Skip to main content
Breach Signal

Breach report

Credit Bureau

TransUnion

TransUnion suffers data breach impacting over 4.4 million people

Attackers tied to a sweeping Salesforce data-theft campaign accessed a TransUnion consumer support platform, taking names, birth dates and unredacted Social Security numbers for more than 4.4 million Americans.

Reported by BleepingComputer

Records exposed

4.4M

More than 4.4 million people

Scale vs. largest on file

When
2025
How they got in
Compromise of third-party Salesforce application used for consumer support
Sector
Credit Bureau

In late August 2025, credit bureau TransUnion began notifying more than 4.4 million people in the United States that their personal information had been exposed. According to filings with state regulators, the unauthorized access took place on July 28, 2025, and was discovered two days later. The company said the intrusion involved a third-party application used by its U.S. consumer support operations, not its core credit database.

The breach was part of a broader wave of attacks during 2025 against companies using Salesforce, the customer relationship management platform. In that campaign, attackers typically posed as IT staff in phone calls to employees, persuading them to authorize malicious connected apps or hand over credentials that allowed bulk export of customer records. Security researchers and the attackers themselves linked the TransUnion theft to the extortion group known as ShinyHunters, which claimed to have stolen far more records than the company confirmed.

TransUnion said the affected data was limited to specific elements, but those elements were sensitive: names, billing addresses, phone numbers, email addresses and dates of birth, along with unredacted Social Security numbers for many individuals. Some records also contained the reason a person contacted the company, such as a request for a credit report, and the text of support tickets. TransUnion stressed that no credit reports or core credit information were exposed.

The company offered 24 months of free credit monitoring and identity theft protection to those affected. The incident drew class-action lawsuits and renewed criticism of the credit reporting industry, which had already weathered the 2017 Equifax breach and faced persistent questions about how it safeguards information consumers never chose to provide. It was also a reminder that the data bureaus collect for support and dispute handling can be nearly as sensitive as credit files themselves.

The TransUnion case illustrates how the attack surface of large firms now extends deep into software-as-a-service platforms. The breach did not require exploiting a software flaw in TransUnion's own systems, only access to a cloud tool connected to them. It underscored the need for strict controls on third-party app authorizations, phishing-resistant login methods and staff training focused on voice-based impersonation.

More from the wire

More in Credit Bureau.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.