CNA Financial, one of the largest insurance companies U.S., has paid a $40 million ransom to be freed from a ransomware attack it suffered in March, according to a new report from Bloomberg. The hackers who carried out the attack reportedly demanded $60 million when negotiations beganabout a week after some of CNA’s systems were encrypted, and the insurance company paid the lower amount of $40 million a week later.
If the $40 million figure is accurate, CNA's payment would rank as one of the highest ransom payments to ransomware gangs ever made public. Companies that have recently been hit by hackers and asked to pay high ransoms include Apple Acer and.
Read also: Six ransomware gangs have "hit" 292 organizations in 2021!

In both cases, companies and each was asked to pay a ransom of $50 million. It seems that hackers are increasingly demanding larger ransoms from their victims. Specifically, this week we saw reports that Colonial Pipeline (the company that manages the largest fuel pipeline in the US) paid a ransom of $4.4 million to a ransomware gang. While this amount is not as large as what CNA paid, it is still much higher than the estimated average ransom amount demanded by ransomware gangs in 2020.
See also: How long do ransomware groups stay on networks before being detected?
Law enforcement agencies recommend that victims of ransomware attacks not pay ransoms, as doing so encourages hackers to continue demanding higher and higher amounts, while also financially empowering them to carry out more attacks in the future.

CNA, for its part, told Bloomberg that it would not comment on the ransomware, but said it “followed all laws and regulations, and also published guidance, including OFAC ’s 2020 ransomware guidance , in handling this matter.”
Suggestion: Double encryption: The new technique used by ransomware groups
According to Bloomberg, the ransomware used against CNA was a derivative of one developed by the hacking group “Evil Corp.”
