TIAA has disclosed a data breach involving an unauthorized acquisition of personal information. Names and Social Security numbers are listed as exposed, and the company is offering identity monitoring to people who were notified.
TIAA’s Data Breach Investigation
TIAA is a large U.S. financial services organization best known for retirement savings, annuities and investment products for people who work in education, research, healthcare and other nonprofit fields. Companies like this hold a great deal of sensitive customer and participant information, which makes any security incident a serious concern for the people whose records are involved.
According to the notice sent to affected individuals, TIAA discovered the incident on September 8, 2026. The company describes it as an unauthorized acquisition of personal information, meaning someone outside the organization obtained data they were not supposed to have. TIAA began mailing notification letters on September 25, 2026, roughly two and a half weeks after the discovery.
The incident became publicly visible when TIAA reported it to the Massachusetts Office of Consumer Affairs and Business Regulation on September 25, 2026. That filing identified 13 Massachusetts residents as affected. Companies that operate nationwide typically file separate reports with each state regulator that requires one, so the Massachusetts figure should be read as one state’s share rather than a total count. TIAA has not publicly stated how many people were affected across the country, and this page will be updated if a total is published.
The notice states that the information involved was names combined with Social Security numbers. That pairing is the combination identity thieves value most, because a name and Social Security number together can be used to apply for credit, open accounts, file false tax returns or attempt to take over existing financial accounts. Unlike a password or a credit card number, a Social Security number cannot easily be replaced, so the risk can last for years rather than weeks.
TIAA has not publicly explained how the information was obtained, which systems or vendors were involved, or whether the data has been used or offered for sale. It has also not said what changes it plans to make to prevent a repeat. The letter does not describe any confirmed misuse of the information. A gap between discovery and notification is also normal, since companies usually need time to work out whose data was involved before they can mail letters. Anyone who received a notice should still treat the situation seriously, since stolen data is sometimes held for a long time before it is used.
To help affected individuals, TIAA is providing 24 months of complimentary credit monitoring and identity restoration through Experian IdentityWorks. The package covers monitoring across the three major credit bureaus, internet surveillance for personal information being traded online, identity theft insurance of up to $1 million, and help from a fraud resolution specialist if misuse is found. Households with children can also enroll minors for monitoring. People who received a letter must use the activation code printed in it, and enrollment is open until December 31, 2026. No credit card is required to sign up.
The company has set up two phone lines, one for questions about the Experian membership and one for general questions about the incident. The numbers appear in the notification letter itself, and it is best to use the contact details printed there rather than numbers from an unsolicited call, text or email. Scammers frequently follow a publicized breach with fake messages claiming to be from the affected company.
If you were notified, it is worth keeping the letter and your activation code in a safe place and noting the deadline to enroll. Even if you do not recall how TIAA came to hold your information, you may be connected through an employer retirement plan, an account of your own, or a relationship with a family member. The sections below explain when the incident occurred, what information was involved, and what steps you can take now.
When Did This Breach Occur?
TIAA says it discovered the incident on September 8, 2026. It began notifying affected individuals on September 25, 2026, and reported the matter to the Massachusetts Office of Consumer Affairs and Business Regulation the same day. The company has not disclosed when the unauthorized access itself began.
What Information Was Breached?
According to TIAA’s notice, the information involved was names and Social Security numbers. The company has not reported other data types, such as financial account numbers, in the notice. If your letter lists anything different, rely on your letter, since it is the most accurate guide to what applies to you.
What You Can Do
If you received a notice from TIAA, consider these steps:
- Enroll in the complimentary Experian IdentityWorks membership using the activation code in your letter before December 31, 2026.
- Check your credit reports for free at annualcreditreport.com and consider placing a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Review your TIAA and other financial account statements for transactions you do not recognize, and report anything suspicious right away.
- Be cautious with unexpected calls, texts or emails that mention TIAA or your retirement accounts, and use the contact details printed in your letter.
- Consider an Identity Protection PIN from the IRS to guard against false tax returns, and report identity theft to the Federal Trade Commission at identitytheft.gov.
File a Data Breach Lawsuit Against TIAA
If you were notified of the TIAA data breach, or you believe your name and Social Security number were exposed, you may have legal options. Financial services companies are expected to protect the personal information they hold and to notify people promptly when it is compromised, and a lawsuit can help hold a company accountable when it falls short.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.