HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Tiaa-cref Life Insurance Company
bd_5876c4c2a15a0cb7 · schema v1 · pii pii-v1
Full breach record for Tiaa-cref Life Insurance Company →TIAA-CREF Life Insurance Company notified the California AG of a data breach involving its third-party service provider, Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer product to access PBI's servers on May 29-30, 2023, and exfiltrated data. The compromised information included names, Social Security numbers, dates of birth, addresses, and gender. PBI patched servers, investigated the incident, and is offering 24 months of identity monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_159519eb728b514eIdaho State AGfiled 2023-08-01Candidate
- bd_c409725c75cde49bMontana State AGfiled 2023-08-02(1d gap)Verified
- bd_e470d727916117afWashington State AGfiled 2023-08-02(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571157
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2023
- Raw hash
- e3767ec74aa9b545399f04a158d0a9e3bc72fbd0ffbcbf7697a86ffee0793800
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Tiaa-cref Life Insurance Companynorm: tiaa cref life insurance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Pension Benefit Information, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.