/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources: CNA Financial, one of the largest insurance companies in the US, paid $40M in late March to regain control of its network after a ransomware attack

CNA Financial Corp., among the largest insurance companies in the U.S., paid $40 million in late March to regain control of its network …

Bloomberg

Context & Ripple Effects

CNA's reported payment followed an earlier ransomware disruption at Cognizant that carried a projected $50M–$70M quarterly cost, showing that network recovery and business interruption were already material exposures for large service organizations. Subsequent FinCEN data placed payments like CNA's within a sharp rise in likely ransomware payments by U.S. financial firms, while the later Change Healthcare case showed how attacks can combine recovery costs with continued extortion pressure.

First-order effects

  • CNA Financial reportedly exchanged $40M to regain control of its network, making the payment an immediate cost of restoring its own systems.
  • The reported outcome gives the attackers a realized payoff from targeting a large U.S. insurer.

Second-order effects

  • CNA's payment contributes to the payment pattern later captured by FinCEN, strengthening the economic incentive for ransomware groups to pursue financial-sector victims.
  • Other large organizations face a starker recovery calculation: Cognizant's reported disruption costs and CNA's reported payment show that both paying and restoring systems can be expensive.

Third-order effects

  • If these cases persist, ransomware shifts from an isolated IT-security expense to a resilience and continuity risk whose costs extend beyond the initial encryption event, as Change Healthcare's reported recovery costs and follow-on extortion illustrate.
  • The repeated presence of large payments and recovery losses points toward a ransomware market in which attackers seek organizations whose operational urgency makes rapid restoration especially valuable.

The trend: Ransomware is becoming a business-continuity threat in which the cost of disrupted systems and the leverage of follow-on extortion raise the stakes for large organizations.

Discussion

  • @c_c_krebs Chris Krebs on x
    I don't know about you, but I'm starting to think this ransomware thing has gotten out of control. /sarcasm. https://www.bloomberg.com/... via @business
  • @dariusjbutler Darius Butler on x
    These hackers are on one! 👀 https://twitter.com/...
  • @tliston Tom Liston on x
    Do you want more ransomware attacks? 'Cause this is how you get more ransomware attacks... https://twitter.com/...
  • @williamturton William Turton on x
    The $40 million payment is bigger than any previously disclosed payments to hackers, according to three people familiar with ransomware negotiations. More details to come. https://www.bloomberg.com/...
  • @rstephens Robert Stephens on x
    The local bank for our community nonprofit made me sign 6 PDF forms to get online access for our little community nonprofit (to do mobile deposit) and after all the hassle, the “default” password they gave me for login was “Bank@1234”. No one knows anything. https://twitter.com/.…
  • @kartikaym Kartikay Mehrotra on x
    CNA Financial, among the largest insurance companies in the U.S., paid $40M in late March to regain control of its network after a ransomware attack. This is one of the biggest — if not the biggest — ransom paid to criminal hackers. w/ @WilliamTurton https://www.bloomberg.com/...
  • @jesskellynt Jess Kelly on x
    This is why ransom attacks continue to happen... the target sometimes pay. https://twitter.com/...