DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

TransUnion notifying more than 4.4 U.S. million consumers of data breach (1)

Posted on August 28, 2025August 28, 2025 by Dissent

When companies have big breaches, they have to notify the big credit reporting agencies. However, it is now one of the major credit reporting agencies that must send notifications.

TransUnion has notified the Maine Attorney General’s Office that  4,461,511 U.S. persons were affected by an incident on July 28, 2025 that involved an unnamed third-party application. TransUnion’s submission to Maine also revealed that the breach was discovered on July 30, 2025.

A copy of their notification letter to consumers, provided to Maine, is skimpy on details. Not only does it not tell those affected when the breach occurred, when it was discovered, or how it happened, but it also does not tell recipients what the third-party application was, and whether there was any ransom demand or threat.

The letter does inform recipients what specifc data elements of theirs were involved, while reassuing them that “The information was limited to specific data elements and did not include credit reports or core credit information.”

TransUnion’s letter or notification to Maine does not provide any sense of what consumers or subgroup of U.S. consumers were affected, but the letter indicates that the data was stored on a “third-party application serving our U.S. consumer support operations,” so the more than 4.4 million are U.S. consumers out of approximately 200 million U.S. consumers that TransUnion compiles data on.

TransUnion is offering those affected 24 months of credit monitoring and what they describe as proactive fraud assistance to help with any questions that those affected may have now or in the event that they become a victim of fraud.

DataBreaches emailed TransUnion to ask whether this incident was related to the Salesforce or  Salesforce / Salesloft Drift campaign and whether any extortion demand has been received.

Update: TransUnion declined to provide any additional details, but in a statement to DataBreaches, ShinyHunters stated:

All records from TransUnion Salesforce CRM instance was taken. Total 13M+ records, 4.4 million records are just U.S. SSNs were also compromised, in plaintext. We’ll begin to leak data on the forum known as BreachStars of companies who did not pay us or chose to ignore us.

When asked whether this attack involved Salesloft Drift or was the prior Salesforce campaign, ShinyHunters declined to comment.

ShinyHunters’ statement about the incident is consistent, however, with information given to DataBreaches on background by someone with knowledge of the incident, who informed DataBreaches that the 13M+ number was the number affected globally.

In related news, “Shiny” (the individual and seeming leader of ShinyHunters) confirmed to DataBreaches that the ShinyHunters user account on the new Breachsta[.]rs forum is, in fact, their account — unlike the “ShinyHunters” imposter account that had briefly appearaed on UmbraForums[.]net.

 


Related:

  • Madison Square Garden Company Alerts Customers of Payment Card Data Breach
  • McAlisters Deli, Moe’s Southwest Grill, Schlotzsky’s Notice of Data Breach to Consumers
  • TX: Statement and Frequently Asked Questions about the 2018 ERS OnLine Security Incident
  • LPL Financial reports theft of computers
  • Indiana Attorney General reaches settlement with WellPoint in consumer data breach
Category: Business SectorSubcontractorU.S.

Post navigation

← South Korea fines SK Telecom US$97M over data breach
We Get Privacy For Work — Episode 8: The Surge in Data Breach Lawsuits: Trends and Tactics →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life
  • Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.