HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLC
bd_64b8aab8b357fd3f · schema v1 · pii pii-v1
Full breach record for TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLC →TIAA reported a cybersecurity incident involving one Maryland resident. An unauthorized individual accessed the resident's TIAA account between January 4 and January 6, 2025, using valid credentials obtained from an unknown external source. TIAA reset the credentials, placed additional authentication monitoring, and offered 24 months of complimentary credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376221.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 5cb07ef4354889204d81a91637df8aa69618f591bd25efb20f11f40dbeb0dfed
Reporting entity
- Name
- TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLCnorm: tiaa cref individual institutional
- Domain
- tiaa.org
Victim entity
- Name
- TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLCnorm: tiaa cref individual institutional
- Domain
- tiaa.org
Incident
- Discovered
- Jan 6, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 44 weeks(311 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.