© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company

Cyber Insurance Recovery Alert
Recently, in Perry & Perry Builders Inc. v. Cowbell Cyber Inc., 2026 WL 673558 (W.D. Tex. Mar. 9. 2026), the United States District Court for the Western District of Texas delivered a cautionary decision for policyholders navigating cyber insurance claims – particularly those involving social engineering fraud and sub-limited coverage. While many coverage disputes turn on whether a loss falls within a policy’s coverage grant, this case instead concerns how much coverage is available for a loss that your insurance company acknowledges is covered.
Disputes over sublimits have emerged recently as a flashpoint in cyber coverage claims in particular. As my colleague Joshua Gold recently noted, courts in New York and Texas recently have rejected companies’ attempts to improperly invoke sublimits to reduce their coverage obligations – underscoring that the placement, scope and clarity of sublimits in cyber policies demands special scrutiny.
Background Facts
The dispute arose after Perry & Perry Builders, Inc. (“Perry”) fell victim to a social engineering scheme that resulted in two fraudulent wire transfers. The transfers were made after a fraudster impersonating Perry’s steel vendor requested payment of two outstanding (legitimate) invoices be sent to a particular Chase bank account different from the account on file for the steel vendor. Perry wired over $874,000 into the Chase bank account controlled by the fraudster. The money was wired as two separate payments corresponding to the two outstanding invoices Perry believed it was paying to its steel vendor.
After discovering the fraud, Perry sought coverage under its cyber insurance policy purchased from Cowbell Cyber, Inc. and Obsidian Specialty Insurance Company. Although the insurance companies did not dispute that the loss fell within the policy’s coverage, they only paid Perry $250,000, arguing that Perry’s recovery was capped by a $250,000 sublimit for social engineering fraud. Perry sued on the basis that it was entitled to an additional $250,000 because each wire transfer represented a separate “claim.” Accordingly, Perry argued that it was entitled to recover the $250,000 per claim sublimit twice – once for each separate transfer.
Analysis of Court Decision
The court rejected Perry’s argument, finding that Perry acted volitionally in separating the payments into two separate transfers, made one minute apart, and refused to allow what it characterized as Perry’s “booking choices” to dictate the number of claims. Instead, the court concluded that an endorsement in the policy capped the limit of liability at $250,000 for all Perry’s cyber losses during the policy period regardless of the number and value of each such loss.
In so ruling, the court did not find ambiguity in the terms of the policy sufficient to justify a reading in favor of coverage. Rather, it concluded that the policy, when read as a whole, supported the insurance companies’ interpretation that the sublimit functioned as a single aggregate cap for the type of loss at issue. The fact that multiple transfers occurred did not alter that conclusion. As such, the court ruled in favor of the insurance companies, finding that they owed no further obligations to Perry.
For policyholders, the implications of this decision are significant. First, it underscores that the existence of coverage is only part of the analysis. Even where a loss clearly falls within the scope of a cyber policy, insurance companies may attempt to use other provisions in the policy to reduce a policyholder’s actual recovery. In this case, the sublimit for social engineering fraud reduced Perry’s recovery.
Second, the decision highlights the need to understand the effect of sublimits and their potential use by insurance companies to try and reduce their payments on covered claims. Sublimits are frequently embedded in endorsements addressing specific risks. It is critical for policyholders to identify and evaluate whether their policies include sublimits for particular coverages, including social engineering coverage, funds transfer fraud, and invoice manipulation, that may be substantially lower than the policy’s per claim limit – particularly, as noted above, in cyber policies.
Third, the decision underscores the critical importance of how a loss is characterized. Cyber-related losses frequently implicate multiple insuring agreements, and insurance companies may seek to characterize a claim in a manner that confines it to the most restrictive coverage grant – often one subject to a significantly lower sublimit than the policy’s overall limit. To mitigate this risk, policyholders should refrain from identifying or limiting their claims to specific coverage grants when providing notice. Rather, the insurance company bears the responsibility of evaluating coverage under all potentially applicable insuring agreements, not merely those that most narrowly circumscribe its exposure.
In sum, Perry & Perry Builders Inc. is not a case about denying coverage – it is a case about limiting it. For policyholders, the lesson is clear: understanding and negotiating sublimits is just as important as securing broad insuring agreements. Without that focus, even a successful claim may yield a fraction of the expected recovery.


© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company