TransUnion
bd_331561e568edbb3f · schema v1 · pii pii-v1
Full breach record for TransUnion →13 incidents on fileTransUnion LLC notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its Salesforce application. A threat actor used social engineering (posing as a help desk technician) to trick call center agents into downloading a malicious application, gaining limited access on July 28-29, 2025. Consumer Social Security Numbers were exfiltrated. Approximately 16,508 New Hampshire residents were affected. TransUnion contained the breach, notified the FBI, and is offering 24 months of complimentary credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 28, 2025
Begins
Jul 30, 2025
Discovered
Sep 4, 2025
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteshinyhuntersbd_12f1bc01ded96f422025-06-28 · +68dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Texas State AGbd_83b605646965217d2025-09-04Candidate
- South Carolina State AGbd_d7d141dc595dd1b02025-09-04Verified
- Massachusetts State AGbd_d87eb450bda408862025-09-04Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.