Desk live·
ForensicPost
Insurance/Ransomware/File 21-0323

CNA Financial Reportedly Paid $40 Million After a Fake Browser Update Locked 15,000 Devices

The seventh-largest U.S. commercial insurer, a seller of cyber cover, was encrypted on March 21, 2021, by Phoenix CryptoLocker. Bloomberg reported the payment two months later. CNA has never confirmed the amount, and its 75,349 notification letters went mostly to its own staff.

Constructed geometry · not a chart of case data
JurisdictionUSAChicagothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCNA Financial Corp.
ActorPhoenix (Evil Corp-linked, alleged)
S. Rosler11 min readConfidence: medium5 sources reviewed

CNA Financial Corp. said on March 23, 2021, that it had sustained a cyberattack two days earlier. According to the account its lawyers later gave New Hampshire’s attorney general, an employee’s workstation was compromised on March 5 by a fake browser update served after a visit to a legitimate website. The attackers spent two weeks moving through the network with stolen credentials and legitimate tools. On March 20 and 21 they disabled monitoring and security software, damaged backups, staged data from three virtual servers, exfiltrated it to a Mega.nz account and deployed ransomware.

BleepingComputer, citing its own sources, reported that more than 15,000 devices were encrypted. The ransom note identified the malware as Phoenix CryptoLocker. Researchers described it as a variant of Hades, a locker associated with Evil Corp, which the U.S. Treasury had sanctioned in December 2019.

Forty Million, Reported And Never Confirmed

On May 20, 2021, Bloomberg reported that CNA had paid $40 million in late March, about two weeks after the lockout, against an initial demand of $60 million. The report cited two people familiar with the matter. A House Oversight Committee memo of November 2021 quoted the attackers’ chat from March 23 demanding 999 bitcoin, then 1,099, and described the payment as reported. CNA has never stated the figure. If accurate, it was the largest ransomware payment then on record.

The sanctions question was live. The Treasury advisory filed at 20-1001 had been issued six months earlier and named insurers specifically. CNA’s position was that Phoenix was not a sanctioned entity and no U.S. agency had confirmed a link between the group and one. It said it consulted the FBI and the Office of Foreign Assets Control and followed the advisory. The Evil Corp connection remains a researcher and press assertion.

Who Was In The Data

CNA’s formal notice of July 9, 2021, and its Maine filing put the affected count at 75,349. More than 90% were employees, former employees and their dependents; the rest were some claimants and policyholders. Fields were name and Social Security number, and in fewer cases birth date, benefits enrolment and medical information. CNA said the FBI helped recover the data from the attackers’ Mega account and that it had no evidence the data was viewed or shared.

An Insurer Of Cyber Risk, As A Claim

CNA sells cyber insurance. It disclosed in November 2021 that its own coverage was unlikely to pay the incident in full. The file records the sector’s recursive position: the industry that prices ransomware was a ransomware victim whose reported payment set the market’s benchmark, and whose own policy did not cover it. The theme continues at 26-0603, where payments fell and claims rose.

How we reported this

Compiled from CNA’s formal notice and its counsel’s letter to the New Hampshire attorney general, Bloomberg’s report as syndicated, the House Oversight Committee memo and contemporaneous reporting, listed below. The $40 million figure rests on anonymous sources and is carried as reported, not confirmed; the file is graded medium on that basis. Corrections: corrections@forensicpost.com.

Sources
  1. Formal Notice of Cybersecurity Incident, July 9, 2021CNA Financial
  2. Notice to the New Hampshire Attorney General, July 8, 2021Norton Rose Fulbright for CNA
  3. CNA Financial Paid $40 Million in Ransom After March CyberattackClaims Journal (Bloomberg)
  4. Supplemental Memo on Ransomware Investigation, Nov. 16, 2021U.S. House Committee on Oversight and Reform
  5. Insurance giant CNA hit by new Phoenix CryptoLocker ransomwareBleepingComputer
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary