HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Teachers' Retirement System of the City of New York
bd_fe91f5d522ee5407 · schema v1 · pii pii-v1
Full breach record for Teachers' Retirement System of the City of New York →The Teachers' Retirement System of the City of New York (TRS) notified members that their personal information was exposed in a data security incident affecting third-party vendor PBI Research Services. An unauthorized third party exploited a previously unknown vulnerability in the MOVEit Transfer application to download data from PBI's servers on May 29-30, 2023. Affected data included names, Social Security numbers, dates of birth, and addresses. TRS systems were not compromised. TRS is offering 24 months of credit monitoring and identity restoration services.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_794f98c2009ad2ecMaine State AGfiled 2023-07-24Candidate
- bd_96f1aacb96ef4caaNew Hampshire State AGfiled 2023-07-24Verified
- bd_e208ddf047767168Montana State AGfiled 2023-07-24Verified
- bd_b129a13df14ad5f0Vermont State AGfiled 2023-07-18(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570789
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 24, 2023
- Raw hash
- a064e28fa918b697267fa237f20dde6dffd7c5b3866e66e9f8d4cd82003e5862
Reporting entity
- Name
- Teachers' Retirement System of the City of New Yorknorm: teachers retirement system of the city of new york
Victim entity
- Name
- Teachers' Retirement System of the City of New Yorknorm: teachers retirement system of the city of new york
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 18, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via PBI Research Services
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.