T. Rowe Price named in Infosys McCamish breach affecting 6 million people
- Organization
- T. Rowe Price Retirement Plan Services
- Exploit
- Third-Party Data Breach
- Industry
- Financial Services
T. Rowe Price Retirement Plan Services was identified in September 2024 as one of the firms whose customers had personal data exposed in the 2023 hack of Infosys McCamish Systems, a business process outsourcer used by insurers and retirement plan administrators. The disclosure came through an amended filing with the Maine Attorney General's Office that updated an earlier notice from June.
Infosys McCamish reported that unauthorized activity took place on its network between October 29 and November 2, 2023, and that it discovered its systems had been encrypted on November 2. The LockBit ransomware operation was linked to the attack, which Infosecurity Magazine reported had encrypted more than 2,000 computers. The amended filing put the total number of people affected at 6,078,263, including over 11,000 Maine residents.
The exposed records varied by individual and could include Social Security numbers, dates of birth, email addresses, usernames and passwords, driver's license and passport numbers, biometric data and financial account information. Alongside T. Rowe Price Retirement Plan Services, the filing named New York Life Group Benefit Solutions and Oceanview Life and Annuity. Principal Life Insurance, Prudential and Vanguard had been reported as affected earlier, and TIAA was added separately in September 2024.
Infosys McCamish said it investigated with outside cybersecurity experts, notified law enforcement, contained and remediated the intrusion, and offered 24 months of monitoring through Kroll. It reported no known fraudulent use of the data.