Social EngineeringPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
TransUnion
bd_2bc0e049aa0901d3 · schema v1 · pii pii-v1
Full breach record for TransUnion →TransUnion LLC filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access attempts to consumer credit files. Between June 13-20, 2023, actors used personal information from non-TransUnion sources to impersonate consumers. Three New Hampshire residents were identified as impacted. TransUnion's systems were not compromised. The company is offering credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/transunion-20230901.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2023
- Raw hash
- 083f112b6ba31b660cc580d9326ea914522ce89586d9c1c86c04cdabd69217af
Reporting entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Victim entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- Aug 18, 2023
- Notification sent
- Aug 28, 2023
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.