From Casetext: Smarter Legal Research

City of Unalaska v. Nat'l Union Fire Ins. Co.

United States District Court, District of Alaska
Mar 18, 2022
591 F. Supp. 3d 440 (D. Alaska 2022)

Opinion

Case No. 3:21-cv-00096-SLG

2022-03-18

CITY OF UNALASKA, Plaintiff, v. NATIONAL UNION FIRE INSURANCE COMPANY, Defendant.

Brooks W. Chandler, Boyd, Chandler & Falconer, LLP, Anchorage, AK, for Plaintiff. Everett W. Jack, Jr., Davis Wright Tremaine LLP, Portland, OR, Michael Scott Broadwell, Pro Hac Vice, Davis Wright Tremaine LLP, Anchorage, AK, for Defendant.


Brooks W. Chandler, Boyd, Chandler & Falconer, LLP, Anchorage, AK, for Plaintiff.

Everett W. Jack, Jr., Davis Wright Tremaine LLP, Portland, OR, Michael Scott Broadwell, Pro Hac Vice, Davis Wright Tremaine LLP, Anchorage, AK, for Defendant.

ORDER RE PENDING MOTIONS

Sharon L. Gleason, UNITED STATES DISTRICT JUDGE

This order addresses two pending motions: (1) Defendant National Union Fire Insurance Company's ("National Union's") Motion for Judgment on the Pleadings at Docket 11; and (2) Plaintiff City of Unalaska's ("the City's") Motion for Summary Judgment at Docket 18. Oral argument was held on December 20, 2021.

The City responded in opposition at Docket 17, and National Union replied at Docket 21.

National Union responded in opposition at Docket 21, and the City replied at Docket 23.

See Docket 27 (Dec. 20, 2021 Hearing Tr.).

BACKGROUND

This action stems from an insurance dispute regarding coverage for computer fraud under the City of Unalaska's Government Crime Policy ("the Policy") with National Union Fire Insurance Company. The undisputed facts are as follows:

On April 11, 2019, the City's Accounts Payable Assistant received an email purportedly sent by one of the City's regular vendors, Northern Alaskan Contractors ("NAC"), requesting a copy of the City's "ACH/EFT form" in order to change its method of receiving payments for invoices from paper checks to electronic ACH transfers. The email was not in fact from NAC but rather from a person whom both parties term a "fraudster." On the same day, another City employee emailed the fraudster an ACH form and advised them that even after receipt of the completed form, it would take at least ten days for the City to process the request before issuing payments. The fraudster returned the completed ACH form by email, designating a Citibank Account in New York as the new method for receiving payments.

Docket 1-1 at 6–7, ¶¶ 18–22 (Compl.).

See, e.g. , Docket 1-1 at 7, ¶ 22; Docket 11 at 1; Docket 17 at 2.

Docket 1-1 at 7, ¶ 24.

Docket 1-1 at 7, ¶¶ 25–26.

The following day, the fraudster sent another email asking about receiving payment of an invoice, and the City responded by email that it could not yet make the payment because additional steps needed to be taken to process the request, as conveyed in its previous email. On April 18, 2019, the City advised the fraudster by email that its Controller had given verbal authorization for future payments by ACH. Between May 7, 2019 and July 9, 2019, the City initiated ACH payments for several NAC invoices totaling $2,985,406.10 to the fraudster's Citibank account. On July 10, 2019, the City discovered the fraud and reported it to the FBI. It was able to recover close to $2.35 million, resulting in a net loss of $637,861.67. The City submitted a claim for the loss to National Union, which accepted coverage under the Impersonation Fraud Coverage endorsement of the Policy and paid the City the $100,000 policy limits of that coverage, reducing the loss to $537,861.67. The City requested coverage for this remaining amount under the Computer Fraud Insuring Agreement ("CFIA") of the Policy, but National Union responded that no coverage was available under that provision because the City's claim "[did] not directly involve the use of any computer to fraudulently cause a transfer of property from inside the premises to a person or place outside the premises." Following National Union's partial denial of coverage, the City also received a $22,500 payment from Alaska Public Entity Insurance, reducing the total remaining loss to $515,631.67.

Docket 1-1 at 8, ¶¶ 31–32.

Docket 1-1 at 8, ¶ 35.

Docket 1-1 at 8–9, ¶¶ 36, 40.

Docket 1-1 at 9, ¶¶ 37–39.

Docket 1-1 at 9, ¶ 40.

Docket 1-1 at 9–10, ¶¶ 42–45; Docket 12-1 at 50 (Levy Decl., Ex. A).

Docket 1-1 at 10, ¶¶ 46–47.

Docket 17-1 at 3, ¶ 8 (Hanson-Zueger Aff.) (identifying the City's loss as $515,361.37, an apparent $0.30 error).

The City filed this action for breach of contract and declaratory relief in Alaska state court on March 22, 2021, alleging that National Union breached its contractual duty to provide coverage for the City's loss under the CFIA. On April 15, 2021, National Union removed the case to federal court on the basis of diversity jurisdiction.

Docket 1-1 at 3–4, ¶¶ 1–6.

Docket 1 (Notice of Removal).

The Government Crime Policy in question was issued to Alaska Public Entity Insurance with effective dates of July 1, 2019 to July 1, 2020 and extends coverage to the City as an additional insured. The Impersonation Fraud Coverage endorsement of the Policy amends the Funds Transfer Fraud Agreement to add:

See Docket 12-1 at 2; Docket 1-1 at 5, ¶ 14.

[National Union] will also pay for loss of "funds" resulting directly from a "fraudulent instruction" directing a financial institution to transfer, pay or deliver "funds" from your "transfer account."

Notwithstanding the above requirement that the loss of "funds" result directly from a "fraudulent instruction," we will also pay for the loss of "funds" resulting from your receipt of a "fraudulent instruction" from a purported vendor, which advises you that the vendor's bank account information has been changed and you suffer a loss of "funds."

Docket 12-1 at 49.

The Policy also includes the aforementioned CFIA, which states:

[National Union] will pay for loss of or damage to "money," "securities" and "other property" resulting directly from the use of any computer to fraudulently cause a transfer of that property from inside the "premises" or "banking premises" ... [t]o a person (other than a "messenger") outside those "premises" [ ] or ... [t]o a place outside those "premises."

Docket 12-1 at 5.

The CFIA has a policy limit of $1 million, subject to a $25,000 deductible.

Docket 12-1 at 2.

The parties filed the instant motions in July and September 2021, each asserting that it is entitled to judgment as a matter of law. The parties agree that there are no disputed facts and that Alaska law applies.

See Docket 17 at 9, 35; Docket 21 at 3–4; Docket 27 at 4, 20; see also Erie R.R. Co. v. Tompkins , 304 U.S. 64, 78, 58 S.Ct. 817, 82 L.Ed. 1188 (1938).

LEGAL STANDARDS

I. Judgment on the Pleadings

Federal Rule of Civil Procedure 12(c) provides that "[a]fter the pleadings are closed—but early enough not to delay trial—a party may move for judgment on the pleadings." "Judgment on the pleadings is properly granted when there is no issue of material fact in dispute, and the moving party is entitled to judgment as a matter of law." When deciding such a motion, the court "accept[s] all factual allegations in the complaint as true and construe[s] them in the light most favorable to the non-moving party." The court may consider documents relied on in a complaint without converting the motion for judgment on the pleadings to one for summary judgment.

Fleming v. Pickard , 581 F.3d 922, 925 (9th Cir. 2009).

Herrera v. Zumiez, Inc. , 953 F.3d 1063, 1068 (9th Cir. 2020).

See Lee v. City of Los Angeles , 250 F.3d 668, 688–89 (9th Cir. 2001), overruled on other grounds by Galbraith v. County of Santa Clara , 307 F.3d 1119 (9th Cir. 2002).

II. Summary Judgment

Federal Rule of Civil Procedure 56(a) directs a court to "grant summary judgment if the movant shows that there is no genuine dispute as to any material fact and the movant is entitled to judgment as a matter of law." The burden of showing the absence of a genuine dispute of material fact lies with the movant. If the movant meets this burden, the non-moving party must demonstrate "specific facts showing that there is a genuine issue for trial." In deciding a motion for summary judgment, "a court must view the evidence ‘in the light most favorable to the opposing party.’ " Even when, as here, "both parties assert[ ] that there are no uncontested issues of material fact," a court still has the independent "responsibility to determine whether disputed issues of material fact are present."

Celotex Corp. v. Catrett , 477 U.S. 317, 325, 106 S.Ct. 2548, 91 L.Ed.2d 265 (1986).

Id. at 324, 106 S.Ct. 2548 (quoting Fed. R. Civ. P. 56(e) ); Anderson v. Liberty Lobby, Inc. , 477 U.S. 242, 248–49, 106 S.Ct. 2505, 91 L.Ed.2d 202 (1986).

Tolan v. Cotton , 572 U.S. 650, 657, 134 S.Ct. 1861, 188 L.Ed.2d 895 (2014) (quoting Adickes v. S.H. Kress & Co. , 398 U.S. 144, 157, 90 S.Ct. 1598, 26 L.Ed.2d 142 (1970) ); see also Anderson , 477 U.S. at 255, 106 S.Ct. 2505.

United States v. Fred A. Arnold, Inc. , 573 F.2d 605, 606 (9th Cir. 1978).

DISCUSSION

There are no genuine disputes of material fact regarding the events leading to Unalaska's loss, the amount of the loss, or the applicable policy language. The only dispute between the parties is whether the CFIA applies to the City's loss, resolution of which calls for interpretation of the Policy.

See Docket 1-1 at 5–10, ¶¶ 14–47; Docket 3 at 3–4, ¶¶ 14–47 (Answer); Docket 17 at 35; Docket 21 at 3–4.

Because this is a diversity action, Alaska law applies to interpretation of the Policy. Generally, Alaska courts construe insurance contracts "so as to provide that coverage which a layperson would have reasonably expected from a lay interpretation of the policy terms." An insured's expectation of coverage must be "objectively reasonable." To determine an insured's reasonable expectations, Alaska courts look to: "1) the language of the disputed policy provisions; 2) the language of other policy provisions; 3) relevant extrinsic evidence; and 4) case law interpreting similar provisions." "Construction of an insurance policy under the principle of reasonable expectations does not depend on a prior determination of policy ambiguity," but "where a clause in an insurance policy is ambiguous the court accepts that interpretation which most favors the insured." However, "[t]he mere fact that the parties disagree about the proper interpretation of the contract does not mean the contract is ambiguous." Rather, an ambiguity exists only when "inconsistent, but reasonable, interpretations of the contract are possible."

See Erie R.R. Co. v. Tompkins , 304 U.S. 64, 78, 58 S.Ct. 817, 82 L.Ed. 1188 (1938).

Downing v. Country Life Ins. Co. , 473 P.3d 699, 704 (Alaska 2020) ("Under this doctrine of reasonable expectations, the policyholder's ‘objectively reasonable expectations’ govern, even if ‘painstaking study of the policy provisions would have negated those expectations.’ " (quoting Allstate Ins. Co. v. Teel , 100 P.3d 2, 4 (Alaska 2004) )).

West v. Umialik Ins. Co. , 8 P.3d 1135, 1138 (Alaska 2000) (quoting State v. Underwriters at Lloyds London , 755 P.2d 396, 400 (Alaska 1988) ); see also State Farm Fire & Cas. Co. v. Bongen , 925 P.2d 1042, 1047 (Alaska 1996) ("[S]ince most insureds develop an expectation that every loss will be covered, the reasonable expectation doctrine ‘must be limited by something more than the fervent hope usually engendered by loss.’ " (quoting Millar v. State Farm Fire & Cas. Co. , 167 Ariz. 93, 804 P.2d 822, 826 (Ct. App. 1990) )).

Bongen , 925 P.2d at 1047 ; see also C.P. ex rel. M.L. v. Allstate Ins. Co. , 996 P.2d 1216, 1223 (Alaska 2000).

Bering Strait Sch. Dist. v. RLI Ins. Co. , 873 P.2d 1292, 1295 (Alaska 1994) ; see also C.P. ex rel. M.L. , 996 P.2d at 1228.

Nelson v. Progressive Cas. Ins. Co. , 162 P.3d 1228, 1234 (Alaska 2007).

Id.

National Union contends that a reasonable insured would not expect coverage based on the language of the policy for two reasons. First, National Union asserts that a reasonable insured would not consider the "incidental" use of email to perpetuate a fraud to constitute "computer fraud." The insurer asserts that "[c]omputerization [has] become pervasive in nearly every method of human communication that is not in person," so the "incidental use of a computer as the means of communication does not turn every act of fraud that involves the incidental use of a computer into computer fraud." Rather, National Union maintains, "[t]he computer fraud insurer agreement covers computer hacking ‘like the introduction of malicious computer code.’ "

See Docket 11 at 7–11.

Docket 21 at 4–5.

Docket 21 at 6 (citing Taylor & Lieberman v. Fed. Ins. Co. , 681 Fed. App'x 627, 629 (9th Cir. 2017) ).

Second, National Union contends that the City's loss is not covered under the CFIA because the use of a computer was not the "direct cause" of the loss. The insurer asserts that "directly" means "to ‘proceed’ ‘without deviation or interruption’ " and thus CFIA coverage is only triggered if "the Fraudster's use of a computer ... directly bring[s] about the funds transfer." National Union suggests that the Court should follow a "direct means direct" approach rather than a "proximate cause" approach, but maintains that Unalaska's claim would fail even under a proximate cause approach "because of the significant and substantial intervening acts and actors, between the fraudulent communication and the authorized transfers by Unalaska." Moreover, the insurer asserts that Unalaska's claim "lacks directness from a temporal standpoint." The insurer maintains that other sections of the Policy should have made this interpretation of "resulting directly" clear to the City, as the Impersonation Fraud Coverage endorsement uses both the phrase "resulting" and the phrase "resulting directly," implying that the two have different meanings and that the latter requires more immediacy.

See Docket 11 at 2, 11–14.

Docket 21 at 5–6 (quoting Direct , Merriam-Webster, https://www.merriam-webster.com/dictionary/direct (last visited Mar. 9, 2022)).

Docket 21 at 10–11.

Docket 21 at 13.

Docket 27 at 6–8.

National Union explains that there were "many intervening events between the Fraudster's email communications and the insured's final decision to issue ACH payments"; the City internally processed the change of payment request, worked with its bank to set up the ACH payment process, and obtained approval from the Controller and Director of Public Works before reviewing the invoices and authorizing ACH payments to the fraudster's account. More than thirty days passed between the fraudster's initial email and the City's first ACH payment to the fraudster's account. Thus, National Union maintains that the City's loss did not "result[ ] directly from the Fraudster's emails" but rather was "temporally remote and involved a chain of intervening and independent steps and decisions that did not involve the fraudster."

Docket 11 at 12–13 (citing Docket 1-1 at 8–9, ¶¶ 33, 35, 36).

Docket 11 at 13 (citing Docket 1-1 at 7–9, ¶¶ 25, 36).

Docket 11 at 14.

In response, the City first contends that the ordinary meaning of the phrase "use of any computer" creates a reasonable expectation of coverage because "[v]irtually everyone that is familiar with e-mail knows that sending and receiving e-mails requires computer hardware and computer software." If "the policy language is lagging the pervasive use of computers and emails," the City asserts, "the solution is to change the language, not to improperly deny coverage." Indeed, the City maintains that National Union could have worded the CFIA more narrowly if it intended to limit coverage to "hacking," pointing to examples of other insurance policies. A different National Union policy, for example, defined "Computer Systems Fraud" as "[l]oss resulting directly from a fraudulent (1) entry of Electronic Data or Computer Program into, or (2) change of Electronic Data or Computer Program within the Insured's proprietary Computer System." The City also highlights a later iteration of the computer fraud policy at issue in Ernst & Haas Management Co. v. Hiscox, Inc. , which stated that "[c]omputer fraud does not include any fraudulent transfer of money, securities, or other property which required you, your employees, your executive employees, or others on your behalf to take any action in order to complete the transfer of such money, securities, or other property."

Docket 17 at 12–13.

Docket 23 at 9–10.

Docket 17 at 14–16; Docket 27 at 28–29.

Docket 17 at 14–15 (quoting Universal Am. Corp. v. Nat'l Union Fire Ins. Co. of Pittsburgh , 25 N.Y.3d 675, 37 N.E.3d 78, 79 (N.Y. 2015) ).

Case No. CV 20-04062-AB (PVCx), 2020 WL 6789095 (C.D. Cal. Nov. 5, 2020), rev'd , Ernst & Haas Mgmt. Co. v. Hiscox, Inc. , 23 F.4th 1195 (9th Cir. 2022).

Docket 17 at 15–16 (quoting Ernst & Haas , 2020 WL 6789095, at *2 ). The district court in Ernst & Haas ultimately did not consider this definition, which was part of a more recent 2019 version of the relevant insurance policy, because it found that the insured's loss was not covered under the original 2012 version of the policy. See 2020 WL 6789095, at *2, *5.

Second, the City disputes National Union's interpretation of the phrase "resulting directly from," asserting that the ordinary meaning of the phrase is "proximately caused by." The City maintains that a reasonable insured would not expect the policy language to exclude "all instances in which an employee of the insured had to act after receipt of a fraudulent e-mail," given that "[c]omputer frauds that involve duping employees into revealing their network passwords are legion." The City also points to the context in which "resulting directly" is used, noting that "[t]he policy speaks to directly causing a transfer," not " ‘effectuating’ or ‘making’ a transfer, which might more closely suggest to a reasonable lay person that something like ‘hacking’ is required, or that acts by employees would sever the ‘causal chain.’ "

Docket 17 at 13, 32–35.

Docket 17 at 14.

Docket 23 at 10.

Both parties agree that this case presents an issue of first impression in Alaska and offer authority from other jurisdictions as guidance for interpretation of the CFIA. "When the state's highest court has not squarely addressed an issue," federal courts "must ‘predict how the highest state court would decide the issue using intermediate appellate court decisions, decisions from other jurisdictions, statutes, treaties and restatements for guidance.’ "

Docket 17 at 1; Docket 23 at 2; Docket 27 at 4.

First Intercontinental Bank v. Ahn , 798 F.3d 1149, 1157 (9th Cir. 2015) (quoting Glendale Assocs., Ltd. v. Nat'l Lab. Rels. Bd. , 347 F.3d 1145, 1154 (9th Cir. 2003) ).

National Union notes that the CFIA and similar provisions have been the subject of prior litigation in the Ninth Circuit and maintains that those cases "have uniformly held that an impersonation fraud scheme like that at issue [here] does not trigger coverage under the [CFIA]." It first points to Pestmaster Services, Inc. v. Travelers Casualty & Surety Co. of America , 656 Fed. App'x 332 (9th Cir. 2016), an unpublished case involving an identical CFIA in a Travelers insurance policy. In that case, the plaintiff had electronically transferred funds to a payroll services company that was hired to handle the plaintiff's employee salaries and payroll taxes using those funds, but the company then failed to pay the plaintiff's payroll taxes with the transferred funds. The plaintiff asserted that it was entitled to coverage for this loss under the CFIA. The Ninth Circuit disagreed, holding that the CFIA's definition of computer fraud—"[t]he use of any computer to fraudulently cause a transfer"—required an "unauthorized transfer of funds." The court reasoned that "[b]ecause computers are used in almost every business transaction, reading this provision to cover all transfers that involve both a computer and fraud at some point in the transaction would convert this Crime Policy into a ‘General Fraud’ Policy."

Docket 11 at 7.

Docket 11 at 8; Pestmaster Servs., Inc. v. Travelers Cas. & Sur. Co. of Am. , Case No. CV 13-5039-JFW (MRWx), 2014 WL 3844627, at *4–5 (C.D. Cal. July 17, 2014) (applying California law), aff'd in part, vacated in part, Pestmaster , 656 Fed. App'x 332.

Pestmaster , 2014 WL 3844627, at *1.

Pestmaster , 656 Fed. App'x at 333.

Id.

National Union also identifies Taylor & Lieberman v. Federal Insurance Co. , 681 Fed. App'x 627 (9th Cir. 2017), an unpublished case in which a fraudster impersonated the plaintiff's client via email to send wire payment instructions. There, the relevant insurance policy provided coverage for a "direct loss sustained by an Insured resulting from Computer Fraud committed by a Third Party." The Ninth Circuit held that "under a common sense reading of the policy, [the fraudster's email was] not the type of instructions that the policy was designed to cover, like the introduction of malicious computer code."

Docket 11 at 9–10; Taylor & Lieberman v. Fed. Ins. Co. , Case No. CV 14-3608 RSWL, 2015 WL 3824130, at *1 C.D. Cal. June 18, 2015 (emphasis omitted) (applying California law).

Taylor & Lieberman , 2015 WL 3824130, at *3.

Taylor & Lieberman , 681 Fed. App'x at 629.

Further, National Union points to a pair of unpublished cases from the Fifth Circuit: Apache Corp. v. Great Am. Ins. Co. , 662 Fed. App'x 252 (5th Cir. 2016) and Mississippi Silicon Holdings, L.L.C. v. Axis Ins. Co. , 843 Fed. App'x 581, 584 (5th Cir. 2021) (per curiam). In Apache , the Fifth Circuit adopted Pestmaster ’s reasoning and held that the CFIA did not cover a loss similar to the City's, concluding that "the email was merely incidental to the occurrence of the authorized transfer of money." In Mississippi Silicon Holdings , which National Union incorrectly describes as a Sixth Circuit case at multiple points in its briefing, the Fifth Circuit held that a "Computer Transfer Fraud" provision was inapplicable to a loss similar to the City's, reasoning that "the mere receipt of an email does not constitute computer fraud in the context of similar insurance provisions." Finally, National Union also cites a number of district court and state court decisions with varying levels of factual similarity to the case at bar, including Ernst & Haas , a Central District of California decision that has since been overturned by the Ninth Circuit and is discussed more extensively below. The City, by contrast, maintains that this Court should adopt the reasoning of a Sixth Circuit decision, American Tooling Center, Inc. v. Travelers Casualty & Surety Co. of America . In that case, the insured received "a series of emails, purportedly from its Chinese vendor, claiming that the vendor had changed its bank accounts and [the insured] should wire transfer its payments to these new accounts," and the insured completed three wire transfers before discovering the fraud. The insured's Travelers policy covered the "direct loss of, or direct loss from damage to, Money, Securities and Other Property directly caused by Computer Fraud," which the policy defined as "[t]he use of any computer to fraudulently cause a transfer of Money, Securities or Other Property from inside the Premises or Financial Institution Premises ... to a person (other than a Messenger) outside the Premises or Financial Institution Premises; or ... to a place outside the Premises or Financial Institution Premises."

Docket 11 at 10; Docket 21 at 7.

Apache , 662 Fed. App'x at 253–54, 256, 258–59 (applying Texas law).

Docket 21 at 2, 7–8.

843 Fed. App'x at 582–84 (applying Mississippi law). The Computer Transfer Fraud provision at issue defined "Computer Transfer Fraud" as "the fraudulent entry of Information into or the fraudulent alteration of any Information within a Computer System." Id. at 584.

See Docket 11 at 10, 12 (citing Ernst & Haas , 2020 WL 6789095 ); Docket 21 at 8 (citing Methodist Health Sys. Found., Inc. v. Hartford Fire Ins. Co. , 834 F. Supp. 2d 493 (E.D. La. 2011) ; Great Am. Ins. Co. v. AFS/IBEX Financial Servs., Inc. , Case No. 3:07-CV-924-O, 2008 WL 2795205 (N.D. Tex. 2008) ; Brightpoint, Inc. v. Zurich Am. Ins. Co. , Case No. 1:04-CV-2085-SEB-JPG, 2006 WL 693377 (S.D. Ind. 2006) ; Kraft Chem. Co., Inc. v. Fed. Ins. Co. , Case No. 13 M2 002568, 2016 WL 4938493, at *6 (III. Cir. Ct. Jan. 5, 2016) ; Universal Am. Corp. v. Nat'l Union Fire Ins. Co. of Pittsburgh, Pa. , 38 Misc.3d 859, 959 N.Y.S.2d 849 (2013) ; Northside Bank v. Am. Cas. Co. of Reading , Case No. GD 97-19482, 2001 WL 34090139 (Pa. Ct. Com. PI. Jan. 10, 2001) ).

895 F.3d 455 (6th Cir. 2018) ; Docket 17 at 22–25.

Am. Tooling Ctr. , 895 F.3d at 457.

Id. at 459, 461.

The Sixth Circuit, applying Michigan law, held that the insured's loss was covered under the CFIA, rejecting several arguments similar to those made by National Union here. Travelers, like National Union, relied on Pestmaster to argue against coverage, but the court found Pestmaster distinguishable on its facts because, in that case, "everything that occurred using the computer was legitimate and the fraudulent conduct occurred without the use of a computer." Travelers also "attempt[ed] to limit the definition of ‘Computer Fraud’ to hacking and similar behaviors in which a nefarious party somehow gains access to and/or controls the insured's computer," but the court concluded that this argument was "not well-founded" because "[i]f Travelers had wished to limit the definition of computer fraud to such criminal behavior it could have done so." Further, the Sixth Circuit concluded that the insured's loss was "directly caused" by the fraud even though "[t]he chain of events that was precipitated by the fraudulent emails and led to the wire transfers involved multiple internal actions [by the insured]." In support of this conclusion, the court cited a Michigan Court of Appeals decision that stated that "[t]he use of the word ‘direct’ signals ‘immediate’ or ‘proximate’ cause, as distinct from remote or incidental causes."

Id. at 461–63.

Id. at 461.

Id. at 462.

Id.

Id. (citing Acorn Inv. Co. v. Mich. Basic Prop. Ins. Ass'n , Case No. 284234, 2009 WL 2952677, at *2 (Mich. Ct. App. Sept. 15, 2009) ).

In addition to American Tooling Center , the City highlights Principle Solutions Group, LLC v. Ironshore Indemnity, Inc. , a case in which the Eleventh Circuit, applying Georgia law, concluded that "the ordinary meaning of the phrase ‘resulting directly from’ requires proximate causation between a covered event and a loss, not an ‘immediate’ link." The court conceded that " ‘directly’ can sometimes mean ‘immediately,’ " but cautioned that "discerning the ordinary meaning of a term requires more than uncritically citing dictionaries." Rather, the Eleventh Circuit reasoned, "reading the phrase ‘resulting directly from’ as a whole requires us to define ‘directly’ within the context of causation[, a]nd in that context, ‘directly’ means ‘proximately.’ " In addition to Principle Solutions , the City cites two other federal cases—from the Second Circuit and the Eastern District of Virginia—that also held that employees’ unwitting facilitation of fund transfers did not sever the causal chain when the relevant policy language required that losses result "directly" from the fraudulent action.

944 F.3d 886, 891 (11th Cir. 2019) ; Docket 17 at 26.

Principle Sols. , 944 F.3d at 891.

Id. at 892 (citing Directly , Webster's Third New International Dictionary; Direct Cause , Black's Law Dictionary (11th ed. 2019)).

Docket 17 at 26–29 (citing Medidata Sols., Inc. v. Fed. Ins. Co. , 729 Fed. App'x 117 (2d Cir. 2018) (applying New York law) ; Cincinnati Ins. Co. v. Norfolk Truck Ctr., Inc. , 430 F. Supp. 3d 116 (E.D. Va. 2019) (applying Virginia law) ).

Neither party has directed the Court's attention to the Ninth Circuit's recent decision in Ernst & Haas , which was published after briefing and oral argument on the instant motions. There, an insurer denied coverage under a CFIA identical to the provision at issue here when the insured's employee "was directed by fraudulent email requests and payment invoices to transfer ... funds to a swindling third party." The district court granted the insurer's motion to dismiss, finding that the Ninth Circuit's unpublished decision in Pestmaster was "relatively on point" and concluding that the loss was not covered under the computer fraud provision because "the relevant wire transfers were authorized and the ... imposter's fraudulent emails did not directly cause the transfer of any funds."

Ernst & Haas , 23 F.4th 1195.

Id. at 1196–97 ; Ernst & Haas , 2020 WL 6789095, at *1 ("With regards to ‘(1) Computer Fraud,’ the 2012 Policy provides that Hiscox ‘will pay for loss of or damage to Money, Securities and/or Other Property resulting directly from the use of any computer to fraudulently cause a transfer of that property from inside the Premises or Banking Premises: (i) to a person (other than a Messenger) outside those Premises or Banking Premises; or (ii) to a place outside those Premises or Banking Premises.’ ").

Ernst & Haas , 2020 WL 6789095, at *5–6.

The Ninth Circuit reversed the district court's decision, holding that the insured's loss was covered by the CFIA. First, the panel concluded that the district court wrongly relied solely on Pestmaster because that case involved "dispositively different" facts. In Pestmaster , the fraudulent action was the embezzlement of funds after the funds were properly authorized for payment, whereas the insured's loss in Ernst & Haas was due to transferring funds based on a fraudulent email authorization. Second, the panel determined that the district court engaged in an "improperly narrow reading of the contractual language" when it interpreted the CFIA to mean that "a direct loss is limited to unauthorized computer use, like hacking." Instead, the panel found the Sixth Circuit's reasoning in American Tooling persuasive on this point, concluding that the insured's loss "result[ed] directly" from the fraud despite the fact that an unwitting employee authorized the wire transfers.

Ernst & Haas , 23 F.4th at 1202.

Id. at 1200.

Id. at 1200–01.

Id. at 1200.

Id. at 1201–02.

After examining the policy language and case law interpreting similar provisions, the Court finds that a reasonable insured would expect coverage under the CFIA. By its plain language, the CFIA applies under these circumstances; the City experienced a loss of money resulting directly from the fraudster's use of a computer—sending an email impersonating the City's vendor—to fraudulently cause a transfer of funds from the City to the fraudster's bank account. The ubiquity of computer usage does not alter the fact that a reasonable layperson would consider the phrase "use of a computer" to encompass a broad range of activities, including sending emails, rather than being limited to instances of computer hacking. Interpreting "use of a computer" in this manner will not, as National Union cautions, turn the CFIA and similar provisions into "general fraud" policies. As the Sixth Circuit noted in distinguishing Pestmaster from American Tooling , the CFIA would not cover circumstances in which "everything that occurred using the computer was legitimate and the fraudulent conduct occurred without the use of a computer," such as the embezzlement that occurred in Pestmaster following a properly authorized electronic funds transfer.

See Bongen , 925 P.2d at 1047.

Am. Tooling , 895 F.3d at 461.

Further, the plain language of the CFIA does not require more than proximate causation for coverage. The Court finds the reasoning of the Eleventh Circuit in Principle Solutions persuasive on this point—though the word "directly" may connote immediacy when read in isolation, a reasonable insured would consider the phrase "resulting directly from" to convey the concept of proximate cause. The Court's finding is unaltered by the fact that the Impersonation Fraud Coverage endorsement, a provision that appears 44 pages after the CFIA in the Policy, may imply a distinction between "directly resulting" and "resulting." This is precisely the kind of "painstaking study of ... policy provisions" that the Alaska Supreme Court eschews when gauging an insured's reasonable expectations of coverage.

See Direct Cause , Black's Law Dictionary (11th ed. 2019) (equating "direct cause" to "proximate cause").

See Docket 12-1 at 5, 49.

See Downing , 473 P.3d at 704.

National Union's contention that the City's claim fails even under a proximate-cause analysis is unavailing. Under Alaska law, "proximate cause requires only that the general kind of harm be foreseeable for an actor's conduct to be considered the proximate cause of the plaintiff's injuries." While National Union characterizes the unwitting actions of City employees in authorizing the funds transfer as "significant and substantial" acts that broke the causal chain, the fraudster's email was clearly intended to bring about those actions. The City's loss was a foreseeable kind of harm arising from a fraudulent email scheme. In addition to the plain language of the CFIA, the weight of relevant authority in other jurisdictions indicates that the CFIA provides coverage under these circumstances. The Court finds the reasoning of the Sixth Circuit in American Tooling and the Ninth Circuit in Ernst & Haas particularly persuasive as both those cases concerned near-identical CFIAs and factually similar fraudulent schemes. While those cases were applying Michigan and California law rather than Alaska law, their reasoning is still persuasive, particularly because Michigan and California law on insurance contract interpretation is less favorable to insureds than Alaska's pure reasonable expectations approach.

Winschel v. Brown , 171 P.3d 142, 149 (Alaska 2007) (citing Dan B. Dobbs, The Law of Torts 466 (2001 & Supp. 2007)).

See Docket 21 at 10–11.

Relatedly, the Court finds that the Ninth Circuit's unpublished decision in Taylor & Lieberman , cited by National Union, has little persuasive weight here given that the Ninth Circuit has since issued a published decision in Ernst & Haas that comes to a different conclusion on what it means for a loss due to computer fraud to be "direct."

California applies "general rules of contract interpretation" to insurance policies and only analyzes the reasonable expectations of the insured if the court finds a term ambiguous; Michigan follows a similar approach. See MacKinnon v. Truck Ins. Exch. , 31 Cal.4th 635, 3 Cal.Rptr.3d 228, 73 P.3d 1205, 1212 (Cal. 2003) ; In re K F Dairies, Inc. & Affiliates , 224 F.3d 922, 925 (9th Cir. 2000) ; Citizens Ins. Co. v. Pro-Seal Serv. Grp., Inc. , 477 Mich. 75, 730 N.W.2d 682, 685–86 (Mich. 2007) ; see also Umialik , 8 P.3d at 1143 (distinguishing Alaska's approach from that of jurisdictions that "require a finding of ambiguity before applying the doctrine of reasonable expectations").

The majority of cases cited by National Union, on the other hand, are distinguishable. In Apache , the Fifth Circuit was clear that its decision was made "[b]earing in mind the limited weight accorded ... non-binding authority, as well as Texas’ policy preference for cross-jurisdictional uniformity." Given that several published decisions have since concluded that the CFIA is applicable to losses similar to the City's, the Apache court may well have reached a different conclusion. Apache also relied on the reasoning of Pestmaster , which, as discussed above, has since been distinguished on a factual basis by the Sixth and Ninth Circuits. Mississippi Silicon Holdings , too, is distinguishable because it concerned a "Computer Transfer Fraud provision" different in key respects from the CFIA at issue here. That provision required that the fraudulent transfer occur "without the Insured Entity's knowledge or consent" and defined "computer transfer fraud" as the fraudulent entry or alteration of information in the insured's computer system, essentially limiting coverage to "instances in which a computer itself is tricked into fraudulently transferring funds." Finally, the Court agrees with the City that the majority of the lower court decisions cited by National Union are distinguishable as they involved different policy language more focused on computer hacking or factually different fraudulent schemes where the use of a computer was more incidental. Thus, among cases involving similar insurance provisions and fraudulent schemes, the balance of authority indicates that the CFIA covers the City's loss.

See id. at 258 (stating that, at the time Apache was decided, "there [was] cross-jurisdictional uniformity in declining to extend coverage when the fraudulent transfer was the result of other events and not directly by the computer use").

See Am. Tooling , 895 F.3d at 461–62 ; Ernst & Haas , 23 F.4th at 1200–01 ; see also Docket 17 at 30–31 ("It was not the transfer itself that was wrongful but the payroll services company's subsequent failure to make the payroll tax payments. Here, the transfer itself was unauthorized from the outset.").

843 Fed. App'x at 584–85, 587.

Docket 23 at 3–5.

CONCLUSION

Based on the plain language of the CFIA and factually similar cases from other jurisdictions, and bearing in mind Alaska's approach to interpreting insurance contracts, the Court finds that the CFIA provides coverage for the City's loss. The City's Motion for Summary Judgment at Docket 18 is therefore GRANTED, and National Union's Motion for Judgment on the Pleadings at Docket 11 is DENIED. The Clerk of Court is directed to enter a Final Judgment for the City in the amount of $515,631.67.


Summaries of

City of Unalaska v. Nat'l Union Fire Ins. Co.

United States District Court, District of Alaska
Mar 18, 2022
591 F. Supp. 3d 440 (D. Alaska 2022)
Case details for

City of Unalaska v. Nat'l Union Fire Ins. Co.

Case Details

Full title:CITY OF UNALASKA, Plaintiff, v. NATIONAL UNION FIRE INSURANCE COMPANY…

Court:United States District Court, District of Alaska

Date published: Mar 18, 2022

Citations

591 F. Supp. 3d 440 (D. Alaska 2022)

Citing Cases

Interstate Removal, LLC v. Nat'l Specialty Ins. Co.

” City of Unalaska v. Nat'l Union Fire Ins. Co., 591 F.Supp.3d 440, 451 (D. Alaska 2022); see…