HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
TransUnion
bd_82d4818cdee39c86 · schema v1 · pii pii-v1
Full breach record for TransUnion →TransUnion notified Vermont consumers of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident involved limited PII but explicitly excluded credit reports. TransUnion is offering 24 months of credit monitoring and fraud assistance via Cyberscout. No specific count of affected individuals was provided in the notice.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 3 about the same incident.View merged incident
A leak claim by shinyhunters about this victim predates this filing by 65 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fd85f6604075cd91Iowa State AGfiled 2025-09-02(1d gap)Candidate
- bd_b4d8a6f47a0b6abcDelaware State AGfiled 2025-08-26(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-01-transunion-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2025
- Raw hash
- 5fdae356c0b9d30e370486168747929324b542ca817e2f3cd0a6287ea2223078
Reporting entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Victim entity
- Name
- TransUnionnorm: transunion
- Domain
- transunion.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Filed breach notice with the Office of the Vermont Attorney General
- Third party
- via Cyberscout
- Initial access
- supply_chain
Compliance
- Compliance flags
- Leak >30d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.