Homesite Challenges United Airlines' Cyber Insurance Claim in Court
In a significant legal dispute, Homesite Insurance Company is contesting United Airlines' claim for business interruption losses stemming from a cyber outage caused by CrowdStrike. This article delves into the implications of this case for the insurance industry and the broader impact on businesses facing cyber risks.

The increasing frequency and severity of cyber incidents have prompted many businesses to invest in comprehensive cyber insurance policies, yet the complexities surrounding these claims can lead to legal disputes that shape the future of the industry. A current high-stakes case involves Homesite Insurance Company challenging a business interruption claim from United Airlines linked to a 2024 cyber outage caused by a faulty CrowdStrike Falcon update. This dispute not only highlights the intricacies of cyber insurance but also raises questions about the adequacy of coverage and the responsibilities of both insurers and insured parties in the event of a cyber incident.
On July 20, 2026, Homesite filed a complaint in the US District Court for the Northern District of Illinois, seeking a judicial declaration that it is not liable for United Airlines' claim stemming from a significant disruption in its operations. The case underscores the evolving landscape of cyber insurance as companies grapple with the fallout from cyber incidents and the legal frameworks that govern their insurance contracts.
Understanding the Cyber Incident
The incident at the heart of this case occurred on July 19, 2024, when a problematic update to the CrowdStrike Falcon cybersecurity software resulted in a major outage for United Airlines. This failure led to significant operational disruptions, including flight cancellations and payment processing issues at airports. According to Homesite's complaint, United was able to restore its systems by July 22, 2024, with only one flight cancellation on that day. However, the aftermath of the outage raises several key questions regarding the nature of compensable losses under the terms of United's cyber insurance policy.
The Claims Process: A Complex Landscape
As is standard in the insurance industry, United Airlines submitted a claim for business interruption losses approximately a year after the incident, on June 18, 2025. This claim included a detailed spreadsheet outlining the financial impact of the outage, but Homesite argues that the basis for the claim is flawed. Central to the dispute is Homesite's assertion that United is attempting to recover for losses for which it has already been compensated by third parties.
Homesite's excess policy, which provides coverage beyond the primary policy issued by Lexington Insurance Company, carries a limit of $5 million and is structured to follow the terms of the primary coverage. However, the policy includes specific language that disallows any recovery for losses that have already been compensated by another source. This provision raises critical issues regarding the validity of United's claims and the extent to which it may have already received compensation from third parties.

Disputed Loss Categories
Two primary categories of loss are currently under dispute in this case: customer compensation payments and downstream revenue losses. Homesite contends that United's claims for customer compensation, which included cash payments, travel certificates, and other forms of goodwill gestures, were not only issued without the insurers' prior consent but also lack the legal justification that would qualify them as necessary under the terms of their policy.
Customer Compensation Payments
- Electronic Travel Certificates: Marketed as gestures of goodwill, these payments were issued to customers impacted by the outage.
- Cash Payments: United provided direct compensation to affected passengers, raising questions about whether such payments were legally mandated.
- Frequent-Flyer Awards: Awards and bonuses given to customers during the disruption, which Homesite argues were non-essential.
According to Homesite, United has not provided any specific legal references that would substantiate its claims that these payments were required by law. The absence of such documentation could significantly weaken United's position in the ongoing legal battle.

Downstream Revenue Losses
The second point of contention involves claims for downstream revenue losses. Homesite argues that United has claimed losses from flight segments that were not canceled but instead proceeded as scheduled following the restoration of systems. United's methodology for calculating these losses, which allegedly relied on an agreed flight-value method intended solely for canceled flights, has come under scrutiny. Homesite contends that United has not adequately justified its assumptions or provided verifiable data to support its claims.
Legal and Operational Implications
This case brings to light several crucial issues affecting the cyber insurance landscape:
- Retention Erosion: The question of how retention, or the amount an insured must pay before coverage kicks in, is impacted by prior recoveries from other sources.
- Double Recovery Concerns: The challenge of ensuring that insured parties do not seek compensation more than once for the same loss.
- Proof-of-Loss Requirements: The necessity for claimants to provide substantial documentation and evidence supporting their claims.
Moreover, Homesite's complaint indicates that United did not provide the final report from the forensic accountant tasked with quantifying the loss, further complicating the claims process. The outcome of this case could set a precedent for how similar disputes are resolved in the future, particularly as businesses increasingly rely on cyber insurance to protect against the growing threat of cyberattacks.

Key Takeaways
- Homesite Insurance is contesting United Airlines' cyber insurance claim regarding a July 2024 outage.
- The case centers on allegations of double recovery and the validity of customer compensation payments.
- The outcome may influence future cyber insurance claims and the responsibilities of businesses and insurers.
- Documentation and proof of loss are critical components of successful claims in the cyber insurance arena.
Frequently Asked Questions
What is cyber insurance, and why is it important for businesses?
Cyber insurance is a specialized form of insurance designed to protect businesses from the financial fallout of cyber incidents, including data breaches, ransomware attacks, and system outages. As cyber threats continue to evolve, more companies are recognizing the importance of having robust cyber insurance policies in place to mitigate the risks associated with these incidents. It offers coverage for loss of income due to business interruptions, liability for data breaches, and costs associated with recovering compromised systems.
What factors can affect a business's eligibility for cyber insurance coverage?
Several factors can influence a business's eligibility for cyber insurance, including the size of the organization, the nature of its operations, the industry it operates within, and its overall cybersecurity posture. Insurers typically assess a company's risk profile, evaluating its cybersecurity measures, data protection protocols, and incident response plans before underwriting a policy. Businesses that demonstrate robust cybersecurity practices may be more likely to secure favorable coverage terms.
How can businesses prepare for potential cyber insurance claims?
Businesses can take several proactive steps to prepare for potential cyber insurance claims. This includes maintaining comprehensive documentation of all cybersecurity incidents, implementing effective incident response plans, and ensuring that all employee training is up to date. Additionally, businesses should regularly review and update their insurance policies to ensure they align with their evolving risk landscape and operational needs. By being prepared, companies can streamline the claims process and increase their chances of successful recovery in the event of a cyber incident.
Comments
Lloyd's Investigation Reveals Compliance Breaches by Former CEO John Neal
An investigation by the Council of Lloyd's has revealed that former CEO John Neal breached compliance rules, raising significant concerns about governance and accountability within the organization. The findings call for a re-evaluation of leadership standards and whistleblower protections at Lloyd's.

Related articles
Popular in Business Insurance
- Surging War-Risk Insurance Rates in the Strait of Hormuz: What It Means for Shipping
- Ross & Yerger Insurance Faces Class Action Over Data Breach Allegations
- Indiana Court Ruling: Insurers Can Deny Fire Claims Without Proving Harm
- WTW's Strategic AI Investment: A Game Changer for Insurance Brokerage
- How AI is Transforming Excess and Surplus Lines Underwriting






