Ukraine and its neighbours, explained

Advertisement

Home › Opinion › What the CNA ransom revealed on 21 May 2021

Opinion

What the CNA ransom revealed on 21 May 2021

Summary

A look back at a disclosure that tied a US insurer's payment to a Russian cybercrime syndicate, and at a sanctions decision made two days earlier.

What did a US insurer's $40 million payment say about the limits of sanctions? On 21 May 2021, CNA Financial, the seventh-largest commercial insurer in the United States, revealed that it had been the target of a ransomware attack in March 2021.

The company said it paid $40 million to a group named Phoenix two weeks after a trove of company data was stolen and its officials were locked out of their network. The attackers used malware called Phoenix Locker, a variant of ransomware dubbed Hades. Cybersecurity experts said Hades was created by a Russian cybercrime syndicate known as Evil Corp.

That link mattered because of the legal backdrop. In December 2019, the Treasury Department announced sanctions on 17 individuals and six entities linked to Evil Corp. The designation made it illegal for a U.S. company to knowingly pay a ransom to Evil Corp.

A second sanctions story

Two days earlier, on 19 May 2021, the Biden administration lifted sanctions on the Nord Stream 2 pipeline project between Russia and Germany. Despite Joe Biden's personal opposition to the project, the State Department said it had concluded that waiving the sanctions served the national interest of the United States.

Taken together, the two items show sanctions being applied, waived and tested within the same week.

Related analysis