CNA Financial reportedly paid $40 million to regain access to systems following a ransomware attack disclosed in March, a sum described as potentially the largest publicly known ransom payment at the time. The insurer said it worked with federal law enforcement during the response, disconnected affected systems, and conducted due diligence on the threat actor before making any payment. CNA said the actor was identified as Phoenix and was not found on the Treasury Department's Office of Foreign Assets Control (OFAC) sanctions list.
After the incident, CNA said it deployed additional endpoint detection and monitoring tools, removed the attacker from its environment, and found no evidence that external customers faced infection or cross-contamination. The case drew wider attention because CNA is a major cyber insurer, making it a high-value target for ransomware groups seeking both sensitive client data and leverage over ransom negotiations, while also underscoring the legal and financial risks of payments involving sanctioned groups such as Evil Corp or REvil.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
CNA later stated that the threat actor was no longer present in its environment. It also said there was no evidence that external customers faced infection or cross-contamination risk from the incident.
By the time of its May 2021 public response, CNA said it had coordinated with federal law enforcement and followed OFAC guidance during its handling of the incident. The company said its due diligence identified the threat actor as Phoenix and that it was not on OFAC's prohibited entities list.
Following the March ransomware attack, CNA Financial reportedly paid attackers $40 million to regain access to its files and systems. Bloomberg described the payment as potentially the largest publicly known ransom payment at that time.
In March 2021, CNA Financial disclosed a ransomware incident and disconnected affected systems to contain the attack. The company later deployed additional endpoint detection and monitoring tools as part of its response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.