CalPERS said 769,000 retirees were exposed by a vendor's MOVEit breach

Organization
California Public Employees' Retirement System (CalPERS)
Exploit
Third-Party Data Breach
Industry
Public Pension Fund

The California Public Employees' Retirement System said in June 2023 that the personal information of roughly 769,000 retirees and beneficiaries had been taken in a breach at one of its vendors.

The vendor, PBI Research Services, part of the Berwyn Group, is used by CalPERS to identify member deaths and keep benefit payments accurate. PBI's systems were caught in the mass exploitation of a vulnerability in Progress Software's MOVEit Transfer product. CalPERS said PBI notified it on June 6 and that it made the breach public on June 22. The Retired Public Employees Association criticised the delay, and CalPERS said it needed to establish the facts first. Its chief executive, Marcie Frost, called the external breach inexcusable.

The exposed data included first and last names, dates of birth and Social Security numbers, and in some cases the names of members' current or former employers, spouses or domestic partners, and children. CalPERS said its own systems, including the myCalPERS portal, were not compromised, and that it had sent the data to PBI in encrypted form.

CalPERS wrote to affected retirees, beneficiaries and inactive members approaching benefit eligibility, and offered two years of credit monitoring and identity restoration through Experian. The California State Teachers' Retirement System, which uses PBI for the same purpose, posted its own notice on June 26 covering names, Social Security numbers, dates of birth and ZIP codes. CalSTRS said its network was not accessed and did not publish a figure for affected members.

Sources