Tiaa-cref Life Insurance Company
ent_019e5a1e3b34446434662651e6f46162
Disclosures
5
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,300
as filed · State AG ID
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Tiaa-cref Life Insurance Company
- Normalized
- tiaa cref life insurance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300KP6RN2MMOB2L13
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🥔Idaho State AGas victim2024-02-18
TIAA-CREF Life Insurance Company notified the Idaho Attorney General of a cybersecurity event involving third-party administrator Infosys McCamish Systems. The incident, discovered on November 3, 2023, resulted in the potential exfiltration of customer data, including names, SSNs, DOBs, financial account numbers, and medical information. Approximately 1,300 Idaho residents are receiving voluntary notices and two years of free identity theft protection.
- 🦬Montana State AGas victim2023-08-02
TIAA-Cref Life Insurance Company reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-02. The breach occurred from 5/29/2023 to 5/30/2023. 94 Montana residents were affected.
- 🌲Washington State AGas victim2023-08-02
TIAA-CREF Life Insurance Company, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-09 and filed notice on 2023-08-02. 904 Washington residents were affected. 54 days elapsed between awareness and notification. 11 days to identify the breach. 0 days to contain the breach.
- 🥔Idaho State AGas victim2023-08-01
TIAA-CREF Life Insurance Company notified the Idaho Attorney General of a data security incident involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer server was exploited between May 29-30, 2023, leading to the exfiltration of files containing names, SSNs, dates of birth, addresses, and gender of 162 Idaho residents. TIAA and PBI investigated, identified affected individuals, and provided 2 years of free credit monitoring and identity theft restoration services.
- 🐻California State AGas victim2023-08-01
TIAA-CREF Life Insurance Company notified the California AG of a data breach involving its third-party service provider, Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer product to access PBI's servers on May 29-30, 2023, and exfiltrated data. The compromised information included names, Social Security numbers, dates of birth, addresses, and gender. PBI patched servers, investigated the incident, and is offering 24 months of identity monitoring to affected individuals.