Tiaa-cref Life Insurance Company
bd_eb98cd8aab9e94a4 · schema v1 · pii pii-v1
Full breach record for Tiaa-cref Life Insurance Company →5 incidents on fileTIAA-CREF Life Insurance Company notified the Idaho AG of a cybersecurity event at its vendor, Infosys McCamish Systems, discovered on November 3, 2023. The vendor suffered a breach potentially resulting in the exfiltration of customer data, including names, SSNs, DOBs, policy numbers, financial account numbers, and medical information. TIAA terminated connections to the vendor and scanned its own systems, finding no compromise. Approximately 1,300 Idaho residents are estimated to be impacted. The investigation into the scope of data exfiltration is ongoing, with results expected in July 2024. TIAA is offering two years of identity theft protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2023
Discovered
Feb 18, 2024
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Illinois State AGbd_f746b59ac2628dee2024-02-01 · +17dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Feb 1 (IL), last Feb 18 (ID) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.