HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Teachers' Retirement System of the City of New York
bd_b129a13df14ad5f0 · schema v1 · pii pii-v1
Full breach record for Teachers' Retirement System of the City of New York →Teachers' Retirement System of the City of New York notified Vermont AG that a third-party vendor, PBI Research Services, experienced a data breach via a MOVEit Transfer vulnerability. Attackers accessed data on May 29-30, 2023. Affected data included names, SSNs, DOBs, and addresses for TRS payees receiving benefits as of March 2023. PBI engaged law enforcement and offered 24 months of credit monitoring.
Vermont clock✓ VT AG ≤14 bday≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_794f98c2009ad2ecMaine State AGfiled 2023-07-24(6d gap)Candidate
- bd_96f1aacb96ef4caaNew Hampshire State AGfiled 2023-07-24(6d gap)Verified
- bd_e208ddf047767168Montana State AGfiled 2023-07-24(6d gap)Verified
- bd_fe91f5d522ee5407California State AGfiled 2023-07-24(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-18-teachers-retirement-system-city-new-york-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 18, 2023
- Raw hash
- e0d6e3b49f04bd460c8664e78091999d540466a0b4f3949d89dd59fbfe241188
Reporting entity
- Name
- Teachers' Retirement System of the City of New Yorknorm: teachers retirement system of the city of new york
Victim entity
- Name
- Teachers' Retirement System of the City of New Yorknorm: teachers retirement system of the city of new york
Incident
- Discovered
- Jul 18, 2023
- Materiality determined
- —
- Notification sent
- Jul 18, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- PBI reported the matter to federal law enforcement
- Third party
- via PBI Research Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.