Resources for... William & Mary
William & Mary W&M menu close William & Mary

MOVEit Transfer Security Incident

Summary

You may be aware of the cybersecurity event that is impacting thousands of organizations across the world involving a software product called MOVEit. W&M does not use the MOVEit data transfer product itself and university systems are not directly impacted by this event. However, at least three of the university’s third-party vendors who handle data involving W&M people have been impacted (National Student Clearinghouse, United Healthcare and TIAA).

Full Description

W&M is aware that three university vendors were impacted by a recent cybersecurity incident involving a vulnerability in one of their third-party software tools, MOVEit Transfer, a product of Progress Software. MOVEit Transfer is used by thousands of organizations worldwide to transfer enterprise files. W&M does not use the MOVEit data transfer product itself and university systems are not directly impacted by this event. However, at least three of the university’s third-party vendors who handle data involving W&M people have been impacted (National Student Clearinghouse, United Healthcare and TIAA).

While the majority of our community will remain unaffected, we want you to be aware and to be on the lookout for messages from these vendors as they will be reaching out directly to impacted individuals.

W&M IT has convened its Incident Response Team (IR) who is monitoring the situation and will provide updates on this page as they become available. 

The following third-party service providers have notified us that data pertaining to W&M students, faculty and/or staff may have been impacted as a result of the MOVEit incident:

National Student Clearinghouse (NSC) 

NSC is a nonprofit organization that provides educational reporting, verification, and research services to North American colleges and universities.  William & Mary partners with NSC for transcript ordering, enrollment reporting, research services and enrollment and degree verification. NSC will contact you directly if your data is at risk. Visit the NSC website for additional information. 

The Teachers Insurance and Annuity Association (TIAA) 

TIAA is a financial organization that provides investment and insurance services for those working for organizations in the nonprofit industry in academic, research, medical, government and cultural fields. TIAA's subcontractor, Pension Benefits Information (PBI), will contact you directly if your data is at risk. For additional information on safeguarding your account and staying updated, please visit the TIAA Security Center or contact TIAA directly at 800-842-2252 or via email at abuse@tiaa.org.

  • Participants can call TIAA’s National Call Center in advance of receiving their letter from PBI.
  • The phone number for the NCC is 1-800-842-2252.
United Healthcare

The Student Injury & Sickness Insurance Plan designed especially for W&M students is underwritten by United Healthcare Insurance Company. UH will contact you directly if your data is at risk. 

What you can do to help protect your personal information 
Please send any questions related to this incident to [[ciso]].
Frequently Asked Questions
frequently asked questions
Were all students impacted by the National Student Clearinghouse breach?

W&M is still waiting on confirmation from NSC regarding the amount of students who were affected by the breach, but we have reason to believe that the number is limited. If you were impacted, you will receive updates directly from NSC.

I am an employee that uses TIAA, was my data breached?

A limited number of employees were impacted by the TIAA breach. Individuals impacted by the data breach with TIAA will receive specific details directly from them.

I have United Healthcare, was my data breached?

A limited number of students were impacted by the UH breach. Individuals impacted by the data breach with UH will receive specific details directly from them.

I haven't heard from any of these vendors. Does that mean I am in the clear?

We do not have an exact timeline for when each vendor will be reaching out. Please continue to monitor your email for the coming weeks to be safe. 

I've been notified that I was included in the breach. Now what?

Here are some things you can do to protect your personal information

Why would W&M use a product that is susceptible to this kind of breach?

W&M does not use the MOVEit data transfer product itself. The university is one of thousands of other organizations who use these third-party vendors.  

What is the timeline we should expect to learn more?

The Incident Response Team has been and will continue to actively monitor the situation and work directly with the vendors to learn the specifics. We want our community to be aware of the situation and the information we have without causing alarm since many members of our community will remain unaffected. Please know that we will provide timely updates as soon as we have them.