The Ace v. Congruity & Trustwave Subrogation Case Turns Into a Circular Firing Squad
An update dropped last week on a complex cyber insurance case that I’ve been following, and I took the weekend to read it.
When ransomware hits and the insurer pays the claim, the insurer goes hunting for someone to blame. Threat actors are notoriously difficult to collect from, so insurers increasingly pursue the vendors who were supposed to prevent the breach. Ace American Insurance, a Chubb subsidiary, paid roughly $500,000 to CoWorx Staffing Services after a 2024 ransomware attack and then sued both of CoWorx’s technology vendors to recover every dollar.
The case is live in the U.S. District Court for the District of New Jersey, and Congruity360’s Answer, Affirmative Defenses, and Crossclaims, filed August 21, 2026, doesn’t just push back on the allegations. It opens new fronts against the insured, the co-defendant, and the threat actors themselves.
How We Got Here
Ace’s version of the facts reads like a playbook for how not to configure a hosted environment, and Congruity disputes nearly all of it, repeatedly pointing the court to the MSA as ‘the best evidence’ of who owed what. CoWorx hired Massachusetts-based Congruity360 to host virtual machines (VMs) running Microsoft Windows at Congruity’s co-location facility. Under the Master Services Agreement (MSA) dated July 28, 2022, Congruity was responsible for securing the host virtualization servers and network, including remote access controls like multi-factor authentication (MFA). CoWorx separately retained Illinois-based Trustwave to monitor the guest-level VMs using CyberReason Managed Detection and Response (MDR) software, with logs feeding into Trustwave’s 24/7 Security Operations Center (SOC).
Incident Timeline
| Date | Event |
|---|---|
| April 18, 2024 | Threat actors log in using a compromised CoWorx credential. No MFA in place on Congruity infrastructure, Ace alleges. |
| April 22, 2024 | Trustwave’s Cybereason flags an LSASS event. Trustwave rates it below the “High”/”Critical” threshold – the complaint alternately calls it “Moderate” and “Medium” – which triggers an email-only notification rather than the email, phone, and application alert a higher rating would have required. |
| April 27, 2024 | Threat actors encrypt VMs at host level and deploy ransomware. CoWorx has no backups and purchases the decryptor. |
The compromised account didn’t have administrative access to any Congruity server, but attackers elevated permissions, dumped credentials from memory, and reached the VMWare ESX host server. The second amended complaint argues that no user should have been able to reach the host network from the guest network, full stop.
Ace paid the claim and filed suit in September 2025, originally charging both vendors with negligence, gross negligence, breach of contract, and breach of implied warranty. A second amended complaint, filed July 24, 2026 pursuant to a court order, narrowed to breach of contract only against both defendants.
What Congruity’s Filing Says
Congruity’s latest filing (Document 42) falls into three buckets:
The Answer
Congruity admits the contract existed and that it ran the ESX hosts, but disputes nearly every characterization of its obligations. It repeatedly directs the court to the contract itself as “the best evidence of its content and meaning,” which is a formal way of saying “read the document, not Ace’s summary.” Buried in the response to the breach allegation is a new fact that wasn’t in the complaint: Congruity asserts that CoWorx failed to disable a user account that was then used to access the VMs. That’s an affirmative allegation, not a denial, and it puts contributory fault by the insured directly in play.
Affirmative Defenses
Seven defenses are raised:
- Comparative and contributory fault of Trustwave and CoWorx, shrinking Congruity’s share proportionally.
- Failure to mitigate, targeting CoWorx’s lack of backups.
- Superseding cause, arguing that criminal acts by the threat actors and Trustwave’s intervening failures broke the causal chain.
- Limitation of liability under Section 11 of the MSA, capping aggregate liability at the total amount paid to Congruity and excluding consequential damages.
- Warranty disclaimer, disclaiming all implied warranties under the contract.
One defense to flag but not overindex on: the warranty disclaimer (Sixth Affirmative Defense) targets an implied-warranty claim the second amended complaint already dropped. It’s preserved as boilerplate, not a live front.
Crossclaims Against Trustwave
Congruity files both contribution and indemnification claims; no direct contract exists between them, so these are common law claims. The indemnification claim is the aggressive one, where Congruity characterizes its own conduct as “passive at most” and Trustwave’s as “active and primary.” Under the active/passive doctrine, a passively negligent party can shift entire liability to the actively negligent one. Congruity isn’t asking to split the bill. It’s trying to leave Trustwave holding all of it.
The Narrowed Claims Changed the Math
The original complaint looked like a scattergun, with four causes of action per vendor thrown at the wall. The second amended complaint drops everything except breach of contract, and that decision cuts both ways.
On Ace’s side, the remaining claims are cleaner. Breach of contract is binary: either you implemented the MSA’s required safeguards (MFA, network segmentation, intrusion detection) or you didn’t.
But on Congruity’s side, dropping gross negligence removed the primary legal argument courts use to invalidate liability caps. Courts generally enforce limitation of liability clauses absent gross negligence or willful misconduct. With gross negligence off the table, Congruity’s Section 11 defense faces a lower bar. If CoWorx was paying Congruity a modest monthly hosting fee, the cap could reduce the $500,000 exposure to whatever was paid over the contract term. That math gets painful fast for the insurer.
Since the only surviving claims are contractual, the entire case turns on interpreting the MSA. Every “best evidence” reference in the answer signals that the fight isn’t about what happened, but about what the contract said was supposed to happen and who bore which obligation.
Three-Way Blame Game
The CoWorx account disablement allegation deserves special attention. Ace is a subrogee, standing in CoWorx’s shoes, so any fault attributable to CoWorx reduces Ace’s recovery proportionally. New Jersey follows modified comparative negligence: if CoWorx is found more than 50% at fault, recovery drops to zero. That framework’s a tort doctrine, so expect Ace to argue it has no place in a contract-only case, which means the availability of comparative-fault reduction is itself a fight, not a given. Congruity’s assertion that CoWorx failed to disable the compromised account, plus the undisputed fact that CoWorx had no backups, gives Congruity a real argument that the insured contributed significantly to its own loss.
The crossclaims against Trustwave set up the circular firing squad. Congruity says Trustwave’s failure to properly categorize the LSASS alert and notify CoWorx was the real cause of the damage. Trustwave hasn’t filed its answer, but a mirror-image crossclaim against Congruity is the obvious response. Expect Trustwave to argue that the breach wouldn’t have happened at all if Congruity had enabled MFA and properly segmented the guest and host networks. Each vendor has a clean narrative where the other is to blame.
The superseding cause defense is the longest shot (and Congruity probably knows it). New Jersey courts recognize superseding cause where intervening acts are sufficiently independent of the original negligence. Congruity will need to show that the threat actors’ escalation, credential dumping, and host-level access weren’t foreseeable consequences of a missing MFA prompt. That’s a tough sell when the initial entry was allegedly facilitated by Congruity’s own configuration failures, but expect it to surface as a discovery battleground.
What I’m Watching For
- Trustwave’s answer. If it includes crossclaims against Congruity, the circular firing squad is complete.
- Discovery on MFA configuration. When was it supposed to be enabled, who was responsible, and why wasn’t it?
- The CoWorx account management practices. Did CoWorx fail to disable a known-compromised credential, and for how long?
- The limitation of liability defense. Whether Ace challenges it or accepts that the MSA caps exposure.
- Comparative fault allocation. How the court or jury assigns percentages across CoWorx, Congruity, and Trustwave.
The side with the best documentation tends to come out ahead in shared responsibility disputes. Right now, everyone’s still building their record.