CNA Financial is a leading US-based insurance company, considered to be one of the sixth-largest commercial insurance companies in the USA, according to the Insurance Information Institute, providing a wide range of insurance products, including cyber insurance policies.

What do we know about the attack?

CNA was the victim of a cyberattack that ended up impacting its business operations and shutting down the CNA website.

The website started showing a message that stated they are “currently experiencing a network disruption that is impacting some of our systems. We are working to address these issues to minimize the disruption to you.”

It seems that the company could’ve suffered a cyberattack that has disrupted business operations and forced them to shut down specific systems.

CNA has confirmed that a cyberattack is the main reason for the network disruption, which also includes the corporate email, so in order to be safe, they decided to disconnect their systems from the network.

On March 21, 2021, CNA determined that it sustained a sophisticated cybersecurity attack. The attack caused a network disruption and impacted certain CNA systems, including corporate email.

 Upon learning of the incident, we immediately engaged a team of third-party forensic experts to investigate and determine the full scope of this incident, which is ongoing. We have alerted law enforcement and will be cooperating with them as they conduct their own investigation.

 Out of an abundance of caution, we have disconnected our systems from our network, which continue to function. We’ve notified employees and provided workarounds where possible to ensure they can continue operating and serving the needs of our insureds and policyholders to the best of their ability.

 The security of our data and that of our insureds’ and other stakeholders is of the utmost importance to us and we are committed to continuing to serve them as we work to resolve this issue. Should we determine that this incident impacted our insureds’ or policyholders’ data, we’ll notify those parties directly.


Why is this attack extremely important?

All the attacks targeted towards insurance carriers are particularly dangerous as they may allow a ransomware operation to create a list of future targets covered under a cyber insurance policy.

Heimdal Official Logo
Your perimeter network is vulnerable to sophisticated attacks.

Heimdal® Threat Prevention - Network

Is the next-generation network protection and response solution that will keep your systems safe.
  • No need to deploy it on your endpoints;
  • Protects any entry point into the organization, including BYODs;
  • Stops even hidden threats using AI and your network traffic log;
  • Complete DNS, HTTP and HTTPs protection, HIPS and HIDS;
Try it for FREE today 30-day Free Trial. Offer valid only for companies.

Recently REvil ransomware operation stated in an interview that insurers are really valuable targets because they can help the hackers to create lists of potential targets that are more likely to pay a ransom.

Yes, this is one of the tastiest morsels. Especially to hack the insurers first—to get their customer base and work in a targeted way from there. And after you go through the list, then hit the insurer themselves.


At the moment the attack on CNA has not been confirmed as a ransomware attack. 

REvil Ransomware Group Threatens to Launch DDoS Attacks, Call Journalists and Business Partners

Banking and Insurance Cybersecurity in 2021: Threats and Considerations

Leave a Reply

Your email address will not be published. Required fields are marked *