Credit reporting giant TransUnion says an unauthorized party accessed a third-party application used for its U.S. consumer support operations, exposing personal information for roughly 4.5 million consumers. The company says no credit reports or “core credit information” were involved.
Timeline: The breach occurred on July 28 and was discovered July 30. The company began notifying authorities and consumers this week.
Zoom in: A filing with the Texas Attorney General lists names, dates of birth, and Social Security numbers among the data types affected.
- Sample consumer notices sent by TransUnion reiterate that no credit reports or core credit info were accessed and offer 24 months of free credit monitoring and proactive fraud assistance.
What they are saying: “We regret any concern caused by this incident,” the company wrote in notification letters, adding that it “continues to enhance” security controls. Affected individuals are being offered complimentary credit monitoring and fraud assistance.
Not the first time: In 2022, TransUnion’s South Africa unit said criminals accessed a server and stole data in a separate incident later reviewed by the country’s regulator.
- In September 2023, a threat actor “USDoD” posted a 3GB database purporting to be TransUnion data; contemporaneous coverage noted the claim and TransUnion said it did not come from its systems.
Big picture: Vendor-side breaches are stacking up
- UBS: Data exposed after an attack on procurement provider Chain IQ (June 2025).
- Allianz Life: Personal data for a majority of 1.4M U.S. customers stolen via a cloud-based CRM (July 2025)
- Qantas: Nearly 6M customers affected after a third-party contact-center platform was compromised (July 2025).
Researchers and defenders have tied recent vendor-platform intrusions to groups operating under the ShinyHunters and Scattered Spider umbrellas, often using social engineering against cloud and IT service providers.
What’s next: Regulator portals indicate details may be updated as investigations proceed. Watch for state AG postings and any follow-up technical indicators from the company or law enforcement.
Credit reporting giant TransUnion says an unauthorized party accessed a third-party application used for its U.S. consumer support operations, exposing personal information for roughly 4.5 million consumers. The company says no credit reports or “core credit information” were involved.
Timeline: The breach occurred on July 28 and was discovered July 30. The company began notifying authorities and consumers this week.
Zoom in: A filing with the Texas Attorney General lists names, dates of birth, and Social Security numbers among the data types affected.
- Sample consumer notices sent by TransUnion reiterate that no credit reports or core credit info were accessed and offer 24 months of free credit monitoring and proactive fraud assistance.
What they are saying: “We regret any concern caused by this incident,” the company wrote in notification letters, adding that it “continues to enhance” security controls. Affected individuals are being offered complimentary credit monitoring and fraud assistance.
Not the first time: In 2022, TransUnion’s South Africa unit said criminals accessed a server and stole data in a separate incident later reviewed by the country’s regulator.
- In September 2023, a threat actor “USDoD” posted a 3GB database purporting to be TransUnion data; contemporaneous coverage noted the claim and TransUnion said it did not come from its systems.
Big picture: Vendor-side breaches are stacking up
- UBS: Data exposed after an attack on procurement provider Chain IQ (June 2025).
- Allianz Life: Personal data for a majority of 1.4M U.S. customers stolen via a cloud-based CRM (July 2025)
- Qantas: Nearly 6M customers affected after a third-party contact-center platform was compromised (July 2025).
Researchers and defenders have tied recent vendor-platform intrusions to groups operating under the ShinyHunters and Scattered Spider umbrellas, often using social engineering against cloud and IT service providers.
What’s next: Regulator portals indicate details may be updated as investigations proceed. Watch for state AG postings and any follow-up technical indicators from the company or law enforcement.




