Court, Explained
U.S. Federal District Courts
Back to docket
D. Minn.Substantive rulingFiled Nov. 3, 2022

Fishbowl Solutions, Inc. v. Hanover Insurance Company, The

Judge
Susan Nelson
Docket
0:21-cv-00794
Court
U.S. District Court · District of Minnesota
Pages
25
InsuranceContractSummary Judgment
In one sentence

Fishbowl Solutions v. Hanover Insurance: Judge Nelson held the policy covered an email-fraud loss, granting Fishbowl summary judgment and awarding $147,926.21.

Who this affects

Fishbowl Solutions, Inc. obtained coverage and a $147,926.21 damages award from The Hanover Insurance Company. Any request for prejudgment interest or attorney’s fees remained subject to further briefing.

What happened

Fishbowl Solutions, Inc. sued The Hanover Insurance Company after a hacker accessed an employee’s email, redirected messages, and tricked a client into sending $176,962 to the hacker. After recovering $29,077.79, Fishbowl sought insurance coverage for the remaining $147,926.21 under a policy covering losses directly resulting from a data breach that impaired business operations.

The court ruled that the policy covered the loss. It found that emailing clients and sending invoices were part of Fishbowl’s regular business activities, that the email interference impaired those activities, and that the lost payments were business income directly resulting from the data breach. The court also rejected Hanover’s arguments that the client’s conduct broke the connection to the breach and that the policy’s general purpose prevented coverage.

Judge Nelson granted Fishbowl’s motion for summary judgment as to all claims and denied Hanover’s motion as to all claims. The court awarded Fishbowl $147,926.21 in damages and ordered further briefing on any request for prejudgment interest or attorney’s fees.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Fishbowl Solutions, Inc. v. Hanover Insurance Company, The · No. 0:21-cv-00794
Judge
Susan Nelson
Date
Nov. 3, 2022

Background

Fishbowl Solutions, Inc. is a technical consulting and software development company. In November 2019, an unknown person gained unauthorized access to the email account of Fishbowl’s senior staff accountant. The person created email rules that redirected messages containing terms such as “invoice,” “wire transfer,” and “payment,” diverted other messages to a subfolder, and marked them as read. The person also sent messages while impersonating the accountant and Fishbowl’s client, Federated Insurance.

Fishbowl had sent Federated two invoices totaling $176,962. The unauthorized person persuaded Federated to send both payments to an account controlled by that person. Fishbowl later recovered $29,077.79, leaving $147,926.21 unrecovered.

Hanover insured Fishbowl under a Technology Professional Liability Policy. The policy included a Cyber Business Interruption and Extra Expense Clause covering actual loss of business income and additional expenses directly resulting from a data breach discovered during the policy period, if the breach caused an actual impairment or denial of business operations during that period. Hanover denied Fishbowl’s claim. Fishbowl sued, alleging that the denial breached the policy. Both parties moved for summary judgment, a procedure allowing judgment without a trial when no material fact is genuinely disputed and one party is entitled to judgment under the law.

Issues and governing law

The court applied Minnesota law, under which interpreting an insurance policy is a legal question governed by contract-interpretation principles. The policy must be read as a whole and according to the words the parties used. Undefined terms receive their ordinary meaning. Ambiguous language is generally interpreted in favor of the insured, while exclusions are read narrowly.

The court examined whether Fishbowl’s loss satisfied each requirement of the Clause: an actual loss of business income; a loss during the policy’s period of restoration; a loss directly resulting from a data breach; discovery of the breach during the policy period; and an actual impairment or denial of business operations during the policy period.

Court’s analysis

Business income and business operations. The policy defined “business income” to include net income that would have been earned if business operations had not been impaired by a covered data breach. It defined “business operations” as the insured’s “usual and regular business activities.” The court rejected Hanover’s argument that business operations meant only income-generating activities. The policy did not add that limitation, and the court would not insert it into the policy’s definition.

The court found that Fishbowl regularly communicated with clients and sent invoices for completed projects. Those activities therefore fell within “usual and regular business activities.” The court also rejected Hanover’s argument that Fishbowl had earned the money when it issued the invoices and was seeking only money it would have received. The court found that “earn” could include receiving or being entitled to receive money through work or another activity. Fishbowl would have received, or at least been entitled to, Federated’s payments absent the data breach. The court concluded that Fishbowl suffered an actual loss of business income of $147,926.21.

Period of restoration. The policy’s period of restoration began after the 24-hour waiting period following the first impairment of business operations and ended when operations were restored or 60 days after the impairment began, whichever was earlier. Fishbowl argued that the unauthorized access began in November 2019 and the fraudulent payments occurred in December 2019. Hanover did not directly challenge the timing; instead, it argued that there was no covered loss because Fishbowl’s revenue-generating activities were not interrupted. Because the court found an actual loss of business income, it also found that the loss occurred within the policy’s period of restoration.

Direct result of the data breach. Hanover argued that Federated’s alleged negligence or breach of contract was an intervening cause that prevented the loss from directly resulting from the data breach. The court declined to decide as a matter of law that Federated breached its contract or acted negligently. The contract did not specify a payment method, and the record did not establish that Federated was required to make a phone call or was negligent for communicating with the accountant by email. The court also found that minor grammatical errors in one fraudulent email did not establish negligence as a matter of law.

Because the loss would not have occurred without the unauthorized access and fraudulent emails, and because the record did not establish an intervening cause, the court found that the loss directly resulted from the data breach.

Impairment of business operations. The court interpreted “impairment” according to its ordinary meaning: an inability to function at full capacity. Fishbowl continued some activities, including communicating with clients and sending invoices, but it could not reliably communicate and send invoices at all times. The unauthorized person intercepted emails and sent fraudulent messages while impersonating Fishbowl’s employee. The court concluded that this interference diminished Fishbowl’s ability to conduct its regular business activities and therefore impaired its business operations.

Policy purpose and invoice-manipulation coverage. Hanover argued that coverage conflicted with the general purpose of business interruption insurance and that other insurance might specifically cover invoice manipulation. The court held that the policy’s actual language controlled. Unlike policies covering losses from an “interruption” of business, this Clause covered losses resulting from an “actual impairment or denial of service,” which included something less than a total shutdown. The policy did not expressly exclude invoice-manipulation coverage, and Hanover did not establish such an exclusion as a matter of law.

Disposition

The court found that Fishbowl’s loss satisfied every element of the Cyber Business Interruption and Extra Expense Clause and that the policy covered the loss. It granted Fishbowl’s Motion for Summary Judgment as to all claims, denied Hanover’s Motion for Summary Judgment as to all claims, and awarded Fishbowl $147,926.21 in damages. The court did not decide any request for prejudgment interest or attorney’s fees; it ordered Fishbowl to submit briefing on those issues by November 17, 2022, if it contended that such amounts were owed.

The authoritative version

Read the full 25-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.