CNA Was Hit by a Cyberattack and Its Operations Were Impacted
CNA was the victim of a cyberattack that ended up impacting its business operations and shutting down the CNA website.
CNA Financial is a leading US-based insurance company, considered to be one of the sixth-largest commercial insurance companies in the USA, according to the Insurance Information Institute, providing a wide range of insurance products, including cyber insurance policies.
What do we know about the attack?
CNA was the victim of a cyberattack that ended up impacting its business operations and shutting down the CNA website.
The website started showing a message that stated they are “currently experiencing a network disruption that is impacting some of our systems. We are working to address these issues to minimize the disruption to you.”
It seems that the company could’ve suffered a cyberattack that has disrupted business operations and forced them to shut down specific systems.
CNA has confirmed that a cyberattack is the main reason for the network disruption, which also includes the corporate email, so in order to be safe, they decided to disconnect their systems from the network.
On March 21, 2021, CNA determined that it sustained a sophisticated cybersecurity attack. The attack caused a network disruption and impacted certain CNA systems, including corporate email.
Upon learning of the incident, we immediately engaged a team of third-party forensic experts to investigate and determine the full scope of this incident, which is ongoing. We have alerted law enforcement and will be cooperating with them as they conduct their own investigation.
Out of an abundance of caution, we have disconnected our systems from our network, which continue to function. We’ve notified employees and provided workarounds where possible to ensure they can continue operating and serving the needs of our insureds and policyholders to the best of their ability.
The security of our data and that of our insureds’ and other stakeholders is of the utmost importance to us and we are committed to continuing to serve them as we work to resolve this issue. Should we determine that this incident impacted our insureds’ or policyholders’ data, we’ll notify those parties directly.
Why is this attack extremely important?
All the attacks targeted towards insurance carriers are particularly dangerous as they may allow a ransomware operation to create a list of future targets covered under a cyber insurance policy.
Heimdal® Threat Prevention - Network
- No need to deploy it on your endpoints;
- Protects any entry point into the organization, including BYODs;
- Stops even hidden threats using AI and your network traffic log;
- Complete DNS, HTTP and HTTPs protection, HIPS and HIDS;
Recently REvil ransomware operation stated in an interview that insurers are really valuable targets because they can help the hackers to create lists of potential targets that are more likely to pay a ransom.
Yes, this is one of the tastiest morsels. Especially to hack the insurers first—to get their customer base and work in a targeted way from there. And after you go through the list, then hit the insurer themselves.
At the moment the attack on CNA has not been confirmed as a ransomware attack.