Study Reveals M&A Deals May Increase Ransomware Insurance Claims

In a recent report published on Tuesday, Resilience, a firm specializing in cyber risk management, highlighted that ransomware continues to be a significant threat, with 64% of ransomware-related claims within its portfolio resulting in losses since January 2023.

The rise in mergers and acquisitions, along with increased dependency on widespread software providers, has offered new opportunities for cybercriminals. These attackers exploit single points of failure, making ransomware attacks more widespread, the report notes.

Vishaal Hariprasad, CEO of Resilience, emphasized the need for a new perspective on cyber risk management at the executive level. “In today’s interconnected business environment, a company’s resilience is intrinsically linked to the stability of its partners and industry peers,” Hariprasad stated in a press release.

According to Ernst & Young, global merger and acquisition activity surged by 36% in the first quarter of this year. While this uptick may signal economic optimism, Resilience warns it also opens up fresh vulnerabilities for cyber threats.

The report reveals that many of the most damaging cyber incidents over the past year involved systems with high interconnectivity or companies recently acquired. Vendor-related claims have become the fastest-growing category in Resilience’s portfolio, now representing the leading cause of financial loss from claims.

This year, vendor failures have accounted for 40% of all claims, a figure anticipated to rise. Additionally, the financial impact of ransomware claims has soared by 411% from 2022 to 2023, the study finds.

One notable case is the ransomware attack on Change Healthcare, a subsidiary of UnitedHealth Group, which occurred in February. Change Healthcare, crucial to healthcare billing, suffered significant disruption. UnitedHealth subsequently revised its estimated financial impact of the attack to between $2.3 billion and $2.45 billion, a $1 billion increase from earlier forecasts, as reported by CFO Dive’s sister publication, Healthcare Dive.

UnitedHealth had acquired Change Healthcare for $13 billion in 2022, overcoming a Department of Justice attempt to block the acquisition on antitrust grounds.

Resilience points out that mergers and acquisitions can exacerbate cyber risks, not only due to existing vulnerabilities but also due to new risks from the acquisition and the complexities of integrating disparate IT systems post-acquisition.

While cybersecurity due diligence is commonly conducted during M&A processes, the report underscores that this practice does not fully eliminate risk but rather helps to identify potential vulnerabilities.

More Articles & Posts