Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Security topic
No spam. Unsubscribe anytime.
District reports 403(b) vendor data breach; FAQs posted
Summary
Tony, the district business/fiscal lead, told the board that Cruz Compliance Consulting — the district's third‑party 403(b) administrator — experienced unauthorized access to sensitive client information in December; the district posted FAQs and resources and the vendor and district are offering protections for affected staff.
Get email alerts on the Data Security topic
No spam. Unsubscribe anytime.
During the business and fiscal report, the district addressed a data breach affecting a third‑party 403(b) provider identified in the presentation as Cruz Compliance Consulting (the transcript also recorded the name as "Cruise Compliance Consulting" in other places). Tony, who led the report, said the vendor detected suspicious activity impacting sensitive client information between Dec. 19 and Dec. 26, 2024; the vendor's investigation concluded Jan. 13, 2025.
"We were informed... that on December 21, there was suspicious activity," Tony said, explaining the timeline the district received from the vendor and the steps taken. The district published an HR web page with frequently asked questions and a vendor contact number; employees were offered guidance about signing up for extra protections. Administrators said the breach affected data held by the third‑party retirement administrator and is separate from PERS files.
Board members thanked staff for quick notification and for preparing resources. District staff said they would continue to communicate updates and urged affected employees to use the posted resources and the vendor helpline for next steps.

