Teachers Insurance and Annuity Association of America ("TIAA")
ent_7d7887b811e2c1e690f97267
Disclosures
13
State AG · 9 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,373,076
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Teachers Insurance and Annuity Association of America ("TIAA")
- Normalized
- teachers insurance and annuity association of america tiaa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- 🏎️Indiana State AGas victim2025-01-16
Teachers Insurance and Annuity Association of America reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-16 and was reported on 2025-01-16. 1 Indiana residents were affected.
- 🏎️Indiana State AGas victim2024-03-07
Teachers Insurance and Annuity Associate of America reported a data breach to the Indiana Attorney General. The breach occurred on 2023-10-29 and was reported on 2024-03-07. 7,119 Indiana residents were affected. 16,713 individuals affected in total.
- 🏎️Indiana State AGas victim2023-11-28
Teachers Insurance and Annuity Association of America reported a data breach to the Indiana Attorney General. The breach occurred on 2023-11-16 and was reported on 2023-11-28. 1 Indiana residents were affected.
- ⛰️New Hampshire State AGas victim2023-08-17
Pension Benefit Information, LLC (PBI), a third-party vendor for TIAA, disclosed a MOVEit Transfer vulnerability exploitation. An unauthorized third party accessed PBI servers on May 29-30, 2023, downloading data. PBI patched servers, investigated, and is offering 24 months of Kroll identity monitoring. No identity theft confirmed.
- 🌲Washington State AGas victim2023-07-27
Teachers Insurance and Annuity Association of America ("TIAA, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-09 and filed notice on 2023-07-27. 56,331 Washington residents were affected. 48 days elapsed between awareness and notification. 11 days to identify the breach. 0 days to contain the breach.
- 🌺Hawaii State AGas victim2023-07-27
Pension Benefit Information, LLC (PBI) notified TIAA customers of a data breach involving the MOVEit Transfer software vulnerability exploited in May 2023. PBI confirmed unauthorized access to a server on May 29-30, 2023, resulting in the exfiltration of names, SSNs, DOBs, addresses, and gender. PBI patched systems, offered 24 months of Kroll identity monitoring, and enhanced security policies.
- 🦞Maine State AGas victim2023-07-24
Teachers Insurance and Annuity Association of America (TIAA) reported a data breach affecting 2,373,076 individuals, originating from a vulnerability in the MOVEit transfer software, a third-party vendor. The breach occurred on May 29, 2023, and was discovered on June 28, 2023. The compromised information includes names and Social Security numbers. TIAA offered affected individuals 24 months of identity theft protection services through Kroll.
- 🐻California State AGas victim2023-07-24
Teachers Insurance and Annuity Association of America (TIAA) notified the California AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing PBI's servers on May 29-30, 2023, and downloading data. Affected information includes names, Social Security numbers, dates of birth, addresses, and gender. TIAA/PBI patched servers, investigated the incident, and offered 24 months of identity monitoring via Kroll.
- 🥔Idaho State AGas reporting2023-07-21
Pension Benefit Information, LLC (PBI), a third-party vendor for Teachers Insurance and Annuity Association of America (TIAA), experienced a data security incident involving the MOVEit Transfer software vulnerability. An unauthorized third party accessed PBI's MOVEit Transfer servers on May 29-30, 2023, and exfiltrated files containing names, Social Security numbers, dates of birth, addresses, and gender of 8,051 Idaho residents. TIAA notified the Idaho Attorney General on July 21, 2023. PBI patched the software, investigated the scope, and offered 24 months of credit monitoring via Kroll to affected individuals.
- 🐻California State AGas victim2023-07-21
Teachers Insurance and Annuity Association of America (TIAA) notified the California AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing PBI servers on May 29-30, 2023, and downloading data. Affected information includes names, Social Security numbers, dates of birth, addresses, and gender. TIAA/PBI patched servers, investigated the incident, and offered 24 months of identity monitoring.
- 🦬Montana State AGas victim2023-07-21
Teachers Insurance and Annuity Association of America reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-21. The breach occurred on 5/31/2023. 5,977 Montana residents were affected.
- 💎Delaware State AGas victim2023-07-14
Pension Benefit Information, LLC (PBI), a third-party vendor for Teachers Insurance and Annuity Association of America (TIAA), disclosed a MOVEit Transfer vulnerability exploited by an unauthorized third party. The incident occurred May 29-30, 2023, involving the exfiltration of names, SSNs, DOBs, addresses, and gender. PBI patched servers, investigated, and offered 24 months of Kroll identity monitoring. No identity theft or fraud has been indicated.
- 💎Delaware State AGas victim2023-07-14
Pension Benefit Information, LLC (PBI) notified Delaware AG that a third-party software vulnerability in Progress Software's MOVEit Transfer was exploited between May 29-30, 2023. PBI, a vendor for Teachers Insurance and Annuity Association of America (TIAA), allowed an unauthorized third party to access a server and download data. Affected data included names, SSNs, dates of birth, addresses, and gender. PBI patched servers, investigated, and offered 24 months of identity monitoring via Kroll. No identity theft or fraud has been indicated.