TransUnion data breach (2025): what was exposed and what to do

Updated Corrections

September 28, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

TransUnion data breach (2025): what was exposed and what to do

By Delist Editorial Team · Updated September 28, 2026 · Corrections

September 28, 2026

What happened

TransUnion, one of the three major U.S. consumer credit bureaus, notified regulators and consumers of a cybersecurity incident involving a third-party application used for U.S. consumer support operations—widely reported as a Salesforce-linked support / CRM environment, not TransUnion’s core credit database.

Per TransUnion’s September 2, 2025 letter to Iowa’s Attorney General (primary PDF), the company confirmed on July 30, 2025, that a threat actor had exfiltrated certain consumer Social Security numbers after social engineering: the actor posed as a help-desk technician and instructed two call-center agents (one a vendor-firm employee) to open a URL that installed a malicious connected application, allowing limited access to the third-party support environment. That access occurred on July 28 and 29, 2025. TransUnion stated the issue “did not affect our core credit database or include credit reports,” informed the FBI, and shut down the agents’ access.

Consumer notices and AG-linked disclosures rolled out around late August 2025 (Iowa residents notified August 26, 2025, per the Iowa AG letter). Press coverage of the Maine Attorney General filing (SecurityWeek, DataBreaches.net, BleepingComputer, The Register) cites 4,461,511 people affected. That is a regulatory filing count as reported publicly—not a Delist estimate. Maine’s public AG breach-viewer database has since been taken offline for abuse review; cite the filing figure via contemporaneous press that reviewed the notice materials, plus the Iowa AG PDF for intrusion mechanics. Iowa’s letter assessed about 25,943 Iowa residents.

Press later linked the event to the 2025 wave of Salesforce social-engineering / OAuth attacks (ShinyHunters / UNC6040 / related clusters). Actor claims of larger global record totals (for example, “over 13 million” in some threat-actor statements to press) are not the same as the Maine AG U.S. consumer figure—keep them separate.

Sources

What data was exposed

Company consumer notices and AG-linked summaries described personal information stored in the third-party support application. SecurityWeek reported company notice language naming names, Social Security numbers, and dates of birth. The Iowa AG letter emphasizes exfiltration of certain consumer SSNs. BleepingComputer and other outlets reported reviewing a sample of stolen support-CRM data that also included:

  • Billing addresses
  • Phone numbers
  • Email addresses
  • Customer-support ticket / message context (as claimed by threat actors and described in press)

Company statements emphasized that credit reports / core credit information were not included. Exact fields vary by person. Rely on the notice you were mailed. Treat press sample inventories as reporting, and the company’s “not core credit DB” statement as the official scope boundary.

Breach details

Detail Value
Breach name TransUnion (U.S. consumer support third-party / Salesforce-linked CRM)
Date Access July 28–29, 2025 (Iowa AG letter); discovered / contained ~July 30, 2025
Disclosed Consumer notices / AG filings ~late August 2025 (Iowa mail Aug 26; press coverage Aug 28–29, 2025); Iowa AG letter Sep 2, 2025
Accounts affected 4,461,511 (Maine AG filing, as reported in press). Iowa AG: ~25,943 Iowa residents. Actor “13M+” claims are separate and unverified as a company census.
Domain transunion.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by TransUnion; it reflects a publicly reported security incident.

For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.

What to do now

Because notices and press inventories name SSNs and dates of birth alongside contact data:

  • Place a free credit freeze at Equifax, Experian, and TransUnion (yes—including TransUnion itself as a bureau). See how to freeze your credit.
  • Enroll in any monitoring TransUnion offered in your letter (Iowa sample letter: 24 months of myTrueIdentity / Cyberscout services) only through channels printed on that letter—not cold emails. Follow the enrollment deadline and code on your notice; offers can vary by mailing wave.
  • Review credit reports and financial statements for unfamiliar accounts; use AnnualCreditReport.com and IdentityTheft.gov if you see misuse.
  • Treat calls that claim to be “TransUnion breach support” and ask for passwords, one-time codes, or payment as scams unless you initiated contact using a number from your official notice (Iowa sample listed 1-800-516-4700).
  • Keep the letter—it documents which fields applied to you.

Short checklist: first 48 hours after a data breach. If the letter is confusing: a company emailed me about a breach.

How this shows up on the open web

Names, phones, emails, and addresses are the same fields people-search sites already publish. When those sit next to a credit-bureau support incident in the news, phishing that pretends to be “credit freeze help” can sound more plausible. Run a free open-web scan to see what is already findable about you. Delist does not claim to have scanned TransUnion’s Salesforce/support systems or this incident’s files, and it does not remove dump copies.

Related reading: 700Credit (2025) and how to freeze your credit.

TransUnion said my SSN was in a support-app breach—what first?

Freeze credit at Equifax, Experian, and TransUnion. Enroll in monitoring only via the channels on your letter. This was a support CRM incident—not the core credit database.

Frequently asked questions

Was TransUnion’s core credit database breached?

No. TransUnion’s Iowa AG letter and public statements say the incident involved a third-party application serving U.S. consumer support operations and did not affect the core credit database or include credit reports. Press linked the event to a Salesforce support CRM compromise.

How many people were affected?

Press coverage of the Maine Attorney General filing cites 4,461,511 people (SecurityWeek, DataBreaches.net, and others). That is the regulatory filing figure as reported publicly—not a Delist count. Iowa’s Sep 2, 2025 AG letter assessed about 25,943 Iowa residents. Separate actor claims of larger record totals are not a substitute for the Maine figure.

When did the unauthorized access happen?

TransUnion’s Iowa AG letter says access occurred on July 28 and 29, 2025, and that exfiltration of certain consumer SSNs was confirmed on July 30, 2025, after social engineering of call-center agents.

Can Delist remove my record from the TransUnion support files?

No. Delist does not scrub bureau systems or breach dumps. A free scan looks at open-web people-search and broker listings only.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.