Retirement Clearinghouse reports data breach

Retirement Clearinghouse reports data breach
Social Security and account numbers were compromised in a phishing attack, but accounts were not accessed, according to the firm.
MAY 25, 2023

Retirement Clearinghouse, a 401(k) and IRA portability firm, is the latest business to report a data breach, earlier this month notifying more than 10,000 account holders that their Social Security numbers had been compromised.

In notices to various states, the firm disclosed that a phishing attempt earlier this year potentially exposed client data.

“On or about March 15, 2023, Retirement Clearinghouse identified potentially suspicious activity for one email account, and promptly took steps to confirm the security of the account,” the company wrote in its disclosure to the Maine attorney general’s office. “Retirement Clearinghouse began an investigation and, in the interim, notified a potentially affected organization on March 18, 2023.”

Retirement Clearinghouse sent letters May 12 to potentially affected account holders. The data breach was reported Tuesday by mutual fund trade publication Ignites.

A personal injury law firm also took note of the data breach notice last week.

In addition to Social Security numbers being compromised, IRA account numbers at Matrix Trust Co. were exposed.

“We are coordinating with Retirement Clearinghouse in their efforts to inform all impacted individuals of this situation and the services being offered to protect their data,” a spokesperson at Broadridge Financial Solutions, parent company of Matrix, said in an email. That firm was unaware of any unauthorized access to accounts as of today, he said.

In response to the breach, Retirement Clearinghouse is “evaluating additional safeguards to mitigate recurrence of this type of event,” it stated in the notice in Maine. It is also “providing access to credit monitoring services for twelve months, through Experian, to individuals whose information was potentially affected by this event, at no cost to these individuals.”

In an email, Retirement Clearinghouse CEO Spencer Williams declined to say when an employee’s email was phished, but he noted that the firm took several steps to protect accounts after it was discovered.

“RCH responded by shutting down the affected account, confiscating all equipment and engaging a third-party forensic firm to ensure that no further data was exposed. That finding was confirmed. RCH subsequently made filings with states, as required by law, and has taken additional actions to reduce future potential email phishing incidents,” Williams said. “At no point were RCH customer accounts exposed to the bad actor, nor were RCH customer assets at risk.”

Retirement Clearinghouse provides retirement account portability services and is part of the Portability Services Network, a group that provides automatic account portability for 401(k)s and other types of retirement plans. Plan record keepers that are part of that network include Vanguard, TIAA, Fidelity, Empower and Alight Solutions.

Data compromises are nothing new in the financial services industry, though they appear to be increasingly common in the retirement business. In 2021, for example, Transamerica disclosed with the California attorney general’s office that a change to one of its plan administration websites temporarily allowed other employers to access information in plans that were not their own. Alight Solutions has also faced lawsuits over compromised accounts.

However, record keepers tend to have safeguards in place, and some have made account-security guarantees to put participants and plan sponsors at ease.

Two years ago, the Department of Labor issued cybersecurity guidance for plan fiduciaries, service providers and account owners. That guidance includes tips for hiring service providers, best practices for cybersecurity for record keepers and security suggestions for plan participants.

Rev up your referral engine by increasing client engagement

Latest News

Northern Trust names new West Region president for wealth
Northern Trust names new West Region president for wealth

The new regional leader brings nearly 25 years of experience as the firm seeks to tap a complex and evolving market.

Capital Group extends retirement plan services further with a focus on advisors
Capital Group extends retirement plan services further with a focus on advisors

The latest updates to its recordkeeping platform, including a solution originally developed for one large 20,000-advisor client, take aim at the small to medium-sized business space.

Why RIAs are the next growth frontier for annuities
Why RIAs are the next growth frontier for annuities

David Lau, founder and CEO of DPL Financial Partners, explains how the RIA boom and product innovation has fueled a slow-burn growth story in annuities.

Supreme Court slaps down challenge to IRS summons for Coinbase user data
Supreme Court slaps down challenge to IRS summons for Coinbase user data

Crypto investor argues the federal agency's probe, upheld by a federal appeals court, would "strip millions of Americans of meaningful privacy protections."

Houston-based RIA Americana Partners adds $1B+ with former Morgan Stanley director
Houston-based RIA Americana Partners adds $1B+ with former Morgan Stanley director

Meanwhile in Chicago, the wirehouse also lost another $454 million team as a group of defectors moved to Wells Fargo.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.