01Summary
On March 21, 2021, CNA Financial was struck by a sophisticated ransomware attack using the Phoenix CryptoLocker variant. The attack encrypted approximately 15,000 devices across the company's network, crippling operations. CNA was forced to take systems offline, disrupting insurance services. After negotiations with the attackers, CNA paid a $40 million ransom to obtain the decryption key. The payment was one of the largest publicly known ransom payments at the time. The attack was particularly ironic given CNA's position as a cyber insurance provider. The breach was attributed to the Phoenix ransomware group, with suspected links to the Russian cybercriminal group Evil Corp.
02Background
CNA Financial is one of the largest commercial property and casualty insurance companies in the US, providing a wide range of insurance products including cyber insurance. The irony of a major cyber insurer falling victim to a ransomware attack was widely noted.
03Key revelations
- 01A major cyber insurance company was itself vulnerable to ransomware.
- 02The $40M payment was one of the largest ever recorded.
- 03The attack highlighted the irony of insurers needing their own cyber coverage.
04Technical analysis
The attackers deployed the Phoenix CryptoLocker ransomware, which used sophisticated encryption to lock CNA's systems. The group gained initial access through unknown means and moved laterally to maximize the impact.
- Attack vector
- Unknown (likely phishing or vulnerability exploitation)
- Attack method
- Ransomware deployment
- Tool / malware
- Phoenix CryptoLocker
- Malware family
- Phoenix
- Malware type
- Ransomware
MITRE ATT&CK techniques
- T1486
05Threat actor
The Phoenix ransomware group is associated with the Russian-speaking cybercriminal ecosystem. The group operates a RaaS model and has targeted large enterprises across multiple sectors.
Aliases
- Evil Corp (alleged)
Attribution sources
- CNA Disclosure
- Security Researchers
- Bloomberg
06Victims and impact
Countries affected
- United States
07Financial damage
$40M ransom paid plus recovery and remediation costs.
08Timeline
- 2021-03-21Phoenix ransomware attack hits CNA Financial; 15,000 systems encrypted.
- 2021-03-23CNA takes systems offline; publicly discloses incident.
- 2021-04-15CNA restores systems after paying $40M ransom.
09On the record
We have no further comment on the scope of the attack nor the financial commitment made to resolve the incident.
10Reaction and fallout
Public reaction
The attack sent shockwaves through the cyber insurance industry, raising questions about the viability of the cyber insurance model.
Political impact
The incident intensified the debate over whether ransom payments should be banned or regulated.
11Legal
No arrests were made. The FBI investigated.
12Aftermath
Policy changes
- Renewed calls to regulate or ban ransomware payments.
Security improvements
- CNA implemented enhanced network segmentation and offsite backups.
13Significance and legacy
Significance
The CNA attack was one of the largest ransom payments in history and underscored the vulnerability of the insurance industry itself to cyberattacks.
Legacy
The incident raised fundamental questions about the cyber insurance industry's ability to assess and price risk when even insurers themselves could be crippled by ransomware.
14Disclosure and media
- Authentication
- Bloomberg reporting and CNA confirmation
Publishing organisations
- CNA Financial
15Field notes
- 01CNA was one of the largest cyber insurance providers in the US at the time of the attack.
- 02The $40M ransom payment was more than double the Colonial Pipeline ransom ($4.4M) paid just weeks later.
16Resolution
Ransom paid. Systems restored after several weeks.
17Sources
Official documents
- CNA statements (March-April 2021)
References
- [1]Bloomberg reporting
- [2]CNA corporate statements
- [3]Security researcher analysis









