Data breach
CalSTRS
- Records
- 1,141,440
- Breach date
- 13 November 2024Estimated
- Added
- 13 November 2024
What was exposed
7 types of data
- Names1,140,965
- Email addresses562,414
- Phone numbers331,389
- Employment280,617
- Employers280,617
- Home addresses280,193
- Job titles276,957
About this breach
The investigation team has indexed a listing of more than 1.1 million records tied to the California State Teachers' Retirement System, the pension fund better known as CalSTRS. The team estimates the attack date as November 13, 2024, and no hacking group has claimed responsibility for the dataset. The listing surfaces at a time when CalSTRS and its members are already dealing with the fallout from earlier breaches at a contractor, PBI Research Services/Berwyn Group, which the pension system uses to help identify members who have died so payments can be stopped. The California State Treasurer's office maintains a public notice page confirming that personal information of retired members was involved in a security incident at that vendor, and that PBI's services help ensure payments are not made to members who have passed away. That page remains active, and CalSTRS members are directed to contact member services by phone at 800-228-5453 or through an online form with questions. Separately, a notice filed with the California Attorney General describes how an unauthorized party exploited a vulnerability in a secure file transfer application hosted by PBI and acquired files containing CalSTRS members' information, while stressing that CalSTRS's own network was not accessed. As of September 25, 2026, detailed company notices or major news coverage specifically tied to the November 2024 listing were limited in sources reviewed, so the facts below rely primarily on the indexed fields plus the secondary sources cited.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, home addresses, and employment information including employer names and job titles.
According to the indexed fields, names appear on roughly 1.14 million of the 1,141,440 records in the dataset, making it the most common data type by far. Email addresses appear on about 562,000 records, phone numbers on about 331,000, and home addresses on about 280,000. Employer names and job titles each appear on roughly 277,000 to 281,000 records.
Not every individual is affected by every type of data listed here.
The indexed fields do not indicate whether Social Security numbers, dates of birth, or financial details are part of this particular dataset. CalSTRS's earlier notification for the PBI vendor incident described files containing names, Social Security numbers, dates of birth, and ZIP codes, and stated that financial account information was not included, but that notice concerned a separate, previously disclosed event.
What Are the Potential Risks for Affected Individuals?
A combination of names, emails, phone numbers, home addresses, and employment details is well suited to targeted phishing. Scammers can reference a person's employer or pension to make messages look convincing, and phone numbers open the door to smishing texts and voice phishing calls. Where home addresses are included, the data can also support mail fraud or intimidation attempts.
Because this dataset does not appear to include passwords, account takeover through password reuse is less of a direct concern here than in credential leaks. The larger risk is impersonation: an attacker who knows your name, employer, and contact details can pose as a pension administrator, benefits office, or government agency with unusual credibility. Retirees, who are frequent targets of impersonation scams, should treat unexpected calls, texts, or emails about their benefits with suspicion.
What Is CalSTRS Doing in Response?
The Office of the State Treasurer maintains a public page noting that CalSTRS and CalPERS are alerting retired members and their families whose personal information was involved in the incident at PBI Research Services/Berwyn Group, and CalSTRS directs members with questions to its member services line or online inquiry form. In its earlier notification filed with the California Attorney General, CalSTRS offered affected members a complimentary 12-month Experian IdentityWorks membership and a dedicated incident response line.
What Should You Do If You Were Affected?
Be skeptical of unsolicited calls, texts, or emails about your pension or benefits, and contact CalSTRS directly at 800-228-5453 rather than through links or numbers in a message.
Monitor your credit reports and bank statements for activity you did not authorize. Free annual reports are available at annualcreditreport.com.
Consider a fraud alert or a security freeze with the three credit bureaus; both are free.
Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state attorney general.
