Were you recently affected by a data breach?

TIAA Data Breach

TIAA reported an unauthorized acquisition of personal information discovered on September 8, 2026. Names and Social Security numbers were exposed, and the company is offering 24 months of credit monitoring.

TIAA
Date of Breach: Discovered September 8, 2026; notifications began September 25, 2026
CAU logo

Who was affected:

Clients of TIAA

Impacted Data:

Names and Social Security numbers

TIAA has disclosed a data breach involving an unauthorized acquisition of personal information. Names and Social Security numbers are listed as exposed, and the company is offering identity monitoring to people who were notified.

TIAA’s Data Breach Investigation

TIAA is a large U.S. financial services organization best known for retirement savings, annuities and investment products for people who work in education, research, healthcare and other nonprofit fields. Companies like this hold a great deal of sensitive customer and participant information, which makes any security incident a serious concern for the people whose records are involved.

According to the notice sent to affected individuals, TIAA discovered the incident on September 8, 2026. The company describes it as an unauthorized acquisition of personal information, meaning someone outside the organization obtained data they were not supposed to have. TIAA began mailing notification letters on September 25, 2026, roughly two and a half weeks after the discovery.

The incident became publicly visible when TIAA reported it to the Massachusetts Office of Consumer Affairs and Business Regulation on September 25, 2026. That filing identified 13 Massachusetts residents as affected. Companies that operate nationwide typically file separate reports with each state regulator that requires one, so the Massachusetts figure should be read as one state’s share rather than a total count. TIAA has not publicly stated how many people were affected across the country, and this page will be updated if a total is published.

The notice states that the information involved was names combined with Social Security numbers. That pairing is the combination identity thieves value most, because a name and Social Security number together can be used to apply for credit, open accounts, file false tax returns or attempt to take over existing financial accounts. Unlike a password or a credit card number, a Social Security number cannot easily be replaced, so the risk can last for years rather than weeks.

TIAA has not publicly explained how the information was obtained, which systems or vendors were involved, or whether the data has been used or offered for sale. It has also not said what changes it plans to make to prevent a repeat. The letter does not describe any confirmed misuse of the information. A gap between discovery and notification is also normal, since companies usually need time to work out whose data was involved before they can mail letters. Anyone who received a notice should still treat the situation seriously, since stolen data is sometimes held for a long time before it is used.

To help affected individuals, TIAA is providing 24 months of complimentary credit monitoring and identity restoration through Experian IdentityWorks. The package covers monitoring across the three major credit bureaus, internet surveillance for personal information being traded online, identity theft insurance of up to $1 million, and help from a fraud resolution specialist if misuse is found. Households with children can also enroll minors for monitoring. People who received a letter must use the activation code printed in it, and enrollment is open until December 31, 2026. No credit card is required to sign up.

The company has set up two phone lines, one for questions about the Experian membership and one for general questions about the incident. The numbers appear in the notification letter itself, and it is best to use the contact details printed there rather than numbers from an unsolicited call, text or email. Scammers frequently follow a publicized breach with fake messages claiming to be from the affected company.

If you were notified, it is worth keeping the letter and your activation code in a safe place and noting the deadline to enroll. Even if you do not recall how TIAA came to hold your information, you may be connected through an employer retirement plan, an account of your own, or a relationship with a family member. The sections below explain when the incident occurred, what information was involved, and what steps you can take now.

When Did This Breach Occur?

TIAA says it discovered the incident on September 8, 2026. It began notifying affected individuals on September 25, 2026, and reported the matter to the Massachusetts Office of Consumer Affairs and Business Regulation the same day. The company has not disclosed when the unauthorized access itself began.

What Information Was Breached?

According to TIAA’s notice, the information involved was names and Social Security numbers. The company has not reported other data types, such as financial account numbers, in the notice. If your letter lists anything different, rely on your letter, since it is the most accurate guide to what applies to you.

What You Can Do

If you received a notice from TIAA, consider these steps:

  • Enroll in the complimentary Experian IdentityWorks membership using the activation code in your letter before December 31, 2026.
  • Check your credit reports for free at annualcreditreport.com and consider placing a fraud alert or credit freeze with Equifax, Experian and TransUnion.
  • Review your TIAA and other financial account statements for transactions you do not recognize, and report anything suspicious right away.
  • Be cautious with unexpected calls, texts or emails that mention TIAA or your retirement accounts, and use the contact details printed in your letter.
  • Consider an Identity Protection PIN from the IRS to guard against false tax returns, and report identity theft to the Federal Trade Commission at identitytheft.gov.

File a Data Breach Lawsuit Against TIAA

If you were notified of the TIAA data breach, or you believe your name and Social Security number were exposed, you may have legal options. Financial services companies are expected to protect the personal information they hold and to notify people promptly when it is compromised, and a lawsuit can help hold a company accountable when it falls short.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Discovered September 8, 2026; notifications began September 25, 2026
Date of Breach: July 10, 2026 to July 27, 2026
Date of Breach: August 8, 2025 (discovered); notice published September 17, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.