ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

TIAA reports data breach impacting 9,000 clients following a cyberattack on IMS

TIAA, the financial services giant that manages retirement plans for university professors and non-profits, has become the latest major firm to disclose a data breach that compromised client information. The breach, reported by the Maine Attorney General’s office, affected 8,977 customers, including 81 residents of Maine.

 

The cybersecurity incident occurred between October 29 and November 2, 2023, and was traced to Infosys McCamish Systems (IMS), an administrative support services provider for TIAA and its life insurance division, TIAA-CREF Life Insurance Co. According to a letter sent to affected clients, unauthorized parties gained access to IMS systems during this period. TIAA was notified on November 2, 2023, and IMS immediately enlisted a third-party cybersecurity expert to investigate and contain the breach.

 

While the specific client data exposed in the breach has not been disclosed, TIAA assured customers that its own systems and recordkeeping platform were not involved. TIAA has offered two years of complimentary identity monitoring services through Kroll for those affected by the incident.

 

A TIAA spokesperson emphasized the company’s commitment to data security and reassured customers that only retail clients, not institutional plan participants, were impacted.

 

This breach is part of a growing trend of cybersecurity threats targeting financial services firms. Earlier this year, major firms like Interactive Brokers and JPMorgan Chase also reported incidents involving compromised sensitive financial information.

 

Industry experts, such as Lisa Roth, president of compliance firm Monohan & Roth, stress the importance of preventive measures, including enhanced data protection protocols and advisor training to avoid common hacker entry points. Roth also highlighted the critical need for clear breach reporting stipulations in contracts with third-party vendors, an essential element in minimizing the fallout from such attacks.

 

With $1.2 trillion in client assets under management, TIAA is among the largest firms in its sector, making this latest incident a significant concern for affected customers and the broader financial services industry.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543