HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
Teachers Insurance and Annuity Association of America ("TIAA")
bd_53687e79813fbfd2 · schema v1 · pii pii-v1
Full breach record for Teachers Insurance and Annuity Association of America ("TIAA") →Pension Benefit Information, LLC (PBI), a third-party vendor for TIAA, disclosed a MOVEit Transfer vulnerability exploitation. An unauthorized third party accessed PBI servers on May 29-30, 2023, downloading data. PBI patched servers, investigated, and is offering 24 months of Kroll identity monitoring. No identity theft confirmed.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_2ebc416a4ea0530dWashington State AGfiled 2023-07-27(21d gap)Verified
- bd_69cfd607fb6c4807Hawaii State AGfiled 2023-07-27(21d gap)Verified
- bd_a760fbad056957c0Maine State AGfiled 2023-07-24(24d gap)Verified
- bd_dc7396da17f400f6California State AGfiled 2023-07-24(24d gap)Candidate
Show 4 more filings ↓Show fewer ↑up to 34d gap
- bd_7b3aede4e2719215California State AGfiled 2023-07-21(27d gap)Candidate
- bd_c76c639d9bdb3a6dMontana State AGfiled 2023-07-21(27d gap)Verified
- bd_73c09f3ceeff8d69Delaware State AGfiled 2023-07-14(34d gap)Verified
- bd_94fc53d6e49a86b6Delaware State AGfiled 2023-07-14(34d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/teachers-insurance-annuity-association-america-20230817.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2023
- Raw hash
- 619cbc875ca60e53f56539ff3daae01ee1a63dce0d68b10aca62768d5e9968b2
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Teachers Insurance and Annuity Association of America ("TIAA")norm: teachers insurance and annuity association of america tiaa
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Pension Benefit Information, LLC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.