The personal information of about 769,000 retired CalPERS members was exposed in a third-party data breach that was reported earlier this month. CalSTRS also said it was affected by the breach and KCRA 3 is trying to find out how many of its members were affected. CalPERS, the California Public Employees Retirement System, is the nation’s largest public pension fund. It serves more than 2 million members in its retirement system and more than 1.5 million in its health program. CalSTRS, the California State Teacher Retirement System, is the second largest public pension fund in the United States and the largest teacher retirement system . It serves more than 947,000 members. CalPERS first said in a statement Wednesday that its third-party provider PBI Research Services/Berwyn Group notified the agency on June 6 of a vulnerability with its MOVEit transfer app that has since been fixed. PBI helps CalPERS identify member deaths and make sure the correct payments reach retirees and their beneficiaries. The vulnerability in the app allowed data such as first and last name, date of birth and social security numbers to be downloaded by an unauthorized third party, CalPERS said. The names of the members’ relatives could also have been accessed. CalPERS said the breach did not affect its own information systems, myCalPERS or active members. It also does not affect members’ monthly benefit payments. But along with retired members and their families, the violation could also have affected inactive members who soon become eligible for benefits, CalPERS said. PBI said it reported the rape to the federal police. CalPERS said thousands of other organizations have also been affected by the breach. CalPERS said Thursday it will begin sending affected members letters about the breach and offer them free credit monitoring from Experian for two years. It was not immediately clear if CalPERS has received reports of fraud in connection with the violation. KCRA 3 also questions why the agency waited until this week to announce the violation. People can email questions about the violation to PBIquestions@calpers.ca.gov or call 833-919-4735 Monday through Friday from 6 a.m. to 8 p.m. or Saturday and Sunday from 8 a.m. to 5 p.m. CalPERS said that in response to the breach it is developing new protocols for myCalPERS and safeguards for those who use the call center or visit a regional office. “This external data breach is inexcusable,” CalPERS Executive Director Marcie Frost said in a statement. “Our members deserve better. As soon as we learned what happened, we took swift action to protect our members’ financial interests, as well as action to ensure long-term protection.” On Thursday, CalSTRS confirmed that he was also affected when asked by KCRA 3. The system said it was notified on June 4, two days before CalPERS said it was notified. “This incident did not involve unauthorized access to the CalSTRS network,” CalSTRS said. “CalSTRS is working with PBI to identify CalSTRS members whose information was involved in the PBI incident. CalSTRS will notify members and beneficiaries whose personal information was involved in accordance with applicable law.”
The personal information of about 769,000 retired CalPERS members was exposed in a third party data breach which was reported earlier this month. CalSTRS also said it was affected by the breach and KCRA 3 is trying to find out how many of its members were affected.
CalPERS, the California Public Employees Retirement System, is the nation’s largest public pension fund. It serves more than 2 million affiliates in its retirement system and more than 1.5 million in its health program.
CalSTRS, the California State Teacher Retirement System, is the second largest public pension fund in the United States and the largest teacher retirement system. It serves more than 947,000 members.
CalPERS first said in a statement Wednesday that its third-party provider PBI Research Services/Berwyn Group notified the agency on June 6 of a vulnerability with its MOVEit transfer app that has since been fixed.
PBI helps CalPERS identify member deaths and make sure the correct payments reach retirees and their beneficiaries.
The vulnerability in the app allowed data such as first and last name, date of birth and social security numbers to be downloaded by an unauthorized third party, CalPERS said. The names of the members’ relatives could also have been accessed.
CalPERS said the breach did not affect its own information systems, myCalPERS or active members. It also does not affect members’ monthly benefit payments.
But along with retired members and their families, the violation could also have affected inactive members who soon become eligible for benefits, CalPERS said.
PBI said it reported the rape to the federal police. CalPERS said thousands of other organizations have also been affected by the breach.
CalPERS said Thursday it will begin sending affected members letters about the breach and offer them free credit monitoring from Experian for two years.
It was not immediately clear if CalPERS has received reports of fraud in connection with the violation. KCRA 3 also questions why the agency waited until this week to announce the violation.
Individuals can email questions about the violation to PBIquestions@calpers.ca.gov or call 833-919-4735 Monday through Friday from 6 am to 8 pm or Saturday and Sunday from 8 am to 5 pm
CalPERS said that, in response to the violation, it is creating new protocols for myCalPERS and safeguards for those who use the call center or visit a regional office.
“This external data breach is inexcusable,” CalPERS Executive Director Marcie Frost said in a statement. “Our members deserve better. As soon as we learned what happened, we took swift action to protect our members’ financial interests, as well as action to ensure long-term protection.”
On Thursday, CalSTRS confirmed that he was also affected when asked by KCRA 3. The system said it was notified on June 4, two days before CalPERS said it was notified.
“This incident did not involve unauthorized access to the CalSTRS network,” CalSTRS said. “CalSTRS is working with PBI to identify CalSTRS members whose information was involved in the PBI incident. CalSTRS will notify members and beneficiaries whose personal information was involved in accordance with applicable law.”
Discover more from PressNewsAgency
Subscribe to get the latest posts sent to your email.