TIAA and TIAA Life
ent_72178cf195fde0fbe8018e9d
Disclosures
10
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
8,977
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIAA and TIAA Life
- Normalized
- tiaa and tiaa life— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Maine State AGas victim2024-09-27
TIAA and TIAA Life reported a cybersecurity incident involving third-party administrator Infosys McCamish Systems (IMS). Between Oct 29 and Nov 2, 2023, an unauthorized party accessed IMS systems. The breach affected 8,977 individuals, including 81 Maine residents. Personal information including names and government identifiers was acquired. TIAA offered 24 months of identity monitoring via Kroll. The incident was discovered on Nov 2, 2023.
- California State AGas victim2024-09-06
TIAA notified customers of a cybersecurity incident at its administrative support provider, Infosys McCamish Systems (IMS). Between Oct 29 and Nov 2, 2023, an unauthorized party accessed IMS systems. IMS detected the incident on Nov 2, 2023, and contained it by December 2023. Personal information was potentially accessed. TIAA is offering 2 years of complimentary identity monitoring via Kroll.
- Massachusetts State AGas victim2022-05-10
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-05-10. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-11-23
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-11-23. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-08-05
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-08-05. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-04-20
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-04-20. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2021-03-01
TIAA reported a data breach affecting one Maine resident. The breach occurred on May 5, 2020, and was discovered on February 21, 2021. The incident involved the manual input of stolen credentials, leading to the compromise of names and financial account numbers with their access codes. TIAA notified the affected individual on March 1, 2021, and offered two years of credit monitoring and identity theft protection services from Experian.
- Massachusetts State AGas victim2020-04-15
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-04-15. 14 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-04-17
TIAA notified Montana residents that an unauthorized third party viewed their personal identifiable information, including name, account balance, and Social Security number, online. TIAA disabled affected accounts and offered two years of credit monitoring and identity protection services through AllClear ID.
- Massachusetts State AGas victim2018-04-02
TIAA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-02. 2 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- TIAA and TIAA Life’s filing is one of at least 20 in the INFOSYS MCCAMISH SYSTEMS, LLC supply-chain incident (2024).