EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/cna-financial-ransomware-2021
186/430

File EL-0245CriticalResolvedCyberattack / Ransomware / Insurance Sector

CNA Financial Ransomware Attack (2021)

Also filed as CNA Insurance Ransomware · $40M Ransom Payment

CNA Financial, one of the largest commercial insurance companies in the US, was hit by a Phoenix ransomware attack. The attackers encrypted 15,000 systems and demanded a ransom. CNA paid $40 million to restore operations — one of the largest ransom payments in history.

  • #cna-financial
  • #ransomware
  • #insurance
  • #phoenix-cryptolocker
  • #ransom-payment
  • #2021
Notoriety8/10
Event
21 Mar 2021
Disclosed
23 Mar 2021
Target
CNA Financial Corporation
Actor
Phoenix (CryptoLocker variant group)
Scale
15,000 devices encrypted
Status
Resolved

01Summary

On March 21, 2021, CNA Financial was struck by a sophisticated ransomware attack using the Phoenix CryptoLocker variant. The attack encrypted approximately 15,000 devices across the company's network, crippling operations. CNA was forced to take systems offline, disrupting insurance services. After negotiations with the attackers, CNA paid a $40 million ransom to obtain the decryption key. The payment was one of the largest publicly known ransom payments at the time. The attack was particularly ironic given CNA's position as a cyber insurance provider. The breach was attributed to the Phoenix ransomware group, with suspected links to the Russian cybercriminal group Evil Corp.

02Background

CNA Financial is one of the largest commercial property and casualty insurance companies in the US, providing a wide range of insurance products including cyber insurance. The irony of a major cyber insurer falling victim to a ransomware attack was widely noted.

03Key revelations

  1. 01A major cyber insurance company was itself vulnerable to ransomware.
  2. 02The $40M payment was one of the largest ever recorded.
  3. 03The attack highlighted the irony of insurers needing their own cyber coverage.

04Technical analysis

The attackers deployed the Phoenix CryptoLocker ransomware, which used sophisticated encryption to lock CNA's systems. The group gained initial access through unknown means and moved laterally to maximize the impact.

Attack vector
Unknown (likely phishing or vulnerability exploitation)
Attack method
Ransomware deployment
Tool / malware
Phoenix CryptoLocker
Malware family
Phoenix
Malware type
Ransomware

MITRE ATT&CK techniques

  • T1486

05Threat actor

The Phoenix ransomware group is associated with the Russian-speaking cybercriminal ecosystem. The group operates a RaaS model and has targeted large enterprises across multiple sectors.

Aliases

  • Evil Corp (alleged)

Attribution sources

  • CNA Disclosure
  • Security Researchers
  • Bloomberg

06Victims and impact

Countries affected

  • United States

07Financial damage

$40M ransom paid plus recovery and remediation costs.

08Timeline

  1. 2021-03-21Phoenix ransomware attack hits CNA Financial; 15,000 systems encrypted.
  2. 2021-03-23CNA takes systems offline; publicly discloses incident.
  3. 2021-04-15CNA restores systems after paying $40M ransom.

09On the record

We have no further comment on the scope of the attack nor the financial commitment made to resolve the incident.

CNA Financial Spokesperson, Response to questions about the $40M ransom.

10Reaction and fallout

Public reaction

The attack sent shockwaves through the cyber insurance industry, raising questions about the viability of the cyber insurance model.

Political impact

The incident intensified the debate over whether ransom payments should be banned or regulated.

11Legal

No arrests were made. The FBI investigated.

12Aftermath

Policy changes

  • Renewed calls to regulate or ban ransomware payments.

Security improvements

  • CNA implemented enhanced network segmentation and offsite backups.

13Significance and legacy

Significance

The CNA attack was one of the largest ransom payments in history and underscored the vulnerability of the insurance industry itself to cyberattacks.

Legacy

The incident raised fundamental questions about the cyber insurance industry's ability to assess and price risk when even insurers themselves could be crippled by ransomware.

14Disclosure and media

Authentication
Bloomberg reporting and CNA confirmation

Publishing organisations

  • CNA Financial

15Field notes

  1. 01CNA was one of the largest cyber insurance providers in the US at the time of the attack.
  2. 02The $40M ransom payment was more than double the Colonial Pipeline ransom ($4.4M) paid just weeks later.

16Resolution

Ransom paid. Systems restored after several weeks.

17Sources

Official documents

  • CNA statements (March-April 2021)

References

  1. [1]Bloomberg reporting
  2. [2]CNA corporate statements
  3. [3]Security researcher analysis
Fact sheetEL-0245

Dates

Event
21 Mar 2021
Started
21 Mar 2021
Ended
28 Mar 2021
Duration
26 days
Discovered
21 Mar 2021
Disclosed
23 Mar 2021
Resolved
15 Apr 2021
Ongoing
No

Target

Organisation
CNA Financial Corporation
Type
Corporation
Sector
Insurance / Financial Services
Country
United States

Actor

Name
Phoenix (CryptoLocker variant group)
Type
Criminal Gang
Nationality
Likely Russian/Eastern European
Motivation
Financial gain through ransom payment.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
15,000 devices encrypted
Sensitivity
Confidential
Published
No
Sold (dark web)
No

Money

Ransom asked
$40,000,000
Ransom paid
$40,000,000
Damage
$40,000,000
Crypto
Bitcoin (likely)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.