Data Breaches

TransUnion Data Breach Impacts 4.4 Million

The credit reporting firm did not name the third-party application involved in the incident, only noting that it was used for its US consumer support operations.

Credit reporting firm TransUnion (NYSE: TRU) is notifying more than 4.4 million people that their personal information was compromised in a data breach.

The incident occurred on July 28, 2025, the company said in data breach notifications sent to the impacted individuals, copies of which were submitted to the Maine and Texas Attorney General’s Offices.

According to TransUnion, the data breach involved personal information stored in a third-party application, including names, Social Security numbers, and dates of birth.

“TransUnion recently experienced a cyber incident that affected a third-party application serving our US consumer support operations. Upon discovery, we quickly contained the issue, which did not involve our core credit database or include credit reports,” the company told SecurityWeek.

“We identified and contained this event within hours,” a TransUnion spokesperson said.

TransUnion told the Maine AGO that 4,461,511 individuals were impacted by the data breach, and that it is providing them with 24 months of free credit monitoring services, and with proactive fraud assistance.

Advertisement. Scroll to continue reading.

The credit reporting firm did not name the third-party application involved in the incident, but said it has been working with law enforcement and third-party cyber security experts to investigate the attack.

However, it appears that the data breach was related to a broader wave of data theft attacks impacting Salesforce customers, and that the infamous extortion group known as ShinyHunters was responsible for it, BleepingComputer reports.

In addition to the personal information that TransUnion has reported as compromised, addresses, email addresses, and phone numbers were also stolen, the hackers claim.

In early August, Google disclosed a data breach involving its Salesforce instance, after warning in June that UNC6040, a threat actor specializing in voice phishing attacks, was running a large-scale Salesforce data theft and extortion campaign.

Google linked UNC6040 to Scattered Spider, which apparently merged with ShinyHunters. Recently disclosed data breaches impacting Adidas, Allianz Life, Cisco, Dior, Louis Vuitton, and other companies appear to be part of the Salesforce hacking campaign.

*Updated with statement from TransUnion.

Related: Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign

Related: Nevada State Offices Closed Following Disruptive Cyberattack

Related: Police in Brazil Arrest a Suspect Over $100M Banking Hack

Related:Year of the Twin Dragons: Developers Must Slay the Complexity and Security Issues of AI Coding Tools

Related Content

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Data Breaches

The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version