TIAA Kaspick, LLC
ent_a5c02cd6e9fed80d4cfa1bf9
Disclosures
6
State AG · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,235
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIAA Kaspick, LLC
- Normalized
- tiaa kaspick— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- 🌲Washington State AGas victim2023-07-28
TIAA Kaspick, LLC ("Kaspick"), a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-09 and filed notice on 2023-07-28. 1,235 Washington residents were affected. 49 days elapsed between awareness and notification. 11 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2023-07-27
TIAA Kaspick, LLC reported a data breach impacting 359 Maine residents after a vendor, Pension Benefit Information, LLC (PBI), was affected by a zero-day exploit in its MOVEit Transfer server. The breach, which occurred between May 29 and May 30, 2023, and was discovered on June 23, 2023, resulted in the acquisition of names and Social Security numbers. TIAA Kaspick is offering two years of complimentary credit monitoring and identity theft restoration services through Kroll.
- 🐻California State AGas victim2023-07-27
TIAA Kaspick, LLC notified the California AG of a data breach involving its third-party vendor, Pension Benefit Information (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer product to access PBI's servers on May 29-30, 2023, and exfiltrated data. Affected individuals' name, Social Security number, and date of birth were involved. PBI patched servers, investigated the incident, and offered 24 months of identity monitoring through Kroll.
- 🥔Idaho State AGas victim2023-07-27
TIAA Kaspick, LLC notified the Idaho Attorney General of a data security incident involving 150 Idaho residents. The breach stemmed from a vulnerability in Progress Software's MOVEit Transfer software exploited by an unauthorized third party via Pension Benefit Information, LLC (PBI), a third-party vendor. The attacker accessed PBI's MOVEit server on May 29-30, 2023, and exfiltrated files containing names, Social Security numbers, and dates of birth. TIAA Kaspick and PBI patched systems, investigated, and provided 24 months of credit monitoring to affected individuals.
- ⛰️New Hampshire State AGas victim2023-07-26
TIAA Kaspick, LLC notified the NH Attorney General of a data security incident involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer server was exploited by an unauthorized third party on May 29-30, 2023, resulting in the exfiltration of files containing personal information of 353 New Hampshire residents. TIAA Kaspick learned of the investigation on June 9, 2023. Notifications were mailed starting July 14, 2023, offering credit monitoring services.
- 🦬Montana State AGas victim2023-07-26
TIAA Kaspick, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-26. The breach occurred from 5/29/2023 to 5/30/2023. 447 Montana residents were affected.