CNA Financial suffers extensive network disruption following cyber attack
The Chicago-based insurer took down its website and systems to mitigate potential damage from the attack
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Chicago-based CNA Financial, one of the country’s largest insurance providers, has been hit by a cyber attack that’s left its website out of action and many network systems disrupted.
The insurance firm is the sixth-largest in the US and offers an extensive range of products, including policies against cyber attacks.
On March 21, the firm revealed it sustained a sophisticated cyber security attack.
“The attack caused a network disruption and impacted certain CNA systems, including corporate email,” the company statement read.
“Upon learning of the incident, we immediately engaged a team of third-party forensic experts to investigate and determine the full scope of this incident, which is ongoing. We have alerted law enforcement and will be cooperating with them as they conduct their own investigation.”
It added that it disconnected systems from its network, “out of an abundance of caution,” notified employees, and provided workarounds where possible to ensure they can continue operating.
“The security of our data and that of our insureds ’and other stakeholders is of the utmost importance to us. Should we determine that this incident impacted our insureds’ or policyholders’ data, we’ll notify those parties directly,” said the company.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
CNA has also set up several email addresses to keep in contact with policyholders.
According to The Insurer, a publication serving the insurance industry, CNA’s network may be out of commission for a while, with the attack mainly impacting the underwriting and claims side of its business.
According to a tweet by Joshua Motta, CEO of security firm Coalition, there are rumors that the incident could be a ransomware attack. He added this could be a “nightmare scenario if cyber insurance policyholder data [is] compromised.”
Such data could give hackers information on how much money insurers could payout if a policyholder is attacked in the future. That would mean a hacker has more leverage over a victim, as they know how much money the insurer would pay out as a ransom. Such data could allow hackers to prioritize victims with larger or more comprehensive insurance policies.
CNA hasn’t yet revealed any further details of the attack or any lost or stolen data.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Proofpoint targets partner profitability with revamped channel programNews The Proofpoint Partner Network offers fresh incentives, investments, and expanded services to help partners capture AI-driven opportunities
-
86% of companies are reducing their VMware dependency post-Broadcom acquisitionNews Nearly two and a half years on from the Broadcom acquisition, VMware customers are steadily working to unwind their dependence
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwiseNews Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals
-
Everything we know so far about the Nike data breachNews Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Hacker offering US engineering firm data online after alleged breachNews Data relating to Tampa Electric Company, Duke Energy Florida, and American Electric Power was allegedly stolen
-
Cybersecurity experts face 20 years in prison following ransomware campaignTwo men used their tech expertise to carry out ALPHV BlackCat ransomware attacks
