DisclosureLens
MalwareFinancial ServicesFinanceRansomwareData ExfiltratedData EncryptedRansom DemandedIdentity (basic)Government IDMediumContained

CNA FINANCIAL CORPORATION

bd_107e3f0f52c95ee9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 21, 2021

Filed

Jul 9, 2021

To disclose

16 weeks

Affected

74state residents only

Linked

9 filings

Confidence

63%
Full breach record for CNA FINANCIAL CORPORATION

CNA Financial Corporation notified Montana residents of a ransomware attack discovered on March 21, 2021. The threat actor accessed systems between March 5-21, 2021, copying limited personal information (name, SSN) before deploying ransomware. CNA recovered the data, found no evidence of misuse, and reported the incident to the FBI. Affected individuals were offered 24 months of Experian IdentityWorks.

Incident timeline

undetected · 16 days
discovery → filing · 16 weeks / 110 days

Mar 5, 2021

Begins

Mar 21, 2021

Discovered

Jul 9, 2021

Filed

vs. sector median

+7 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 3d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗
California State AGJul 8 · first
HHS OCRJul 8 · first
Maine State AGJul 8 · first
Washington State AGJul 8 · first
Montana State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.