What Cryptojacking Does to a Business
The basic trick is simple. An attacker gets access to a device or system and installs cryptocurrency mining software. That software quietly uses computing power in the background while the business carries on as normal.
The financial damage can still be real. Extra cloud usage creates unexpected bills. Systems can slow down. Security teams need time to investigate and remove the malicious code.
The Policy Wording Matters
Don’t assume that every cost connected to cryptojacking gets paid. Insurers look at the cause of the loss. They also look at what coverage you actually bought.
• Unauthorized system access is often the key detail, because cryptojacking usually starts with an attacker getting somewhere they shouldn’t.
• Cloud costs can become complicated. A policy may respond to certain incident-related expenses without automatically paying every oversized hosting bill.
• Business interruption coverage is another question entirely, especially if cryptojacking slows operations without actually stopping them.
• Some policies have exclusions for particular types of loss, so the definition of a covered cyber event deserves a close read.
What You Should Check Before a Claim
• Incident reports matter, even when the attack feels minor.
• Cloud invoices can show the extra computing costs, although you’ll want to separate normal usage from the spike caused by the attack.
You should also notify the insurer quickly and follow the policy’s reporting requirements. Waiting because “it’s only mining malware” is a bad move. Small incidents sometimes uncover a much bigger security problem.
So, Is Cryptojacking Covered?
In many cases, cyber insurance can cover losses caused by cryptojacking when the underlying attack falls within the policy’s coverage. But there isn’t a universal yes.
The strongest position is to check the policy before an incident happens. Look closely at coverage for unauthorized access and malware. Check the rules around business interruption too.