CNA FINANCIAL CORPORATION
bd_bdd258432c11e629 · schema v1 · pii pii-v1
Full breach record for CNA FINANCIAL CORPORATION →CNA Financial Corporation reported a ransomware attack discovered on March 21, 2021. The threat actor accessed systems starting March 5, 2021, via a fake browser update, stole credentials, and exfiltrated data to a Mega account before deploying ransomware. 205 New Hampshire residents were affected, with data including names, SSNs, and some PHI. CNA recovered the data and reported to the FBI. Notification began July 9, 2021.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 5, 2021
Begins
Mar 21, 2021
Discovered
Jul 12, 2021
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Montana State AGbd_107e3f0f52c95ee92021-07-09 · +3dVerified
- Oregon State AGbd_8f8adf6678098d272021-07-09 · +3dVerified
- Indiana State AGbd_eb7c4eb9cabf7a572021-07-09 · +3dVerified
- California State AGbd_2498cf3d61584cfe2021-07-08 · +4dCandidate
Show 4 more filings ↓Show fewer ↑up to 4d gap
- Massachusetts State AGbd_53180e7c81f57e152021-07-08 · +4dVerified
- HHS OCRbd_641fa664e7fa983f2021-07-08 · +4dVerified
- Maine State AGbd_7abcb947b9a916802021-07-08 · +4dVerified
- Washington State AGbd_7f8a3a5d1d0c1ff62021-07-08 · +4dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.