CNA FINANCIAL CORPORATION
bd_7f8a3a5d1d0c1ff6 · schema v1 · pii pii-v1
Full breach record for CNA FINANCIAL CORPORATION →CNA Financial Corporation reported a ransomware attack affecting 823 Washington residents. The threat actor gained access via a fake browser update (phishing link) on March 5, 2021, moved laterally using stolen credentials, and deployed ransomware on March 21, 2021. Data (names, SSNs, some PHI) was exfiltrated to a Mega account but recovered; no evidence of misuse was found. Notifications began July 9, 2021.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 5, 2021
Begins
Mar 21, 2021
Discovered
Jul 8, 2021
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- California State AGbd_2498cf3d61584cfe2021-07-08Candidate
- Massachusetts State AGbd_53180e7c81f57e152021-07-08Verified
- HHS OCRbd_641fa664e7fa983f2021-07-08Verified
- Maine State AGbd_7abcb947b9a916802021-07-08Verified
Show 4 more filings ↓Show fewer ↑up to 4d gap
- Montana State AGbd_107e3f0f52c95ee92021-07-09 · +1dVerified
- Oregon State AGbd_8f8adf6678098d272021-07-09 · +1dVerified
- Indiana State AGbd_eb7c4eb9cabf7a572021-07-09 · +1dVerified
- New Hampshire State AGbd_bdd258432c11e6292021-07-12 · +4dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.