The headline is directionally right but technically imprecise: schools reported that information connected to their employees or academic communities was exposed in the 2023 MOVEit attack at a TIAA service provider. TIAA said its own systems were not compromised. The affected vendor was Pension Benefit Information, LLC (PBI), which used Progress Software’s MOVEit file-transfer platform.
The incident occurred during the May–June 2023 exploitation of MOVEit. Middlebury College in Vermont and Trinity College in Connecticut were identified in contemporaneous reporting. The available evidence does not show that every TIAA participant was affected, that school networks were breached, or that retirement money was withdrawn.
What happened in the TIAA-related MOVEit incident?
Progress Software received a report of unusual activity involving MOVEit Transfer on May 28, 2023, and disclosed a zero-day vulnerability on May 31. The issue, tracked as CVE-2023-34362, was a SQL-injection flaw that could allow unauthorized access to databases in affected MOVEit environments. Progress later disclosed additional 2023 vulnerabilities, including CVE-2023-35036 and CVE-2023-35708.
MOVEit Transfer is enterprise software used to exchange and store files. Attackers exploited vulnerable installations at many organizations in a mass campaign. Security researchers widely linked the campaign to the Clop (also written Cl0p) cybercrime group, although that attribution is separate from the facts established in the school and TIAA notices. Progress’ incident chronology and technical details are documented in its Form 8-K, MOVEit vulnerability FAQ and 2023 release notes.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
The relevant path was a third-party chain:
- A school or other institution shared employee or participant information with TIAA.
- TIAA used PBI for participant and beneficiary-related administrative services.
- PBI handled files with MOVEit Transfer.
- Attackers exploited PBI’s vulnerable MOVEit environment.
- Information associated with TIAA and some participating institutions was exposed through that vendor environment.
This is a supply-chain exposure: an organization’s internal systems can remain uncompromised while data is accessed at a supplier or subcontractor.
Was TIAA directly hacked?
No direct compromise of TIAA’s systems was reported in the cited notices. TIAA’s participant notice says its information systems were not compromised, that no information was obtained from TIAA’s systems through the MOVEit vulnerability, and that it had not detected unusual activity involving participant accounts. TIAA’s contemporaneous comments to TechCrunch likewise identified PBI as the affected vendor.
PBI provides services that help TIAA identify participants who may have died. That supports beneficiary and retirement-plan administration; it does not necessarily represent a complete retirement-account database. The incident therefore should not be described as hackers breaking into TIAA’s core account platform.
Which school communities were identified?
| Institution | What was reported | Status of its own systems |
|---|---|---|
| Middlebury College, Vermont | Middlebury said it shared employee information with TIAA and that TIAA confirmed Middlebury data was included in the vendor-related exposure. | The college described the event as involving a third-party TIAA vendor, not a direct compromise of Middlebury’s systems. |
| Trinity College, Connecticut | Trinity used TIAA as record keeper for its annuity plan and had shared Social Security numbers and dates of birth with TIAA. Files held by TIAA may have been impacted. | Trinity said its own systems were unaffected. |
These institutions were named in the original reporting; they do not establish that all colleges using TIAA, all teachers, or all TIAA customers were affected. Middlebury’s notice also discussed a separate National Student Clearinghouse-related exposure. That incident should not be merged with the TIAA/PBI event.
What information may have been exposed?
TIAA’s participant notification says PBI’s incident may have involved the following fields for affected individuals:
- First and last name
- Address
- Date of birth
- Gender
- Social Security number
“May have involved” matters: the list describes possible data elements, not proof that every person’s complete profile was accessed. Exposure varied by individual and by the records supplied to PBI. Trinity’s account specifically discussed Social Security numbers and dates of birth shared with TIAA.
Rank #3
Was money taken from retirement accounts?
The cited evidence does not establish withdrawals, unauthorized transfers, or access to TIAA retirement balances. TIAA said it had not observed related unusual participant-account activity. The documented risk is identity theft, fraud, targeted phishing, or attempts to use exposed personal information—not demonstrated theft of retirement funds.
A lack of detected account fraud does not make exposed Social Security numbers harmless. Identity information can be misused later, which is why credit protections and account monitoring remain appropriate for people who received an official notice.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What affected people should do
1. Verify that a notice applies to you
Check letters or emails from TIAA, PBI, your school, or Kroll. A school affiliation alone does not prove that you were a PBI record or a TIAA participant. Use a phone number or website you already know rather than links in an unsolicited message.
2. Use the offered monitoring if you are eligible
PBI offered eligible affected individuals free identity-monitoring services through Kroll. Enrollment requires the eligibility information in the official notice. Paid monitoring is not automatically necessary; the Kroll offer is the relevant no-cost remediation described by TIAA.
3. Consider a credit freeze
A freeze with Equifax, Experian, and TransUnion restricts new creditors from accessing your file until you lift the freeze. A fraud alert is an alternative, but a freeze is generally the more direct protection when a Social Security number may be exposed.
4. Review financial and benefits accounts
Check bank, credit-card, retirement, health-benefit, and other financial statements for unfamiliar activity. Turn on transaction alerts where available and contact the institution through its established channel if something looks wrong.
Recommended Free Tools
5. Expect follow-up phishing
Attackers may use the MOVEit incident as a pretext for convincing messages. Do not disclose passwords, one-time codes, Social Security numbers, or account details in response to an unexpected call or email. Use unique, randomized passwords and keep devices and software updated, as TIAA advised in its notice.
6. Report suspected identity theft
Contact the affected financial institution immediately and report suspected identity theft to the appropriate government authorities. Preserve messages, letters, transaction records, and other evidence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the available record does—and does not—establish
- Established: PBI, a TIAA vendor, used MOVEit; the 2023 MOVEit vulnerabilities were exploited; Middlebury confirmed its data was included; and TIAA described specific personal-data fields that may have been exposed.
- Not established: a direct compromise of TIAA’s systems, theft from retirement accounts, exposure of every TIAA participant, or identical exposure for every school and individual.
- Also not established: that every person connected with a named college was a TIAA participant or appeared in PBI’s files.
Why the incident matters beyond TIAA
File-transfer systems aggregate data from many customers, making one vulnerable platform a high-value target. Vendors may retain Social Security numbers and other identity data for legitimate administrative work, while institutions may have limited visibility into how those files are secured downstream.
Patching MOVEit could stop additional exploitation, but it could not reverse data already accessed. Vendors and institutions also needed time to identify affected records and meet notification requirements, which helps explain why notices could arrive well after the initial May 2023 intrusion.
Free tools Windows power users keep installed
One-click scans. No signup required.
For schools, retirement providers, and other organizations, the lesson is broader than one software flaw: security reviews must include suppliers and subcontractors that store or transmit sensitive identity and benefits information.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




