HomeSecurityCNA reports data breach after ransomware attack

CNA reports a data breach after the ransomware attack

CNA Financial Corporation, a leading insurance company based in the US, informs customers of a data breach following a ransomware attack by Phoenix CryptoLocker that hit its systems in March.

CNA is considered the seventh largest commercial insurance company in the US based on statistics from the Insurance Information Institute.

The company offers a wide range of insurance products, including cyber insurance policies, to individuals and businesses across the US, Canada, Europe, and Asia.

CNA

See also: Ransomware businesses: Negotiators are in high demand

Over 75,000 people were affected

The data breach reported by CNA affected 75,349 people, according to information filed with the office of the Attorney General of Maine.

After examining the stolen files during the attack, CNA discovered that they contained customers' personal data (names and social security numbers).

The company added that “it was able to quickly recover this information and there was no indication that the data had been stolen.”

Furthermore, CNA claims that there is no reason to suspect that the stolen information was used or will be used in any way.

See also: Kaseya REvil ransomware: Over 1,500 companies affected

Systems fully restored after ransomware attack

Sources familiar with the attack told BleepingComputer that the operators of Phoenix CryptoLocker encrypted over 15,000 devices after deploying the ransomware payloads on CNA's network on March 21.

BleepingComputer also learned that the intruders encrypted the computers of employees who were working remotely and had connected to the company's VPN during the incident.

Based on code similarities, Phoenix Locker is believed to be a new ransomware family developed by the hacking group Evil Corp to avoid sanctions, as WastedLocker ransomware victims will no longer pay ransoms.

When asked about the link between Evil Corp and the Phoenix group, CNA responded that there was no confirmed relationship.

See also: REvil ransomware Kaseya: Hackers demand $70 million to decrypt all systems

Two months ago, CNA said it had restored systems affected by the ransomware attack and was operating “smoothly.” The insurance provider added that it had found no evidence that its users’ data was being offered for sale on the dark web or hacking forums.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS