Data breach
TIAA.org
- Records
- 2,464,625
- Breach date
- 31 May 2023Estimated
- Added
- 13 November 2024
What was exposed
3 types of data · 2 more reported · 1 puts you at serious risk
- Social security numbers2,464,621
- Home addresses2,464,578
- Names2,438,519
- Dates of birthReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A large dataset tied to the Teachers Insurance and Annuity Association of America, commonly known as TIAA, has surfaced online containing sensitive personal information on roughly 2.46 million people. According to our investigation team, the dataset contains about 2,464,621 Social Security numbers, 2,438,519 names, and 2,464,578 home addresses. The records relate to a third-party breach first reported in 2023, when attackers exploited a flaw in file transfer software used by one of TIAA's vendors. No hacking group has publicly claimed responsibility for the release.
May 29–30, 2023: According to a notice TIAA filed with state attorneys general, a third party accessed a MOVEit Transfer server operated by Pension Benefit Information, LLC (PBI), a TIAA vendor, and downloaded specific TIAA files.
May 31, 2023: Progress Software, the maker of MOVEit, publicly announced the software vulnerability and began releasing patches.
June 19, 2023: PBI confirmed to TIAA that there were indications certain named TIAA files had been exfiltrated, per TIAA's notice.
June 28, 2023: TIAA's analysis to determine which participants were affected concluded, per its notice.
July 14, 2023: Kroll, working for PBI, began mailing notification letters to affected individuals. TIAA reported the incident to the Maine Attorney General on July 24, 2023.
Around November 12, 2024: Sensitive TIAA data began circulating online, according to ConsumerAffairs, citing Atlas Privacy.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, names, and home addresses.
TIAA's own notification letters, filed with state regulators, listed additional details present on the compromised server: dates of birth and gender.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers paired with full names, birth dates, and home addresses are the core ingredients for identity theft. Criminals can use this combination to open credit accounts, file fraudulent tax returns, apply for government benefits, or impersonate victims when dealing with financial institutions. Because addresses and birth dates change rarely, exposed data of this kind remains useful to criminals for years. It can also fuel targeted phishing, since a scammer who knows your name, address, and the last digits of your financial history sounds far more convincing.
TIAA stated in its notice that it had not detected unusual activity attributable to the incident through its normal monitoring, but that it could not rule out compromise of the listed information.
What Is TIAA.org Doing in Response?
In its July 2023 notices, TIAA said it worked with PBI to investigate the scope of the event, reconciled the downloaded files against its own records, and arranged for Kroll to mail notification letters on a rolling basis. Affected individuals were offered two years of free credit monitoring, fraud consulting, and identity theft restoration services through Kroll, along with a dedicated call line. A class action lawsuit was filed against TIAA in the Southern District of New York on August 7, 2023, according to HALOCK. In November 2024, a TIAA spokesperson told ConsumerAffairs that the circulating data stemmed from the mid-2023 vendor vulnerability and was "neither a new incident nor a security breach of TIAA systems."
What Should You Do If You Were Affected?
Accept the free credit monitoring offered through Kroll if you received a notification letter.
Place a free fraud alert or credit freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
Review your credit reports at annualcreditreport.com and dispute anything you do not recognize.
Watch for phishing calls, texts, and emails that reference your finances; criminals can use breached details to appear legitimate.
Monitor your bank and retirement accounts for unfamiliar activity and consider an IRS Identity Protection PIN to block fraudulent tax filings.
In the news
- ConsumerAffairs: TIAA data breach exposes 2.4 million Social Security numbersconsumeraffairs.com (opens in a new tab)
- Maine Attorney General: TIAA breach notificationmaine.gov (opens in a new tab)
- Iowa Attorney General: TIAA notification letter (PDF)iowaattorneygeneral.gov (opens in a new tab)
- HALOCK: TIAA data breach lawsuithalock.com (opens in a new tab)
