TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLC
ent_019ed84758b76cc4e934c17d2a849ebf
Disclosures
3
State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
46
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIAA-CREF INDIVIDUAL & INSTITUTIONAL SERVICES, LLC
- Normalized
- tiaa cref individual institutional— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900X9A0WEUBJW5675
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- tiaa.org
Disclosure history (3)newest first
- Maryland State AGas reporting2025-11-13
TIAA reported a cybersecurity incident involving one Maryland resident. An unauthorized individual accessed the resident's TIAA account between January 4 and January 6, 2025, using valid credentials obtained from an unknown external source. TIAA reset the credentials, placed additional authentication monitoring, and offered 24 months of complimentary credit monitoring.
- Maryland State AGas victim2025-03-12
On March 5, 2025, an unauthorized individual accessed a Maryland resident's TIAA online account using credentials obtained from an external source. The attacker viewed the resident's name, user ID, account number, and financial account balance. TIAA deactivated the compromised credentials, placed account alerts, and offered two years of credit monitoring. No unauthorized transactions occurred.
- Massachusetts State AGas reporting2013-04-20
TIAA CREF Financial Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-04-20. 46 Massachusetts residents were affected. The report records the breach type as undefined.