CNA FINANCIAL CORPORATION
ent_019e0ce19ccc3280d4aaa0cbdcf69894
Disclosures
7
SEC 10-K Item 1C · State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
75,349
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CNA FINANCIAL CORPORATION
- Normalized
- cna financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300YX2GSZD7YG1R84
- SEC EDGAR CIK
- 0000021175
- Domain
- cna.com
- Corporate parent
- LOEWS CORP— per SEC Exhibit 21 filing
Disclosure history (7)newest first
- FEDERALSEC 10-K Item 1Cas victim2024-02-06
CNA Financial Corporation's 10-K Item 1C cybersecurity disclosure describes its information security program governance, NIST CSF alignment, CISO/CIO oversight structure, and Audit Committee reporting cadence. The filing explicitly states that to date, no risks from cybersecurity threats, including from previous incidents, have materially affected or are reasonably likely to materially affect the Company. No specific breach incident is disclosed in this Item 1C.
- 🦬Montana State AGas victim2021-07-09
CNA Financial Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2021-07-09. The breach occurred from 3/5/2021 to 3/21/2021. 74 Montana residents were affected.
- 🦫Oregon State AGas victim2021-07-09
CNA Financial Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-09. The breach occurred during 3/5/2021 - 3/21/2021. The breach was discovered on 3/21/2021. 75,349 individuals were affected. Notice was sent on 7/9/2021.
- 🐻California State AGas victim2021-07-08
CNA Financial Corporation experienced a ransomware attack on its systems between March 5 and March 21, 2021. The threat actor accessed systems, copied a limited amount of personal information (names and Social Security numbers), and then deployed ransomware. CNA recovered the copied data and found no evidence of misuse. CNA notified law enforcement (FBI) and offered 24 months of credit monitoring to affected individuals.
- ILHHS OCRas victim2021-07-08
CNA Financial Corporation (IL), a Health Plan, reported to HHS OCR on 2021-07-08 a ransomware attack affecting PHI of approximately 5,095 individuals. Breached information was located on a Network Server. PHI exposed included names, addresses, Social Security numbers, birthdates, diagnoses, lab results, and claims/treatment information. The CE notified HHS, affected individuals, media, and law enforcement. OCR provided technical assistance regarding the HIPAA Security Rule. No business associate was involved.
- 🦞Maine State AGas victim2021-07-08
CNA Financial Corporation reported an external system breach (hacking) occurring between March 5, 2021, and March 21, 2021. The incident affected 75,349 individuals, including 96 Maine residents. Acquired information included names and Social Security Numbers. CNA provided 24 months of credit monitoring through Experian and a toll-free hotline.
- 🌲Washington State AGas victim2021-07-08
CNA Financial Corporation, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2021-03-21 and filed notice on 2021-07-08. 823 Washington residents were affected. 109 days elapsed between awareness and notification. 16 days to identify the breach. 0 days to contain the breach.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of CNA FINANCIAL CORPORATION — not by CNA FINANCIAL CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.