Desk live·
ForensicPost
Insurance/Market/File 21-0506

AXA Became the First Major Insurer to Stop Reimbursing Ransomware Payments, in France Only

The decision announced May 6, 2021, followed a French Senate roundtable where prosecutors argued that insured ransoms fund the next attack. It applied to new policies in one country and left response and recovery cover in place. Nine days later AXA’s Asian units were hit.

Constructed geometry · not a chart of case data
JurisdictionFranceParisthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFrench cyber insurance market
ActorUnattributed
S. Rosler8 min readConfidence: high3 sources reviewed

AXA said on May 6, 2021, that it would stop writing cyber insurance policies in France that reimburse extortion payments to ransomware criminals. The Associated Press described the move as an apparent industry first. The decision followed a roundtable in the French Senate in April at which justice and cybersecurity officials had argued that insurance reimbursement was sustaining the ransomware economy. Paris cybercrime prosecutor Johanna Brousse was quoted saying that regarding ransomware, “we don’t pay and we won’t pay.”

The change applied to France only, did not affect existing policies and left in place coverage for incident response and recovery. Emsisoft estimated French ransomware losses at more than $5.5 billion in 2020, second only to the United States.

The Argument Against Paying, Made By The Payer

The case against ransom reimbursement had been made by governments for years. An insurer making it was new. The economics are direct: a criminal who knows the victim is insured knows the money exists and who will authorise it. The REvil operator interviewed by Recorded Future in March 2021 had said that hacking insurers first, to read their customer lists, was among the most attractive targets available. AXA’s decision removed one line item from that calculation for one market.

What It Left In Place

The policy still paid for forensics, restoration, legal costs and business interruption. Those are the larger costs in most incidents and the ones an insurer can price. The excluded item was the one the criminal sets. Whether that changed any attacker’s behaviour was never established, and the attack on AXA’s own Asian operations nine days later, filed at 21-0516, was read by many as a reply, without any evidence that it was one.

The Market Did Not Follow

No other major carrier adopted the same position. The industry’s response instead ran through underwriting: multifactor authentication requirements, backup attestations and the rescission case filed at 22-0826b, where a misstatement about controls voided the policy. Ransom reimbursement remained standard cover outside France. The corpus recorded at 26-0603 that payments eventually fell anyway, for reasons that had more to do with victims than with insurers.

How we reported this

Compiled from Associated Press reporting as carried by Insurance Journal, Euronews and Carrier Management, listed below. No AXA France primary release was located; the scope of the decision is as the company’s spokesperson described it to AP. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Insurer AXA to Stop Paying for Ransomware Crime Payments in FranceInsurance Journal (AP)
  2. Cybercrime: Insurance giant AXA to stop covering ransomware payments in FranceEuronews (AP)
  3. AXA Won’t Cover Ransomware Extortion Payments Anymore in FranceCarrier Management
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary