The attackers likely avoided that route because it would be easy to trace.
That’s likely the same reason that the insurance policy has special treatment for debit card/ATM incidents, because those sorts of transactions are more difficult to trace and therefore have a higher risk classification.
The fact there were two similar incidents 8 months apart tells me there was a fundamental security issue which wasn't addressed correctly.
It's possible, but the only evidence we have is that insurance companies want to avoid the payout, not that poor practices impacted premiums at all. Given what I've seen from security audits of the past, particularly when influenced by non-security professionals (such as the accountants in this scenario, both the insurers and the insured), I have little faith that if insurance companies dictate the practices that we'll get actual useful security increases, but plenty of extra bureaucratic hoops that will result in the same "productivity vs security _risk_" dilemma we have now, except the CBA changes to "is the hit to our productivity worth this hoop compared to the cost our lawyers would involve to prove this hoop was unnecessary or unrelated times the likelihood that it comes up"
What about Equifax?
The things actually specified in the contract, taking account the exclusions?
That said if too many "hacking insurance" policies fail to pay out, business are going to be less keen to use them.
Did you read this bit:
‘The second exclusion in the C&E rider negates coverage for “loss involving automated mechanical devices which, on behalf of the Insured, disburse Money, accept deposits, cash checks, drafts or similar Written instruments or make credit card loans . . ..”‘’
And never lose the opportunity to blame 'Russian' hackers.
“Foregenix .. determined the hacking tools and activity appeared to come from Russian-based Internet addresses .. according to the bank Verizon’s forensics experts concluded that the tools and servers used by the hackers were of Russian origin”
They're clever enough to hack a bank but not clever enough to disguise their IP address.
We expect the NSA to be compromising foreign systems. We don't expect them to be doing this with them.