{"id":41576,"date":"2023-06-30T13:21:50","date_gmt":"2023-06-30T17:21:50","guid":{"rendered":"https:\/\/inside.wooster.edu\/technology\/?page_id=41576"},"modified":"2023-07-12T14:01:07","modified_gmt":"2023-07-12T18:01:07","slug":"tiaa-moveit-transfer-security-vulnerability","status":"publish","type":"page","link":"https:\/\/inside.wooster.edu\/technology\/moveit-transfer-security-vulnerability\/tiaa-moveit-transfer-security-vulnerability\/","title":{"rendered":"TIAA MOVEIt Transfer Security Vulnerability"},"content":{"rendered":"\n<p>The College received notification that one of TIAA&#8217;s third-party vendors has been affected by the MOVEIt security vulnerability. TIAA confirmed that there are some individuals affiliated with the College whose personal information was involved.<\/p>\n\n\n\n<p>The Teachers Insurance and Annuity Association (TIAA) is a financial organization that provides investment and insurance services for those working for organizations in the nonprofit industry in academic, research, medical, government, and cultural fields.  TIAA administers the College&#8217;s 403(b) retirement plan. <\/p>\n\n\n\n<h2 id=\"updates\" class=\"wp-block-heading\">Updates<\/h2>\n\n\n\n<section id=\"436779\" class=\"section-436779 gutentor-module gutentor-module-accordion\"><div class=\"grid-container\">\n<div id=\"bb7f29\" class=\"wp-block-gutentor-m6-item section-bb7f29 gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-436779\"><div tabindex=\"0\" class=\"gm-ah-436779 gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>June 30, 2023<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-436779 gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-436779 gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-436779 gutentor-module-accordion-body\">\n<div id=\"section-gbf512a\" class=\"wp-block-gutentor-e0 section-gbf512a gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\"><em>Sent to ZWDfaculty, ZWDStaff, ZWDRetirees<\/em><br>Dear Colleagues,<br><br>The College received notification from TIAA that one of its third-party vendors has been affected by the MOVEIt security vulnerability. TIAA confirmed that there are some individuals affiliated with the College whose personal information was involved.<br><br>TIAA is the latest organization reporting that it has been impacted by the vulnerability in the MOVEIt file transfer application that has been covered in <a href=\"https:\/\/techcrunch.com\/2023\/06\/15\/moveit-clop-mass-hacks-banks-universities\/\">national and technology media<\/a>. Wednesday evening, I wrote that the National Student Clearinghouse (NSC) notified us that some of the student data we provides to them was accessed in a similar incident.\u00a0<br><br>TIAA has indicated that the personal information that is part of the incident is first and last name, address, date of birth, gender, and Social Security Number.\u00a0<br><br>Pension Benefit Information, LLC (&#8220;PBI&#8221;), TIAA\u2019s third-party vendor, will send affected individuals a letter in the coming weeks offering free credit monitoring for two years at no cost to them.<br><br>Additional information is provided in the TIAA update received today (below).\u00a0<br><br>For additional information on safeguarding your account and staying updated, please visit the <a href=\"https:\/\/www.tiaa.org\/public\/support\/security-center\">TIAA Security Center<\/a> or contact TIAA directly at 800-842-2252 or via email at <a href=\"mailto:abuse@tiaa.org\">abuse@tiaa.org<\/a><br><br>Information Technology continues to monitor this developing event, both through TIAA communications and information security lists.\u00a0 We will provide relevant updates as we have them. We are compiling information about the College\u2019s service providers that have been impacted by the MOVEIt vulnerability on <a href=\"https:\/\/inside.wooster.edu\/technology\/\">IT\u2019s website<\/a>.<br><br>If you have any questions about this incident, please contact Vince DiScipio or Ellen Falduto.<\/p><\/div><\/div>\n<\/div><\/div><\/div>\n<\/div><\/section>\n\n\n\n<h2 id=\"faq\" class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<section id=\"25d75f\" class=\"section-25d75f gutentor-module gutentor-module-accordion\"><div class=\"grid-container\">\n<div id=\"ee678b\" class=\"wp-block-gutentor-m6-item section-ee678b gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>Where can I learn more about TIAA&#8217;s privacy policies &amp; practices?<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-geb35e7\" class=\"wp-block-gutentor-e0 section-geb35e7 gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">See TIAA&#8217;s <a rel=\"noreferrer noopener\" href=\"https:\/\/www.tiaa.org\/public\/support\/privacy\" data-type=\"URL\" data-id=\"https:\/\/www.tiaa.org\/public\/support\/privacy\" target=\"_blank\">privacy commitment<\/a><\/p><\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n<div id=\"3c3f7b\" class=\"wp-block-gutentor-m6-item section-3c3f7b gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>Where can I learn more about how TIAA protects my information?<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-g2e570c\" class=\"wp-block-gutentor-e0 section-g2e570c gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">See TIAA&#8217;s <a rel=\"noreferrer noopener\" href=\"https:\/\/www.tiaa.org\/public\/support\/security-center\" target=\"_blank\">data protection commitment.<\/a><\/p><\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n<div id=\"c9528a\" class=\"wp-block-gutentor-m6-item section-c9528a gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>How do I report suspicious activity on my TIAA account? <\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-g12c07d\" class=\"wp-block-gutentor-e0 section-g12c07d gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">Call TIAA at 800-842-2252, weekdays, 8 a.m. \u2013 10 p.m. (ET)<\/p><\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n<div id=\"b09337\" class=\"wp-block-gutentor-m6-item section-b09337 gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>How do I know if my information was involved?<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-g2bc6ff\" class=\"wp-block-gutentor-e0 section-g2bc6ff gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">You will receive a letter from TIAA and\/or PBI stating that your information was involved. The letter will include more information about next steps. The sending of letters was expected to begin the week of July 10, 2023.<\/p><\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n<div id=\"29e786\" class=\"wp-block-gutentor-m6-item section-29e786 gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>If my information was involved, what happens next?<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-g58a2ab\" class=\"wp-block-gutentor-e0 section-g58a2ab gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">You should receive a letter by mail from TIAA&#8217;s third-party vendor, Pension Benefit Information, LLC (\u201cPBI\u201d). PBI will fulfill all required obligations under federal and state privacy regulations, including notifying you and offering free credit monitoring for two years at no cost. The letter will provide instructions and a unique code to reference when registering for the free credit monitoring. The letter will include a telephone number you may call to learn more or ask questions about the credit monitoring service.<\/p><\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n<div id=\"bf1f66\" class=\"wp-block-gutentor-m6-item section-bf1f66 gutentor-module gutentor-module-accordion-item\"><div class=\"gutentor-module-accordion-panel g-a-panel-25d75f\"><div tabindex=\"0\" class=\"gm-ah-25d75f gutentor-module-accordion-item-heading gutentor-module-icon-position-right\"><span class=\"gutentor-module-accordion-panel-handler\" role=\"button\"><span class=\"gutentor-module-accordion-panel-handler-label\"><strong>Who may I contact if I have questions?<\/strong><\/span><span class=\"gutentor-module-accordion-icon\"><i class=\"gm-aio-25d75f gutentor-module-accordion-icon-open fas fa-plus\"><\/i><i class=\"gm-aic-25d75f gutentor-module-accordion-icon-close fas fa-minus\"><\/i><\/span><\/span><\/div><div class=\"gm-ab-25d75f gutentor-module-accordion-body\">\n<div id=\"section-g50a1a2\" class=\"wp-block-gutentor-e0 section-g50a1a2 gutentor-element gutentor-element-advanced-text\"><div class=\"gutentor-text-wrap\"><p class=\"gutentor-text\">Specific questions about your information, next steps, or credit monitoring should be directed to the organization in the letter you receive from PBI.<\/p><\/div><\/div>\n<\/div><\/div><\/div>\n<\/div><\/section>\n\n\n\n<h2 id=\"tiaa-resources\" class=\"wp-block-heading\">TIAA Resources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EW9aBEZqFfRKrBGg51BiBHcBEaUdJc5PA19ljyxivALzVg?e=OKnnQR\" data-type=\"URL\" data-id=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EW9aBEZqFfRKrBGg51BiBHcBEaUdJc5PA19ljyxivALzVg?e=OKnnQR\" target=\"_blank\" rel=\"noreferrer noopener\">TIAA Cyber Safety Tips<\/a><\/li>\n<\/ul>\n\n\n\n<h2 id=\"tiaa-notices-to-the-college\" class=\"wp-block-heading\">TIAA notices to the College<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EacrCUy1jZNPr7GxOSbsmnAB32mzms9pIfbhSATDVMjdAQ?e=Yz3xFU\" data-type=\"URL\" data-id=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EacrCUy1jZNPr7GxOSbsmnAB32mzms9pIfbhSATDVMjdAQ?e=Yz3xFU\" target=\"_blank\" rel=\"noreferrer noopener\">June 16, 2023<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EQZ0uq0q0w9Av5pcqkfS5xEBBzsW-W4KKkfEE84EsBlQSg?e=ca8VUY\" data-type=\"URL\" data-id=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EQZ0uq0q0w9Av5pcqkfS5xEBBzsW-W4KKkfEE84EsBlQSg?e=ca8VUY\" target=\"_blank\" rel=\"noreferrer noopener\">June 22, 2023<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EZPyNE1XDIRGoFObMKQUMEABckv9EsJzCZYWfXf_Fti-GQ?e=c8hbPa\" data-type=\"URL\" data-id=\"https:\/\/livewooster.sharepoint.com\/:b:\/s\/IT-Everyone-InfoSecurityIncidents\/EZPyNE1XDIRGoFObMKQUMEABckv9EsJzCZYWfXf_Fti-GQ?e=c8hbPa\" target=\"_blank\" rel=\"noreferrer noopener\">June 29, 2023<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The College received notification that one of TIAA&#8217;s third-party vendors has been affected by the MOVEIt security vulnerability. TIAA confirmed that there are some individuals affiliated with the College whose personal information was involved. The Teachers Insurance and Annuity Association (TIAA) is a financial organization that provides investment and insurance services for those working for [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":0,"parent":41565,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_uag_custom_page_level_css":"","footnotes":""},"coauthors":[436],"class_list":["post-41576","page","type-page","status-publish","hentry"],"acf":[],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":""},"post_excerpt_stackable":"<p>The College received notification that one of TIAA&#8217;s third-party vendors has been affected by the MOVEIt security vulnerability. TIAA confirmed that there are some individuals affiliated with the College whose personal information was involved. The Teachers Insurance and Annuity Association (TIAA) is a financial organization that provides investment and insurance services for those working for organizations in the nonprofit industry in academic, research, medical, government, and cultural fields. TIAA administers the College&#8217;s 403(b) retirement plan. Updates June 30, 2023 Sent to ZWDfaculty, ZWDStaff, ZWDRetireesDear Colleagues,The College received notification from TIAA that one of its third-party vendors has been affected by&hellip;<\/p>\n","category_list":"","author_info":{"name":"Ellen Falduto","url":"https:\/\/inside.wooster.edu\/technology\/author\/efaldutowooster-edu\/"},"comments_num":"0 comments","uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Ellen Falduto","author_link":"https:\/\/inside.wooster.edu\/technology\/author\/efaldutowooster-edu\/"},"uagb_comment_info":0,"uagb_excerpt":"The College received notification that one of TIAA&#8217;s third-party vendors has been affected by the MOVEIt security vulnerability. TIAA confirmed that there are some individuals affiliated with the College whose personal information was involved. The Teachers Insurance and Annuity Association (TIAA) is a financial organization that provides investment and insurance services for those working for&hellip;","_links":{"self":[{"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/pages\/41576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/comments?post=41576"}],"version-history":[{"count":22,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/pages\/41576\/revisions"}],"predecessor-version":[{"id":46445,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/pages\/41576\/revisions\/46445"}],"up":[{"embeddable":true,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/pages\/41565"}],"wp:attachment":[{"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/media?parent=41576"}],"wp:term":[{"taxonomy":"author","embeddable":true,"href":"https:\/\/inside.wooster.edu\/technology\/wp-json\/wp\/v2\/coauthors?post=41576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}