• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Insurance Giant Reportedly Paid $40 Million Ransom

You are here: Home / General Cyber Security News / Insurance Giant Reportedly Paid $40 Million Ransom
May 24, 2021

A single of America’s biggest insurers agreed to pay out a $40 million ransom just after its IT systems were locked down and data stolen by menace actors, in accordance to a report.

CNA Monetary compensated its attackers in late March, about a fortnight soon after the incident, two people common with the attack instructed Bloomberg.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


A assertion shared with the news internet site refused to comment on the ransom but claimed that the company had adopted all “laws, rules and posted guidance” when dealing with the make a difference. This consists of the 2020 steerage released by the US Treasury’s Business office of Foreign Assets Control (OFAC), it mentioned.

CNA Monetary also noted in a security update that it did “not consider that the systems of file, statements methods, or underwriting devices, in which the bulk of policyholder data — which includes policy conditions and coverage restrictions — is saved, had been impacted.”

The company was evidently hit by a variant of the Evil Corp-authored Hades ransomware known as Phoenix Locker.

The payment could be the biggest at any time designed to a ransomware team — whilst not all incidents and payment amounts are disclosed provided the professional sensitivities included.

Attackers tried to extort $50 million from Acer back again in March, whilst it’s unclear irrespective of whether they ended up thriving or not.

The FBI urges victims not to do so as it encourages additional copycat attacks and does not warranty that the organization’s stolen information will not be monetized in the long run, or that it will even receive a operating decryption essential.

Insurance policy providers like CNA Monetary have been at the middle of intense discussion just lately in excess of irrespective of whether the marketplace should really be helping shoppers monetarily who have been struck by ransomware.

Axa has determined to stop reimbursing new policyholders in France for payments to these kinds of threat teams, for case in point.

Insurers may also be a rewarding target if their attackers handle to come across shopper lists, which would give them with a helpful line-up of companies lined by coverage.

The ordinary payment to ransomware groups improved by 43% from Q4 2020 to the initially three months of 2021, in accordance to Coveware.


Some pieces of this write-up are sourced from:
www.infosecurity-journal.com

Previous Post: «details disclosed on critical flaws affecting nagios it monitoring software Details Disclosed On Critical Flaws Affecting Nagios IT Monitoring Software
Next Post: Air India cyber attack exposes 4.5 million customers’ data air india cyber attack exposes 4.5 million customers’ data»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.