Desk live·
ForensicPost
Insurance/Coverage/File 22-0826b

Travelers Voided a Cyber Policy From Inception Because the Application Said MFA Was in Place

An Illinois electronics manufacturer was hit by ransomware in May 2022, a month into its policy year. Its insurer found multifactor authentication only on the firewall, sued to rescind in July, and by Aug. 26 the policyholder had agreed the policy never existed.

Constructed geometry · not a chart of case data
JurisdictionUSADecaturthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetInternational Control Services Inc.
ActorUnattributed
D. Kennedy8 min readConfidence: high3 sources reviewed

On Aug. 26, 2022, a federal court in Illinois entered a stipulated judgment declaring a cyber insurance policy issued by Travelers Property Casualty Co. of America to International Control Services Inc. rescinded and void from its inception. No coverage would be available for any past, present or future claim. Each side bore its own costs. The policy had been in force since April 4, 2022. ICS, an electronics manufacturing services company in Decatur, Illinois, had suffered a ransomware attack in May.

Travelers had sued on July 6. Its complaint said the application, signed in March 2022 by the company’s president and a person responsible for its network security, stated that ICS used multifactor authentication for administrative or privileged access. The post-incident investigation found the compromised server had no MFA and that the control existed only on the firewall. The misrepresentation, Travelers argued, materially affected its acceptance of the risk.

Rescission, Not Denial

The remedy matters. A denied claim leaves the policy in place and the dispute about one loss. Rescission treats the contract as never having existed, returns the premium and removes every claim under it, including ones nobody has made yet. ICS did not contest it. The case is the first widely reported instance of a cyber policy being unwound over an application answer about a security control.

The Control The Market Chose

By 2022 multifactor authentication was the underwriting question. Carriers had spent 2021 absorbing ransomware losses and had settled on MFA as the one control they could ask about in a checkbox and verify after a loss. The corpus later filed at 26-0416 that control failures had become the most common ground for cyber-claim disputes. Travelers v. ICS is where that practice acquired a precedent: the application is a warranty, and the insurer will check.

The people who signed were an executive and a network manager attesting to something that was partly true. MFA existed. It was not where the application said it was, and the difference between a firewall and a server cost the company its entire policy at the moment it needed it.

How we reported this

Compiled from Insurance Journal’s reporting of the complaint and the stipulated judgment, and from broker and law-firm analyses of the case, listed below. One secondary source gives later dates for the filing and order; the two concurring trade reports are used. No ransom figure or attacker was reported. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Travelers Wants Out of Contract With Insured That Allegedly Misrepresented MFA UseInsurance Journal
  2. Travelers, Policyholder Agree to Void Current Cyber PolicyInsurance Journal
  3. Travelers v. ICS underscores need to respond carefully to cyber insurance applicationsLockton
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary