CNA Financial suffers extensive network disruption following cyber attack
The Chicago-based insurer took down its website and systems to mitigate potential damage from the attack


Chicago-based CNA Financial, one of the country’s largest insurance providers, has been hit by a cyber attack that’s left its website out of action and many network systems disrupted.
The insurance firm is the sixth-largest in the US and offers an extensive range of products, including policies against cyber attacks.
On March 21, the firm revealed it sustained a sophisticated cyber security attack.
“The attack caused a network disruption and impacted certain CNA systems, including corporate email,” the company statement read.
“Upon learning of the incident, we immediately engaged a team of third-party forensic experts to investigate and determine the full scope of this incident, which is ongoing. We have alerted law enforcement and will be cooperating with them as they conduct their own investigation.”
It added that it disconnected systems from its network, “out of an abundance of caution,” notified employees, and provided workarounds where possible to ensure they can continue operating.
“The security of our data and that of our insureds ’and other stakeholders is of the utmost importance to us. Should we determine that this incident impacted our insureds’ or policyholders’ data, we’ll notify those parties directly,” said the company.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
CNA has also set up several email addresses to keep in contact with policyholders.
According to The Insurer, a publication serving the insurance industry, CNA’s network may be out of commission for a while, with the attack mainly impacting the underwriting and claims side of its business.
According to a tweet by Joshua Motta, CEO of security firm Coalition, there are rumors that the incident could be a ransomware attack. He added this could be a “nightmare scenario if cyber insurance policyholder data [is] compromised.”
Such data could give hackers information on how much money insurers could payout if a policyholder is attacked in the future. That would mean a hacker has more leverage over a victim, as they know how much money the insurer would pay out as a ransom. Such data could allow hackers to prioritize victims with larger or more comprehensive insurance policies.
CNA hasn’t yet revealed any further details of the attack or any lost or stolen data.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
Reports: White House mulling DeepSeek ban amid investigation
News Nvidia is caught up in US-China AI battle, but Huang still visits DeepSeek in Beijing
By Nicole Kobie
-
Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won't be the last
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott
-
Healthcare systems are rife with exploits — and ransomware gangs have noticed
News Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
By Nicole Kobie
-
Alleged LockBit developer extradited to the US
News A Russian-Israeli man has been extradited to the US amid accusations of being a key LockBit ransomware developer.
By Emma Woollacott
-
February was the worst month on record for ransomware attacks – and one threat group had a field day
News February 2025 was the worst month on record for the number of ransomware attacks, according to new research from Bitdefender.
By Emma Woollacott
-
CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted
News The Medusa ransomware as a Service operation compromised twice as many organizations at the start of 2025 compared to 2024
By Solomon Klappholz
-
More than 300,000 US healthcare patients impacted in suspected Rhysida cyber attacks
News Two US healthcare organizations have warned threat actors were able to breach their internal systems, exposing more than 300,000 individuals.
By Solomon Klappholz
-
‘It’s your worst nightmare’: A batch of €5 hard drives found at a flea market held 15GB of Dutch medical records – and experts warn it could’ve caused a disastrous data breach
News Robert Polet made a startling discovery after finding hard drives on sale for €5 each in a flea market.
By Solomon Klappholz