MCNA Settled Class Action Over 2023 Data Breach
The settlement offers reimbursement and monitoring to millions affected by the 2023 LockBit ransomware attack.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Do you trust that major companies are doing enough to protect your private personal information?
MCNA Insurance Company has settled a class action lawsuit stemming from a 2023 security breach that exposed the personal information of nearly 9 million people. The agreement provides financial relief and identity protection for those impacted by the unauthorized access.
Why it matters
The settlement addresses claims that the insurer failed to implement adequate security protocols, resulting in a widespread data exposure by a known ransomware group. It highlights the growing legal and financial liabilities companies face following large-scale exfiltration events.
The incident involved unauthorized access to company systems over a nine-day window, ultimately resulting in the publication of stolen data after a $10 million ransom demand was refused. Affected individuals are now eligible for up to $2,500 in reimbursements and two years of medical data monitoring.
The players
MCNA Insurance Company
An insurance provider whose systems were compromised in a 2023 ransomware attack affecting millions of records.
LockBit
A notorious ransomware group known for exfiltrating sensitive data and publishing it when ransom demands are not met.
The details
The breach occurred when an unauthorized party infiltrated MCNA computer systems, retaining access for over a week to copy sensitive information. The ransomware group LockBit—a syndicate that encrypts victim data and threatens publication—claimed responsibility for the intrusion. After the company refused to pay the $10 million ransom, the attackers published the stolen personal records online, leading to the underlying litigation.
Timeline
Feb 26, 2023 - March 7, 2023: Unauthorized access to MCNA computer systems.
March 2023: MCNA discovered the data breach.
Oct 19, 2026: Deadline for filing claims or opting out.
Nov 16, 2026: Final settlement approval hearing.
The Tech Race
This settlement follows the pattern established by the 2023 LockBit ransomware attacks, where exfiltrated data is published as a tactic following a company's refusal to pay. It marks a continued effort by the legal system to enforce security accountability through large-scale class action agreements.
Individuals affected by the breach have until October 19, 2026, to file claims for out-of-pocket loss reimbursement. Eligible members should review the settlement terms to ensure they access the two years of medical data monitoring included in the agreement.
The takeaway
This case underscores the long-term financial consequences companies face when failing to secure sensitive databases against known extortion syndicates. Interested parties should mark October 19, 2026, as the final deadline to submit documentation for reimbursement claims.
What happens next
The court will conduct a final approval hearing for the settlement on November 16, 2026.
Further reading
For broader trends in incident response and institutional liability, see our Cybersecurity section.
Live Poll
Do you trust that major companies are doing enough to protect your private personal information?









