CNA Financial Corporation experienced a ransomware attack on its systems between March 5 and March 21, 2021. The threat actor accessed systems, copied a limited amount of personal information (names and Social Security numbers), and then deployed ransomware. CNA recovered the copied data and found no evidence of misuse. CNA notified law enforcement (FBI) and offered 24 months of credit monitoring to affected individuals.