Hackers steal social security numbers, birth dates and more on CalPERS, CalSTRS retirees - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Health/Employee Benefits News
Newswires RSS Get our newsletter
Order Prints
June 23, 2023 Newswires
Share
Share
Tweet
Email

Hackers steal social security numbers, birth dates and more on CalPERS, CalSTRS retirees

Sacramento Bee (CA)

The California Public Employees’ Retirement System reported Wednesday that hackers stole the names, social security numbers, birth dates and other confidential information of roughly 769,000 retirees and beneficiaries, taking advantage of a vulnerability in a contracted vendor’s cybersecurity system.

“This external breach of information is inexcusable,” said CalPERS CEO Marcie Frost in a news release. “Our members deserve better. As soon as we learned about what happened, we took fast action to protect our members’ financial interests, as well as steps to ensure long-term protections.”

CalPERS is the largest pension system in the nation, with more than 2 million members and administering benefits to more than 1.5 million members and their families. CalSTRS, the nation’s second-largest, said Thursday it, too, was hacked through the same vendor, though it denied to offer specifics on who was affected.

“CalSTRS will provide notice to any members and beneficiaries whose personal information was involved in accordance with applicable law,” the West Sacramento-based system said. “This incident did not involve unauthorized access to CalSTRS’ network.”

In a Q&A posted on the agency’s website, CalPERS leaders said that all affected members are eligible to receive two years of free credit monitoring and identity restoration services through Experian. CalPERS mailed letters Thursday with the agency logo and a signed message from the CEO detailing what’s available and how to enroll.

Threat analyst Brett Callow of the cybersecurity firm Emsisoft said the hackers responsible for the attack claim that hundreds of businesses, government agencies and other entities worldwide were victims in the attack.

So far, Callow said, about 100 organizations have announced they had personal data stolen. In a report last week, the U.S. Department of Health and Human Services said that millions of Americans have been affected.

“The cost of this incident will be absolutely enormous,” Callow said. “A small town in Massachusetts called Lowell recently had to offer credit monitoring to its employees. That cost a million bucks. Now, Lowell has a population of just over 100,000, so that can’t be that many city employees.”

CalPERS public information officer Amy Morgan said it was too early to provide an estimate of the agency’s costs. The hackers also may have gotten the information on CalPERS members’ former or current employers, spouses or domestic partners, and children. All types of retirees are affected, whether they worked for the state, public agencies, school districts, in the courts or in the California legislature.

If you believe you were affected but don’t receive a letter by next week, you can call Experian at 833-919-4735 or email CalPERS at [email protected]. The phone line is staffed 6 a.m. to 8 p.m. Monday through Friday and 8 a.m. to 5 p.m. Saturday and Sunday. The line is closed on major holidays.

The agency notice said that a third-party vendor, PBI Research Services + Berwyn Group, had informed CalPERS of the breach on June 6 and that CalPERS moved swiftly to protect the security of its member accounts, rolling out new security protocols to protect member accounts.

CalSTRS said Thursday it was notified June 4, two days before CalPERS.

Retiree asks: What took CalPERS so long?

Randy Cheek, the legislative director of the Retired Public Employees Association, said he was livid that he and other affected members were not informed of this breach immediately. Cheek made a run for a seat on the 13-member CalPERS Board of Administration but lost to retired union chief Yvonne Walker last December.

“They found out about it two weeks ago ... and they’re just now saying something, and they’re gonna send letters out tomorrow,” he said. “On top of that, they didn’t even tell the bank because I just called Golden 1 (Credit Union) and they had no idea. I talked to their top security guy.”

Golden 1, Cheek said, holds accounts on hundreds of thousands of state employees, and it should have been alerted so they could enhance security.

When asked about the lag between learning about the hack and alerting members, CalPERS officials told The Sacramento Bee: “We needed to make sure we had all the facts and that our system was secure before alerting retirees. Our primary duty was and is to ensure the safety of all our member and retiree information.”

PBI, the third-party vendor, helps CalPERS to identify any members who have died, helping the agency to prevent overpayments or other errors. PBI also validates information on inactive members, helping CalPERS to assess who may be eligible for benefits soon.

CalPERS said that PBI was using a data transfer application called MoveIt Transfer, made by Progress Software, that organizations around the nation use to share data securely. The application boasts encryption, tracking and access controls for secure collaboration and automated transfers.

How did hackers get CalPERS data?

The hacker community discovered a critical vulnerability in the MoveIt Transfer software and a ransomware group known as Clop claimed to have exploited it before a patch was deployed, using malicious software code to gain unauthorized access to data not intended to be displayed, according to the notice on the CalPERS website.

Callow said that, as of Thursday morning, victims included 12 state or government entities in the U.S., eight public-sector agencies in other countries and six U.S. universities.

The news agency Cybersecurity Dive reported that at least two federal class-action suits have been filed against Progress Software so far, alleging negligence.

Because the MoveIt Transfer app is used by multiple hospitals, clinics and health insurance groups to share sensitive information such as medical records, bank records and social security numbers, the U.S. Department of Health and Human Services has kept tabs on vulnerabilities that could leave health care companies open to having data stolen or held for ransom.

In a dispatch last week, HHS said that local, state, and federal agencies reported June 15 that the Clop hack had compromised personal data on millions of U.S. citizens.

“Oregon and Louisiana transportation departments have warned millions of residents their identities are at risk after a cyberattack (June 15) stole names, addresses and social security numbers,” HHS officials wrote. “Two Department of Energy entities were among the impacted federal agencies. The education sector was also targeted; Johns Hopkins University in Baltimore and the university’s renowned health system said in a statement this week that sensitive personal and financial information, including health billing records may have been stolen in the hack. The University of Georgia school system is currently investigating the scope and severity of the hack.”

CalPERS officials stressed that their systems were not threatened or breached in this attack and that retirees’ money is secure. They recommended that, in addition to enrolling in credit monitoring services, retirees and beneficiaries regularly review and monitor their accounts and credit reports. If you suspect identity theft or fraud, agency officials said, contact the police.

©2023 The Sacramento Bee. Visit sacbee.com. Distributed by Tribune Content Agency, LLC.

Older

Ill. House Democrats: Mayfield Bill Banning Housing Discrimination Based on Dog Breed Becomes Law

Newer

Forget Florida. These are the 5 most age-friendly states for retirement

Advisor News

  • Flexibility is the future of employee financial wellness benefits
  • Bill aims to boost access to work retirement plans for millions of Americans
  • A new era of advisor support for caregiving
  • Millennial Dilemma: Home ownership or retirement security?
  • How OBBBA is a once-in-a-career window
More Advisor News

Annuity News

  • 2025 Top 5 Annuity Stories: Lawsuits, layoffs and Brighthouse sale rumors
  • An Application for the Trademark “DYNAMIC RETIREMENT MANAGER” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Product understanding will drive the future of insurance
  • Prudential launches FlexGuard 2.0 RILA
  • Lincoln Financial Introduces First Capital Group ETF Strategy for Fixed Indexed Annuities
More Annuity News

Health/Employee Benefits News

  • Tuesday is a big deadline for Mass Health Connector plans — and not all subsidies are going away
  • Health insurance spike will hit 2026 farm budgets, farmers say
  • With no deal in sight, health care costs will rise in 2026. Here’s how that will affect one Lehigh Valley family
  • Repubs and Dems pitch competing plans to tackle affordability
  • THE KID ANGLE: WHAT THE ACA FIGHT HAS TO DO WITH KIDS
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Private placement securities continue to be attractive to insurers
  • Inszone Insurance Services Expands Benefits Department in Michigan with Acquisition of Voyage Benefits, LLC
  • Affordability pressures are reshaping pricing, products and strategy for 2026
  • How the life insurance industry can reach the social media generations
  • Judge rules against loosening receivership over Greg Lindberg finances
More Life Insurance News

- Presented By -

Top Read Stories

  • How the life insurance industry can reach the social media generations
More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • Two industry finance experts join National Life Group amid accelerated growth
  • National Life Group Announces Leadership Transition at Equity Services, Inc.
  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet