Home > Consumer Information > Privacy, Identity Theft and Data Security Breaches > Data Breach Notifications
Data Breach Notifications
Entity Information
- Type of Organization: Financial Services
- Entity Name: TIAA Kaspick, LLC
- Street Address: 70 Franklin Street, 7th Floor
- City: Boston
- State, or Country if outside the US: MA
- Zip Code: 02110
Submitted By
- Name: Louis Senay
- Title: Managing Director, Head of Supervisory Affairs
- Firm name (if different than entity): TIAA
- Telephone Number: 704-988-6252
- Email Address: lsenay@tiaa.org
- Relationship to entity whose information was compromised: Employee
Breach Information
- Total number of persons affected (including residents): 27946
- Total number of Maine residents affected: 359
- If the number of Maine residents exceeds 1,000, have the consumer reporting agencies been notified:
- Date(s) Breach Occured: 05/29/2023-05/30/2023
- Date Breach Discovered: 06/23/2023
- Description of the Breach:
- External system breach (hacking)
- If other, please specify: Pension Benefit Information, LLC (PBI), a vendor to TIAA Kaspick, LLC (Kaspick), suffered a zero-day exploit in its MOVEIt Transfer server on May 29-30.
- Information Acquired - Name or other personal identifier in combination with: Social Security Number
Notification and Protection Services
- Type of Notification: Written
- Date(s) of consumer notification: 07/14/2023
- Copy of notice to affected Maine residents:
TIAA Kaspick PBI Individual Notification Letter.pdf
PBI - Kaspick - ME Letter.pdf
- Date of any previous (within 12 months) breach notifications:
- Were identity theft protection services offered: Yes
- If yes, please provide the duration, the provider of the service and a brief description of the service: Affected individuals are being offered two (2) years of free credit monitoring, fraud consulting and identity theft restoration services and has provided a call-line for potentially affected individuals to contact with questions or concerns regarding this incident and the services being offered. The provider of the service is Kroll.