HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
TransUnion
bd_217b0e65bf1e4897 · schema v1 · pii pii-v1
Full breach record for TransUnion →TransUnion LLC reported a cybersecurity incident involving unauthorized access to a third-party application used for U.S. consumer support operations. The breach exposed limited personal information (PII) but explicitly excluded credit reports or core credit data. TransUnion engaged Cyberscout for investigation and remediation, offering 24 months of complimentary credit monitoring and fraud assistance to affected individuals. The incident was reported to the California Office of the Attorney General under SB 24 on July 28, 2025.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by shinyhunters about this victim predates this filing by 60 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_12f1bc01ded96f42Leak Siteshinyhuntersfiled 2025-06-28(60d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_9d7ad1a3ef9bd9aeMaine State AGfiled 2025-08-27Verified
- bd_085cfd4342522886Indiana State AGfiled 2025-08-26(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607772
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2025
- Raw hash
- d3e5c41c3a516d7f45380e72971b6a3a19fc8fb560777f6298a183c807608eb8
Reporting entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Victim entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General (SB 24)
- Third party
- via Cyberscout
- Initial access
- supply_chain
Compliance
- Compliance flags
- Leak >30d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.