DataBreachSearch.com

Did TIAA have a data breach?

Answer

Yes. TIAA reported a data breach to the Maryland Attorney General on March 12, 2025.

What the filing says

Reported to
Maryland Attorney General
Filing date
March 12, 2025
Breach date
Not stated in the filing
People affected
Not stated in the filing

In plain terms

TIAA is a prominent financial services organization that provides retirement planning, investment management, and insurance products to individuals and institutional clients. As a financial institution, the company maintains highly sensitive personal and financial records, including Social Security numbers, retirement account details, and tax-related documentation. In 2025, TIAA officially reported a data security incident to the Maryland Attorney General, confirming that unauthorized parties may have accessed the personal information of certain customers. If you received a data breach notification letter from TIAA, it indicates that your specific information was involved in this incident. This notice is intended to inform you of the event, the types of data potentially compromised, and the steps the company is taking to address the security breach.

Other filings by TIAA

Companies often file the same breach in several states. Each filing is listed separately.

Commonly recommended next steps

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Maryland

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with TIAA.