TIAA notified Maryland AG of a single-incident breach on March 5, 2025. An unauthorized individual used credentials obtained from a third-party source to reset a resident's online TIAA account credentials and viewed their name, user ID, account number, and financial balance. TIAA deactivated credentials, placed alerts, and offered 24 months of credit monitoring.
Affected (this filing): 1