MCNA Settled Class Action Over 2023 Data Breach

The settlement offers reimbursement and monitoring to millions affected by the 2023 LockBit ransomware attack.

Updated on Oct. 5, 2026 in Cybersecurity

Isometric editorial illustration of a heavy industrial steel lock latching onto a fiber-optic cable conduit, representing digital infrastructure security.
MCNA Insurance Company has agreed to a class action settlement following a 2023 ransomware attack that exposed nearly nine million records. AI Illustration. Upload story photo >

Live Poll

Do you trust that major companies are doing enough to protect your private personal information?

MCNA Insurance Company has settled a class action lawsuit stemming from a 2023 security breach that exposed the personal information of nearly 9 million people. The agreement provides financial relief and identity protection for those impacted by the unauthorized access.

Why it matters

The settlement addresses claims that the insurer failed to implement adequate security protocols, resulting in a widespread data exposure by a known ransomware group. It highlights the growing legal and financial liabilities companies face following large-scale exfiltration events.

The incident involved unauthorized access to company systems over a nine-day window, ultimately resulting in the publication of stolen data after a $10 million ransom demand was refused. Affected individuals are now eligible for up to $2,500 in reimbursements and two years of medical data monitoring.

The players

MCNA Insurance Company

An insurance provider whose systems were compromised in a 2023 ransomware attack affecting millions of records.

LockBit

A notorious ransomware group known for exfiltrating sensitive data and publishing it when ransom demands are not met.

The details

The breach occurred when an unauthorized party infiltrated MCNA computer systems, retaining access for over a week to copy sensitive information. The ransomware group LockBit—a syndicate that encrypts victim data and threatens publication—claimed responsibility for the intrusion. After the company refused to pay the $10 million ransom, the attackers published the stolen personal records online, leading to the underlying litigation.

Timeline

  1. Feb 26, 2023 - March 7, 2023: Unauthorized access to MCNA computer systems.

  2. March 2023: MCNA discovered the data breach.

  3. Oct 19, 2026: Deadline for filing claims or opting out.

  4. Nov 16, 2026: Final settlement approval hearing.

The Tech Race

This settlement follows the pattern established by the 2023 LockBit ransomware attacks, where exfiltrated data is published as a tactic following a company's refusal to pay. It marks a continued effort by the legal system to enforce security accountability through large-scale class action agreements.

Individuals affected by the breach have until October 19, 2026, to file claims for out-of-pocket loss reimbursement. Eligible members should review the settlement terms to ensure they access the two years of medical data monitoring included in the agreement.

The takeaway

This case underscores the long-term financial consequences companies face when failing to secure sensitive databases against known extortion syndicates. Interested parties should mark October 19, 2026, as the final deadline to submit documentation for reimbursement claims.

What happens next

The court will conduct a final approval hearing for the settlement on November 16, 2026.

Further reading

For broader trends in incident response and institutional liability, see our Cybersecurity section.

Live Poll

Do you trust that major companies are doing enough to protect your private personal information?