What the CNA ransomware payment and Nord Stream 2 waiver revealed
A look back at two US stories from the days around 22 May 2021, one about a ransom paid to hackers and one about a pipeline waiver.

What was Washington dealing with on 22 May 2021? Two stories from the preceding days set the tone: a disclosed ransomware payment and a decision on sanctions.
On 21 May 2021, CNA Financial, the seventh-largest commercial insurer in the United States, revealed that it had been hit by a ransomware attack in March 2021. The company said it paid $40 million to a group named Phoenix two weeks after a trove of company data was stolen and its officials were locked out of their network.
The attackers used malware called Phoenix Locker, a variant of ransomware dubbed Hades. According to cybersecurity experts, Hades was created by a Russian cybercrime syndicate known as Evil Corp. In December 2019, the Treasury Department had announced sanctions on 17 individuals and six entities linked to Evil Corp. That designation made it illegal for a US company to knowingly pay a ransom to Evil Corp.
Two days earlier, on 19 May 2021, the Biden administration lifted sanctions on the Nord Stream 2 pipeline project between Russia and Germany. Joe Biden personally opposed the project, but the State Department said it had concluded that waiving the sanctions served the US national interest.