DisclosureLens
HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountHealth (basic)HighActive

Tiaa-cref Life Insurance Company

bd_eb98cd8aab9e94a4 · schema v1 · pii pii-v1

Severity

High

Discovered

Nov 3, 2023

Filed

Feb 18, 2024

To disclose

15 weeks

Affected

1,300state residents only

Linked

2 filings

Confidence

67%
Full breach record for Tiaa-cref Life Insurance Company5 incidents on file

TIAA-CREF Life Insurance Company notified the Idaho AG of a cybersecurity event at its vendor, Infosys McCamish Systems, discovered on November 3, 2023. The vendor suffered a breach potentially resulting in the exfiltration of customer data, including names, SSNs, DOBs, policy numbers, financial account numbers, and medical information. TIAA terminated connections to the vendor and scanned its own systems, finding no compromise. Approximately 1,300 Idaho residents are estimated to be impacted. The investigation into the scope of data exfiltration is ongoing, with results expected in July 2024. TIAA is offering two years of identity theft protection.

Incident timeline

discovery → filing · 15 weeks / 107 days

Nov 3, 2023

Discovered

Feb 18, 2024

Filed

vs. sector median

+7 wks slower

This filing is one of 2 about the same incident.View merged incident
Part of INFOSYS MCCAMISH SYSTEMS, LLC supply-chain incident (2024) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Illinois State AGFeb 1 · first
Idaho State AG+17d · this page

Pattern: first filing Feb 1 (IL), last Feb 18 (ID) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.