TIAA Kaspick, LLC
bd_fa66956c081fbea7 · schema v1 · pii pii-v1
Full breach record for TIAA Kaspick, LLC →3 incidents on fileTIAA Kaspick, LLC notified the Idaho Attorney General of a data security incident involving 150 Idaho residents. The breach stemmed from a vulnerability in Progress Software's MOVEit Transfer software exploited by an unauthorized third party via Pension Benefit Information, LLC (PBI), a third-party vendor. The attacker accessed PBI's MOVEit server on May 29-30, 2023, and exfiltrated files containing names, Social Security numbers, and dates of birth. TIAA Kaspick and PBI patched systems, investigated, and provided 24 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Jun 9, 2023
Discovered
Jul 27, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Maine State AGbd_05f642e9efff15cc2023-07-27Verified
- California State AGbd_b82d3fc6babe68a12023-07-27Verified
- New Hampshire State AGbd_8ae2f91c9a2c0c122023-07-26 · +1dVerified
- Montana State AGbd_f2b549864eb15db82023-07-26 · +1dCandidate
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.