A breach of 401(k) participant data earlier this year prompted a class action lawsuit this month against Transamerica Retirement Solutions.
In June, the company became aware of a change within one of its websites that let employer customers view compromising data about participants in other retirement plans, according to a notice posted by the State of California. That data included Social Security numbers, birth dates and other personally identifying information.
The data was only viewable by plan administrators who had permission to access the site, the company stated in the disclosure sent in August to 401(k) participants. At the time, Transamerica said that it was unaware of any participant data being misused, it had fixed the glitch and would provide two years of identity monitoring services to people whose data were compromised.
But that was insufficient, the plaintiff representing the proposed class said.
The company failed to protect sensitive information and waited too long to make 401(k) participants aware of the problem, according to the Dec. 3 complaint filed in U.S. District Court in the Southern District of New York.
That man, California resident Eric Giannini, “has experienced a number of harms as a result of the data breach incident since Transamerica’s systems were accessed, including the misuse of his identifying information for fraudulent purchases,” the complaint read.
Giannini claimed that he was not contacted about his data being compromised until Oct. 8.
The law firm representing him and the proposed class, Migliaccio & Rathod, said in the complaint that the affected plan participants “will continue to experience various types of misuse of their [personally identifying information] in the coming years, including but not limited to unauthorized credit card charges, unauthorized access to email accounts and other fraudulent use of their financial information.”
The complaint alleges negligence, breach of contract, breach of fiduciary duty and violations of New York and California state laws.
The case differs from others brought in recent years against retirement plan record keepers over data security, in that it is a class action and does not indicate that any 401(k) assets were pilfered.
Individual lawsuits against Alight Solutions and plan sponsors, for example, centered on thefts from accounts.
The new case also does not raise claims under the Employee Retirement Income Security Act.
Transamerica said in a statement that it was aware of the lawsuit, calling the allegations “inaccurate and misleading.”
“At no time did unauthorized individuals gain access to Transamerica’s systems as the lawsuit suggests,” the statement read. “Transamerica is proud of the services we provide to our retirement plan clients, and we will vigorously defend against this lawsuit. We remain dedicated to providing the highest quality of care and security to our customers.”
InvestmentNews reported in 2017 that the IRS was scrutinizing the tax shelter land deals, called syndication conservation easements.
Advisors gain a second workflow for 401(k) guidance as the fintech expands beyond bulk rebalancing, backed by new policy research on advice access.
New data shows most people do not have enough saved to cover costs and are not fully utilizing their accounts.
Firms announce new recruits this week, with teams overseeing hundreds of millions in client assets switching affiliations.
It’s the 12th deal for Stratos since SEI's investment and follows 11 acquisitions worth $4.8B in 2025.
Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains
Dan Biagini of American Equity says the steady decline of pensions, longer lifespans and a reset in interest rates are rewriting how advisors build retirement income