Advertisement
Australia markets close in 1 hour 46 minutes
  • ALL ORDS

    7,808.80
    -90.10 (-1.14%)
     
  • ASX 200

    7,558.90
    -83.20 (-1.09%)
     
  • AUD/USD

    0.6401
    -0.0024 (-0.38%)
     
  • OIL

    84.73
    +2.00 (+2.42%)
     
  • GOLD

    2,402.90
    +4.90 (+0.20%)
     
  • Bitcoin AUD

    97,302.77
    +713.95 (+0.74%)
     
  • CMC Crypto 200

    1,287.60
    +402.07 (+44.21%)
     
  • AUD/EUR

    0.6013
    -0.0018 (-0.30%)
     
  • AUD/NZD

    1.0876
    +0.0001 (+0.01%)
     
  • NZX 50

    11,755.13
    -80.91 (-0.68%)
     
  • NASDAQ

    17,394.31
    -99.31 (-0.57%)
     
  • FTSE

    7,877.05
    +29.06 (+0.37%)
     
  • Dow Jones

    37,775.38
    +22.07 (+0.06%)
     
  • DAX

    17,837.40
    +67.38 (+0.38%)
     
  • Hang Seng

    16,184.02
    -201.85 (-1.23%)
     
  • NIKKEI 225

    37,151.54
    -928.16 (-2.44%)
     
Engadget
Why you can trust us

Engadget has been testing and reviewing consumer tech since 2004. Our stories may include affiliate links; if you buy something through a link, we may earn a commission. Read more about how we evaluate products.

CNA Financial reportedly paid $40 million to resolve a ransomware attack

It could be one of the biggest ransom payouts to date.

AndreyPopov via Getty Images

A US insurance company may have paid one of the most expensive malware ransoms to date. According to Bloomberg, CNA Financial shelled out $40 million in late March to regain control of its network following a two-week lockout. To put that payout in perspective, the CEO of the Colonial Pipeline told The Wall Street Journal this week his company paid $4.4 million to hackers. That's a ransomware attack that led to fuel shortages across the US.

"CNA is not commenting on the ransom," a spokesperson for the company told Bloomberg. "CNA followed all laws, regulations and published guidance, including OFAC's 2020 ransomware guidance, in its handling of this matter."

The company fell victim to Phoenix Locker, an offshoot of the Hades ransomware created by infamous Russian cybercrime operation Evil Corp. Some security researchers believe Evil Corp is also behind WastedLocker, the malware linked to last year's Garmin ransomware attack. In 2019, the US Treasury Department sanctioned the group for its activities. It's unclear if Phoenix, the group behind the CNA attack, is affiliated with Evil Corp.

Ransomware attacks have become increasingly common and disruptive in recent years. In April and March, the REvil ransomware gang demanded $50 million from Apple supplier Quanta and Acer. Even Cyberpunk 2077 developer CD Projekt Red had to deal with a lockout, which led to a delay in the game's second major patch coming out.