MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CNA FINANCIAL CORPORATION
bd_2498cf3d61584cfe · schema v1 · pii pii-v1
Full breach record for CNA FINANCIAL CORPORATION →CNA Financial Corporation experienced a ransomware attack on its systems between March 5 and March 21, 2021. The threat actor accessed systems, copied a limited amount of personal information (names and Social Security numbers), and then deployed ransomware. CNA recovered the copied data and found no evidence of misuse. CNA notified law enforcement (FBI) and offered 24 months of credit monitoring to affected individuals.
California clockDiscovered Mar 21, 2021 → Notified Jul 9, 2021110d ✗ CA 60-day late16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_641fa664e7fa983fHHS OCRfiled 2021-07-08Verified
- bd_7abcb947b9a91680Maine State AGfiled 2021-07-08Verified
- bd_7f8a3a5d1d0c1ff6Washington State AGfiled 2021-07-08Verified
- bd_107e3f0f52c95ee9Montana State AGfiled 2021-07-09(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_8f8adf6678098d27Oregon State AGfiled 2021-07-09(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542696
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2021
- Raw hash
- baf5f008ed591c001fe2bafe87962ab80d9be0dc99023edb24bea38e38328a17
Reporting entity
- Name
- CNA FINANCIAL CORPORATIONnorm: cna financial
- Domain
- cna.com
Victim entity
- Name
- CNA FINANCIAL CORPORATIONnorm: cna financial
- Domain
- cna.com
Incident
- Discovered
- Mar 21, 2021
- Materiality determined
- —
- Notification sent
- Jul 9, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to, and is working closely with, the appropriate law enforcement authorities, including the FBI
Compliance
- Time to disclose
- 16 weeks(109 days from discovery to filing)
- Compliance flags
- CA 60-day late · 110d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 21, 2021→ Notified: Jul 9, 2021110d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.