Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Schools Say Data Shared With TIAA Was Exposed in MOVEit Vendor Breach

Schools reported that data connected to their communities was exposed in a MOVEit breach at TIAA vendor Pension Benefit Information. TIAA said its own systems and participant accounts were not compromised.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The headline is directionally right but technically imprecise: schools reported that information connected to their employees or academic communities was exposed in the 2023 MOVEit attack at a TIAA service provider. TIAA said its own systems were not compromised. The affected vendor was Pension Benefit Information, LLC (PBI), which used Progress Software’s MOVEit file-transfer platform.

The incident occurred during the May–June 2023 exploitation of MOVEit. Middlebury College in Vermont and Trinity College in Connecticut were identified in contemporaneous reporting. The available evidence does not show that every TIAA participant was affected, that school networks were breached, or that retirement money was withdrawn.

What happened in the TIAA-related MOVEit incident?

Progress Software received a report of unusual activity involving MOVEit Transfer on May 28, 2023, and disclosed a zero-day vulnerability on May 31. The issue, tracked as CVE-2023-34362, was a SQL-injection flaw that could allow unauthorized access to databases in affected MOVEit environments. Progress later disclosed additional 2023 vulnerabilities, including CVE-2023-35036 and CVE-2023-35708.

MOVEit Transfer is enterprise software used to exchange and store files. Attackers exploited vulnerable installations at many organizations in a mass campaign. Security researchers widely linked the campaign to the Clop (also written Cl0p) cybercrime group, although that attribution is separate from the facts established in the school and TIAA notices. Progress’ incident chronology and technical details are documented in its Form 8-K, MOVEit vulnerability FAQ and 2023 release notes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The relevant path was a third-party chain:

  1. A school or other institution shared employee or participant information with TIAA.
  2. TIAA used PBI for participant and beneficiary-related administrative services.
  3. PBI handled files with MOVEit Transfer.
  4. Attackers exploited PBI’s vulnerable MOVEit environment.
  5. Information associated with TIAA and some participating institutions was exposed through that vendor environment.

This is a supply-chain exposure: an organization’s internal systems can remain uncompromised while data is accessed at a supplier or subcontractor.

Was TIAA directly hacked?

No direct compromise of TIAA’s systems was reported in the cited notices. TIAA’s participant notice says its information systems were not compromised, that no information was obtained from TIAA’s systems through the MOVEit vulnerability, and that it had not detected unusual activity involving participant accounts. TIAA’s contemporaneous comments to TechCrunch likewise identified PBI as the affected vendor.

PBI provides services that help TIAA identify participants who may have died. That supports beneficiary and retirement-plan administration; it does not necessarily represent a complete retirement-account database. The incident therefore should not be described as hackers breaking into TIAA’s core account platform.

Which school communities were identified?

Institution What was reported Status of its own systems
Middlebury College, Vermont Middlebury said it shared employee information with TIAA and that TIAA confirmed Middlebury data was included in the vendor-related exposure. The college described the event as involving a third-party TIAA vendor, not a direct compromise of Middlebury’s systems.
Trinity College, Connecticut Trinity used TIAA as record keeper for its annuity plan and had shared Social Security numbers and dates of birth with TIAA. Files held by TIAA may have been impacted. Trinity said its own systems were unaffected.

These institutions were named in the original reporting; they do not establish that all colleges using TIAA, all teachers, or all TIAA customers were affected. Middlebury’s notice also discussed a separate National Student Clearinghouse-related exposure. That incident should not be merged with the TIAA/PBI event.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information may have been exposed?

TIAA’s participant notification says PBI’s incident may have involved the following fields for affected individuals:

  • First and last name
  • Address
  • Date of birth
  • Gender
  • Social Security number

“May have involved” matters: the list describes possible data elements, not proof that every person’s complete profile was accessed. Exposure varied by individual and by the records supplied to PBI. Trinity’s account specifically discussed Social Security numbers and dates of birth shared with TIAA.

Was money taken from retirement accounts?

The cited evidence does not establish withdrawals, unauthorized transfers, or access to TIAA retirement balances. TIAA said it had not observed related unusual participant-account activity. The documented risk is identity theft, fraud, targeted phishing, or attempts to use exposed personal information—not demonstrated theft of retirement funds.

A lack of detected account fraud does not make exposed Social Security numbers harmless. Identity information can be misused later, which is why credit protections and account monitoring remain appropriate for people who received an official notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What affected people should do

1. Verify that a notice applies to you

Check letters or emails from TIAA, PBI, your school, or Kroll. A school affiliation alone does not prove that you were a PBI record or a TIAA participant. Use a phone number or website you already know rather than links in an unsolicited message.

2. Use the offered monitoring if you are eligible

PBI offered eligible affected individuals free identity-monitoring services through Kroll. Enrollment requires the eligibility information in the official notice. Paid monitoring is not automatically necessary; the Kroll offer is the relevant no-cost remediation described by TIAA.

3. Consider a credit freeze

A freeze with Equifax, Experian, and TransUnion restricts new creditors from accessing your file until you lift the freeze. A fraud alert is an alternative, but a freeze is generally the more direct protection when a Social Security number may be exposed.

4. Review financial and benefits accounts

Check bank, credit-card, retirement, health-benefit, and other financial statements for unfamiliar activity. Turn on transaction alerts where available and contact the institution through its established channel if something looks wrong.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Expect follow-up phishing

Attackers may use the MOVEit incident as a pretext for convincing messages. Do not disclose passwords, one-time codes, Social Security numbers, or account details in response to an unexpected call or email. Use unique, randomized passwords and keep devices and software updated, as TIAA advised in its notice.

6. Report suspected identity theft

Contact the affected financial institution immediately and report suspected identity theft to the appropriate government authorities. Preserve messages, letters, transaction records, and other evidence.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available record does—and does not—establish

  • Established: PBI, a TIAA vendor, used MOVEit; the 2023 MOVEit vulnerabilities were exploited; Middlebury confirmed its data was included; and TIAA described specific personal-data fields that may have been exposed.
  • Not established: a direct compromise of TIAA’s systems, theft from retirement accounts, exposure of every TIAA participant, or identical exposure for every school and individual.
  • Also not established: that every person connected with a named college was a TIAA participant or appeared in PBI’s files.

Why the incident matters beyond TIAA

File-transfer systems aggregate data from many customers, making one vulnerable platform a high-value target. Vendors may retain Social Security numbers and other identity data for legitimate administrative work, while institutions may have limited visibility into how those files are secured downstream.

Patching MOVEit could stop additional exploitation, but it could not reverse data already accessed. Vendors and institutions also needed time to identify affected records and meet notification requirements, which helps explain why notices could arrive well after the initial May 2023 intrusion.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For schools, retirement providers, and other organizations, the lesson is broader than one software flaw: security reviews must include suppliers and subcontractors that store or transmit sensitive identity and benefits information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.