CNA Financial Corp. said on March 23, 2021, that it had sustained a cyberattack two days earlier. According to the account its lawyers later gave New Hampshire’s attorney general, an employee’s workstation was compromised on March 5 by a fake browser update served after a visit to a legitimate website. The attackers spent two weeks moving through the network with stolen credentials and legitimate tools. On March 20 and 21 they disabled monitoring and security software, damaged backups, staged data from three virtual servers, exfiltrated it to a Mega.nz account and deployed ransomware.
BleepingComputer, citing its own sources, reported that more than 15,000 devices were encrypted. The ransom note identified the malware as Phoenix CryptoLocker. Researchers described it as a variant of Hades, a locker associated with Evil Corp, which the U.S. Treasury had sanctioned in December 2019.
Forty Million, Reported And Never Confirmed
On May 20, 2021, Bloomberg reported that CNA had paid $40 million in late March, about two weeks after the lockout, against an initial demand of $60 million. The report cited two people familiar with the matter. A House Oversight Committee memo of November 2021 quoted the attackers’ chat from March 23 demanding 999 bitcoin, then 1,099, and described the payment as reported. CNA has never stated the figure. If accurate, it was the largest ransomware payment then on record.
The sanctions question was live. The Treasury advisory filed at 20-1001 had been issued six months earlier and named insurers specifically. CNA’s position was that Phoenix was not a sanctioned entity and no U.S. agency had confirmed a link between the group and one. It said it consulted the FBI and the Office of Foreign Assets Control and followed the advisory. The Evil Corp connection remains a researcher and press assertion.
Who Was In The Data
CNA’s formal notice of July 9, 2021, and its Maine filing put the affected count at 75,349. More than 90% were employees, former employees and their dependents; the rest were some claimants and policyholders. Fields were name and Social Security number, and in fewer cases birth date, benefits enrolment and medical information. CNA said the FBI helped recover the data from the attackers’ Mega account and that it had no evidence the data was viewed or shared.
An Insurer Of Cyber Risk, As A Claim
CNA sells cyber insurance. It disclosed in November 2021 that its own coverage was unlikely to pay the incident in full. The file records the sector’s recursive position: the industry that prices ransomware was a ransomware victim whose reported payment set the market’s benchmark, and whose own policy did not cover it. The theme continues at 26-0603, where payments fell and claims rose.
Compiled from CNA’s formal notice and its counsel’s letter to the New Hampshire attorney general, Bloomberg’s report as syndicated, the House Oversight Committee memo and contemporaneous reporting, listed below. The $40 million figure rests on anonymous sources and is carried as reported, not confirmed; the file is graded medium on that basis. Corrections: corrections@forensicpost.com.
- Formal Notice of Cybersecurity Incident, July 9, 2021CNA Financial
- Notice to the New Hampshire Attorney General, July 8, 2021Norton Rose Fulbright for CNA
- CNA Financial Paid $40 Million in Ransom After March CyberattackClaims Journal (Bloomberg)
- Supplemental Memo on Ransomware Investigation, Nov. 16, 2021U.S. House Committee on Oversight and Reform
- Insurance giant CNA hit by new Phoenix CryptoLocker ransomwareBleepingComputer