DisclosureLens
HackingFinancial ServicesTechnologyFinanceStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)LowContained

TransUnion

bd_217b0e65bf1e4897 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 27, 2025

To disclose

Affected

Not disclosed

Linked

9 filings

Confidence

68%
Full breach record for TransUnion13 incidents on file

TransUnion LLC reported a cybersecurity incident involving unauthorized access to a third-party application used for U.S. consumer support operations. The breach exposed limited personal information (PII) but explicitly excluded credit reports or core credit data. TransUnion engaged Cyberscout for investigation and remediation, offering 24 months of complimentary credit monitoring and fraud assistance to affected individuals. The incident was reported to the California Office of the Attorney General under SB 24 on July 28, 2025.

Leak gap clock Leak >30d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Jul 28, 2025

Begins

Aug 27, 2025

Filed

This filing is one of 9 about the same incident.View merged incident
A leak claim by shinyhunters about this victim predates this filing by 60 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 12d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗
Indiana State AGAug 26 · first
Wisconsin State AGAug 26 · first
Delaware State AGAug 26 · first
California State AG+1d · this page

Pattern: first filing Aug 26 (IN), last Sep 8 (NE) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.