Breach report
Credit BureauTransUnion
TransUnion suffers data breach impacting over 4.4 million people
Attackers tied to a sweeping Salesforce data-theft campaign accessed a TransUnion consumer support platform, taking names, birth dates and unredacted Social Security numbers for more than 4.4 million Americans.
Reported by BleepingComputer
Records exposed
4.4M
More than 4.4 million people
Scale vs. largest on file
- When
- 2025
- How they got in
- Compromise of third-party Salesforce application used for consumer support
- Sector
- Credit Bureau
In late August 2025, credit bureau TransUnion began notifying more than 4.4 million people in the United States that their personal information had been exposed. According to filings with state regulators, the unauthorized access took place on July 28, 2025, and was discovered two days later. The company said the intrusion involved a third-party application used by its U.S. consumer support operations, not its core credit database.
The breach was part of a broader wave of attacks during 2025 against companies using Salesforce, the customer relationship management platform. In that campaign, attackers typically posed as IT staff in phone calls to employees, persuading them to authorize malicious connected apps or hand over credentials that allowed bulk export of customer records. Security researchers and the attackers themselves linked the TransUnion theft to the extortion group known as ShinyHunters, which claimed to have stolen far more records than the company confirmed.
TransUnion said the affected data was limited to specific elements, but those elements were sensitive: names, billing addresses, phone numbers, email addresses and dates of birth, along with unredacted Social Security numbers for many individuals. Some records also contained the reason a person contacted the company, such as a request for a credit report, and the text of support tickets. TransUnion stressed that no credit reports or core credit information were exposed.
The company offered 24 months of free credit monitoring and identity theft protection to those affected. The incident drew class-action lawsuits and renewed criticism of the credit reporting industry, which had already weathered the 2017 Equifax breach and faced persistent questions about how it safeguards information consumers never chose to provide. It was also a reminder that the data bureaus collect for support and dispute handling can be nearly as sensitive as credit files themselves.
The TransUnion case illustrates how the attack surface of large firms now extends deep into software-as-a-service platforms. The breach did not require exploiting a software flaw in TransUnion's own systems, only access to a cloud tool connected to them. It underscored the need for strict controls on third-party app authorizations, phishing-resistant login methods and staff training focused on voice-based impersonation.