TransUnion
ent_019dd1b59674e88801fdf2003062023e
Disclosures
25+
State AG · Leak Site · 16 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
4,461,511
nationwide · State AG TX
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- TransUnion
- Normalized
- transunion— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300ZS772LUNUMRB03
- SEC EDGAR CIK
- 0001552033
- Domain
- transunion.com
Disclosure history (newest 25)newest first
- Maine State AGas victim2025-10-04
Maine AG data breach notice filed listing TransUnion as the entity. The form reports 51 persons affected total (19 Maine residents) from an 'Internal system breach.' Form fields are internally inconsistent: breach date listed as Sept 19 2022, discovery date as 08-20-2009, and consumer notification date as July 13 2009 — these dates pre-date the breach date and suggest data-entry errors in the submission. The submitter is identified as a 'Consumer' (Trustee), not a TransUnion representative, further reducing reliability. No data categories acquired were specified; no identity-theft-protection services offered.
- Nebraska State AGas victim2025-09-08
TransUnion LLC notified Nebraska residents of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support. The incident did not involve credit reports or core credit information. TransUnion provided 24 months of complimentary credit monitoring and fraud assistance via Cyberscout. No specific count of affected individuals was disclosed in this notification letter.
- New Hampshire State AGas victim2025-09-04
TransUnion LLC notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its Salesforce application. A threat actor used social engineering (posing as a help desk technician) to trick call center agents into downloading a malicious application, gaining limited access on July 28-29, 2025. Consumer Social Security Numbers were exfiltrated. Approximately 16,508 New Hampshire residents were affected. TransUnion contained the breach, notified the FBI, and is offering 24 months of complimentary credit monitoring to affected individuals.
- Texas State AGas victim2025-09-04
TransUnion LLC based in Chicago, Illinois, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-07-29 and reported on 2025-09-04. 377,357 Texas residents were affected. 4,461,511 individuals affected in total. Types of information involved: Social Security Number Information. Consumers were notified via U.S. Mail.
- South Carolina State AGas victim2025-09-04
TransUnion LLC notified South Carolina consumers of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. No credit reports or core credit information were accessed. TransUnion is offering 24 months of credit monitoring and fraud assistance.
- Massachusetts State AGas victim2025-09-04
TransUnion LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-09-04. 95,336 Massachusetts residents were affected.
- Montana State AGas victim2025-09-03
TransUnion LLC notified Montana and Rhode Island residents of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident involved limited personal information (PII) but explicitly excluded credit reports. Approximately 17,155 Rhode Island residents were identified as impacted. TransUnion is offering 24 months of complimentary credit monitoring and fraud assistance via Cyberscout.
- Oregon State AGas victim2025-09-02
TransUnion LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-09-02. 4,461,511 individuals were affected.
- Iowa State AGas victim2025-09-02
TransUnion LLC reported a cyber incident in Iowa where a threat actor used social engineering to pose as a help desk technician, tricking call center agents into downloading a malicious application. This allowed the actor to access a third-party application serving U.S. consumer support operations on July 28-29, 2025. The incident resulted in the exfiltration of consumer Social Security Numbers affecting approximately 25,943 Iowa residents. TransUnion contained the breach, notified the FBI, and provided 24 months of credit monitoring to affected individuals.
- Vermont State AGas victim2025-09-01
TransUnion notified Vermont consumers of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident involved limited PII but explicitly excluded credit reports. TransUnion is offering 24 months of credit monitoring and fraud assistance via Cyberscout. No specific count of affected individuals was provided in the notice.
- California State AGas victim2025-08-27
TransUnion LLC reported a cybersecurity incident involving unauthorized access to a third-party application used for U.S. consumer support operations. The breach exposed limited personal information (PII) but explicitly excluded credit reports or core credit data. TransUnion engaged Cyberscout for investigation and remediation, offering 24 months of complimentary credit monitoring and fraud assistance to affected individuals. The incident was reported to the California Office of the Attorney General under SB 24 on July 28, 2025.
- Maine State AGas victim2025-08-27
TransUnion LLC reported a cybersecurity incident involving unauthorized access to a third-party application used for U.S. consumer support operations. The breach occurred on July 28, 2025, and was discovered on July 30, 2025. Approximately 4.46 million individuals were affected, including 16,828 Maine residents. The incident involved limited personal information (names, addresses, etc.) but explicitly excluded credit reports and core credit information. TransUnion provided 24 months of complimentary credit monitoring and fraud assistance.
- Indiana State AGas victim2025-08-26
TransUnion LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-28 and was reported on 2025-08-26. 88,898 Indiana residents were affected. 4,461,511 individuals affected in total.
- Wisconsin State AGas victim2025-08-26
TransUnion LLC reported a data breach to the Wisconsin DATCP. The public was notified on 2025-08-26. The incident occurred on July 28, 2025. Data accessed: Social Security numbers and dates of birth. 4,461,511 individuals were affected. 69,256 Wisconsin residents were affected.
- Delaware State AGas victim2025-08-26
TransUnion, LLC disclosed a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident did not involve credit reports or core credit information. TransUnion provided 24 months of complimentary credit monitoring and fraud assistance via Cyberscout. The notification was filed with the Delaware Attorney General.
- GLOBALLeak Siteas victim2025-06-28
TransUnion is a global credit reporting agency that provides credit information and analytics services to businesses and individual consumers. It collects and aggregates information on over a billion individual consumers in over thirty countries including "Big Three" credit-reporting agencies in the United States. The data they handle includes credit history, credit scoring, and personal information protection services.
- Illinois State AGas victim2024-10-01
TRANSUNION filed a data-breach notice with the Illinois Attorney General in October 2024 (case 24-10-008). The register records the breach as discovered on June 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2023-09-01
TransUnion LLC notified the NH Attorney General of three additional impacted individuals in New Hampshire. Unauthorized actors used personal information obtained from non-TransUnion sources to impersonate consumers and attempt to access TransUnion products. TransUnion's systems were not compromised. The suspicious activity was identified between June 13 and June 20, 2023. Affected individuals were offered complimentary identity theft protection and credit monitoring.
- GLOBALLeak Siteas victim2023-08-23
- Vermont State AGas victim2023-03-10
TransUnion LLC notified consumers in Vermont of a cybersecurity incident where unauthorized actors exploited a bypass in individual verification measures for direct-to-consumer products. Actors impersonated consumers using personal information from non-TransUnion sources to access the consumer portal. The incident affected individuals between December 1, 2022, and January 13, 2023. TransUnion stopped the bypass, conducted an investigation, and offered one year of complimentary credit monitoring.
- Maine State AGas victim2023-03-10
TransUnion LLC reported a data breach affecting 67 individuals, including 1 Maine resident, occurring between December 1, 2022, and January 13, 2023. The breach involved the acquisition of Social Security Numbers. Notification was sent on March 10, 2023, offering one year of credit monitoring.
- Indiana State AGas victim2023-03-10
TransUnion LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-01 and was reported on 2023-03-10. 2 Indiana residents were affected. 67 individuals affected in total.
- Massachusetts State AGas victim2023-03-10
TransUnion LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-10. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2022-11-07
TransUnion LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2022-02-16 and was reported on 2022-11-07. 3 Indiana residents were affected. 224 individuals affected in total.
- Maine State AGas victim2022-11-07
TransUnion LLC reported an "impersonation event" that occurred between January 16, 2022, and July 15, 2022. The breach, discovered on October 26, 2022, affected 3 Maine residents. The compromised information included names and Social Security numbers. The company offered one year of credit monitoring to those affected.
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of TransUnion — not by TransUnion itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Washington State AGvia TRANS UNION LLC2025-08-27
TransUnion LLC reported unauthorized access to a third-party application used for U.S. consumer support operations. The incident occurred July 28-29, 2025, and was discovered on July 30, 2025. Approximately 88,689 Washington residents were affected. No credit reports or core credit information were accessed. TransUnion provided 24 months of credit monitoring and fraud assistance.
- New Hampshire State AGvia TransUnion Risk and Alternative Data Solutions2024-10-03
TransUnion Risk and Alternative Data Solutions (TRADS) notified New Hampshire residents that individuals misrepresented themselves to gain unauthorized access to consumer data between June 1, 2023, and August 7, 2024. The incident involved 570 NH residents' personal information. TRADS terminated access, contacted authorities, and offered credit monitoring services.
- Montana State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions (TRADS) notified Montana residents of unauthorized access to personal data. Suspicious activity was identified on July 24, 2024, leading to an investigation concluding September 10, 2024. Individuals misrepresented themselves to access consumer accounts. Affected data includes names and other personal information. TRADS provided free credit monitoring services.
- Vermont State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions (TRADS) notified Vermont consumers of unauthorized access to personal data. Suspicious activity began July 24, 2024; investigation concluded Sept 10, 2024. Attackers misrepresented themselves to access consumer accounts. Data involved: name and impacted data elements. TRADS offered free credit monitoring.
- Indiana State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-01 and was reported on 2024-10-02. 1,182 Indiana residents were affected. 86,569 individuals affected in total.
- Illinois State AGvia TRANS UNION LLC2022-01-01
TRANSUNION CORPORATION filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-326). The register records the breach as discovered on April 14, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGvia TRANS UNION LLC2012-03-14
Trans Union LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-03-14. 8 Massachusetts residents were affected. The report records the breach type as electronic.