HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
TIAA Kaspick, LLC
bd_b82d3fc6babe68a1 · schema v1 · pii pii-v1
Full breach record for TIAA Kaspick, LLC →TIAA Kaspick, LLC notified the California AG of a data breach involving its third-party vendor, Pension Benefit Information (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer product to access PBI's servers on May 29-30, 2023, and exfiltrated data. Affected individuals' name, Social Security number, and date of birth were involved. PBI patched servers, investigated the incident, and offered 24 months of identity monitoring through Kroll.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_05f642e9efff15ccMaine State AGfiled 2023-07-27Verified
- bd_fa66956c081fbea7Idaho State AGfiled 2023-07-27Verified
- bd_8ae2f91c9a2c0c12New Hampshire State AGfiled 2023-07-26(1d gap)Verified
- bd_f2b549864eb15db8Montana State AGfiled 2023-07-26(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570931
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 3afa02b9dcca8cd6399f31fd411025d94e5056604df03282ce969e385dfbd1f2
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- TIAA Kaspick, LLCnorm: tiaa kaspick
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.