concerned NotPetya, but it was a separate lawsuit and settled in 2022 during trial. The Record reported that Mondelez claimed about $100 million under a property policy it argued covered cyber-related damage. Zurich invoked a hostile- or warlike-action exclusion. The Record also reported that Mondelez’s network lost more than 1,700 servers and 24,000 laptops.
| Case | Policy and claim | Outcome |
|---|---|---|
| Merck v. its insurers | All-risks property policies; Merck alleged $1.4 billion in losses. Roughly $700 million in claims were at issue in the insurers’ appeal, according to Bloomberg Law (2024). | Settled January 3, 2024, before New Jersey Supreme Court argument; terms confidential. The Appellate Division ruling favoring Merck remained, with no Supreme Court ruling. |
| Mondelez v. Zurich American Insurance | Property policy; Mondelez claimed about $100 million, according to The Record (2022). | Settled during trial in 2022; terms undisclosed and no public merits ruling. Zurich’s spokesperson told The Record, “The parties have mutually resolved the matter.” |
Zurich’s statement confirms resolution of the dispute; it is not an admission that the policy covered the loss. Aon executive Craig Dunn described Mondelez’s policy to The Record as a property policy with some cyber coverage, rather than a standalone cyber policy.
Recommended Free Tools
Does a war exclusion cover a state-sponsored cyberattack?
There is no single answer established by these cases. Merck’s appellate win turned on the wording in its policies and the case record. The Merck settlement then prevented the New Jersey Supreme Court from reviewing that interpretation. Mondelez’s settlement also ended without a public merits decision. Questions about attribution and coverage for state-linked cyber operations therefore remain dependent on the policy language and circumstances involved.
For a business evaluating coverage, the useful question is not simply whether a policy contains a “war exclusion.” Review how it defines war and state-backed cyberattacks, how responsibility for attributing an attack is determined, and whether the exclusion reaches affected systems outside an impacted state. Also check which property damage, cyber losses, and business-interruption costs are covered, and whether the policy is standalone cyber coverage or a property policy with cyber protection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the settlements signal about the cyber insurance market
The cases highlight why precise policy wording matters, but they do not show that the settlements themselves caused a measured, market-wide change in coverage, prices, or availability. The sources cited here provide no quantified market effect attributable to either settlement.
Separately, CSO reported that Lloyd’s market requirements for cyber policies called for clearer treatment of war and state-backed cyberattacks, attribution, affected systems outside an impacted state, and defined terms, with an effective date of March 31, 2023. That is evidence of a policy-wording response; it does not establish that every insurer adopted the same language or that the Merck settlement drove a universal change.
Best Value
What this means for households and business buyers
Merck and Mondelez were commercial disputes involving company property policies, not household insurance claims. These outcomes do not determine whether a homeowner’s, renter’s, or personal cyber policy covers a particular loss. For businesses, the practical next step is to have a broker and, where needed, legal counsel review the actual policy wording—especially exclusions, attribution provisions, covered systems and territories, and business-interruption coverage. Surefire Cyber chief executive Billy Gouveia has also emphasized the value of incident-response preparation alongside insurance; coverage is only one part of a company’s response plan.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




