CNA Financial Corporation, a leading insurance company based in the US, informs customers of a data breach following a ransomware attack by Phoenix CryptoLocker that hit its systems in March.
CNA is considered the seventh largest commercial insurance company in the US based on statistics from the Insurance Information Institute.
The company offers a wide range of insurance products, including cyber insurance policies, to individuals and businesses across the US, Canada, Europe, and Asia.

See also: Ransomware businesses: Negotiators are in high demand
Over 75,000 people were affected
The data breach reported by CNA affected 75,349 people, according to information filed with the office of the Attorney General of Maine.
After examining the stolen files during the attack, CNA discovered that they contained customers' personal data (names and social security numbers).
The company added that “it was able to quickly recover this information and there was no indication that the data had been stolen.”
Furthermore, CNA claims that there is no reason to suspect that the stolen information was used or will be used in any way.
See also: Kaseya REvil ransomware: Over 1,500 companies affected
Systems fully restored after ransomware attack
Sources familiar with the attack told BleepingComputer that the operators of Phoenix CryptoLocker encrypted over 15,000 devices after deploying the ransomware payloads on CNA's network on March 21.
BleepingComputer also learned that the intruders encrypted the computers of employees who were working remotely and had connected to the company's VPN during the incident.
Based on code similarities, Phoenix Locker is believed to be a new ransomware family developed by the hacking group Evil Corp to avoid sanctions, as WastedLocker ransomware victims will no longer pay ransoms.
When asked about the link between Evil Corp and the Phoenix group, CNA responded that there was no confirmed relationship.
See also: REvil ransomware Kaseya: Hackers demand $70 million to decrypt all systems
Two months ago, CNA said it had restored systems affected by the ransomware attack and was operating “smoothly.” The insurance provider added that it had found no evidence that its users’ data was being offered for sale on the dark web or hacking forums.
Information source: bleepingcomputer.com
