HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
TransUnion
bd_5ff096c83f24f861 · schema v1 · pii pii-v1
Full breach record for TransUnion →TransUnion LLC reported a data breach in California involving unauthorized access to consumer credit files. Between August 4, 2021, and January 31, 2022, unauthorized actors used personal information from non-TransUnion sources to impersonate consumers and access TransUnion products. Systems were not compromised, but consumer data (names, potentially SSNs) was accessed. TransUnion offered one year of complimentary credit monitoring and identity theft protection.
California clockDiscovered Jul 25, 2022 → Notified Aug 4, 202210d ✓ CA 60-day OK10 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_6778f937b838f930Montana State AGfiled 2022-08-04Verified
- bd_7d4333b71dc4758aMontana State AGfiled 2022-08-04Verified
- bd_8600c700afac9a54Maine State AGfiled 2022-08-04Verified
- bd_8eae63057a496eaaMontana State AGfiled 2022-08-04Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_1ca0244698b0451eMontana State AGfiled 2022-08-05(1d gap)Verified by operator
- bd_82a944d4ca5bf8b9Montana State AGfiled 2022-08-05(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555950
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2022
- Raw hash
- 431b66c72d0a8bfdb1d02bd88c060e95083b3fa3d494e0f0447104ca0a2252f5
Reporting entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Victim entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Incident
- Discovered
- Jul 25, 2022
- Materiality determined
- —
- Notification sent
- Aug 4, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 10d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 25, 2022→ Notified: Aug 4, 202210d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.