TransUnion
ent_019dd1b59674e88801fdf2003062023e
Disclosures
25+
SEC 10-K Item 1C · State AG · Leak Site · 13 jurisdictions
Incidents
6
filings grouped by incident
Max affected reported
4,461,511
as filed · State AG OR
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- TransUnion
- Normalized
- transunion— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300ZS772LUNUMRB03
- SEC EDGAR CIK
- 0001552033
- Domain
- transunion.com
Disclosure history (newest 25)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-27
TransUnion (TRU) filed Item 1C of Form 10-K disclosing its cybersecurity risk management program, governance structure, and incident response capabilities. The filing explicitly states that no known cybersecurity threats have materially affected the company's operations, business strategy, or financial condition. It details the Security and Technology Risk Committee (STRC) and Enterprise Risk Management Committee (ERMC) oversight, the role of the CISO, and the integration of cybersecurity with enterprise risk management. No specific breach or incident is reported.
- 🦞Maine State AGas victim2025-10-04
Maine AG data breach notice filed listing TransUnion as the entity. The form reports 51 persons affected total (19 Maine residents) from an 'Internal system breach.' Form fields are internally inconsistent: breach date listed as Sept 19 2022, discovery date as 08-20-2009, and consumer notification date as July 13 2009 — these dates pre-date the breach date and suggest data-entry errors in the submission. The submitter is identified as a 'Consumer' (Trustee), not a TransUnion representative, further reducing reliability. No data categories acquired were specified; no identity-theft-protection services offered.
- ⛰️New Hampshire State AGas victim2025-09-04
TransUnion LLC notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its Salesforce application. A threat actor used social engineering (posing as a help desk technician) to trick call center agents into downloading a malicious application, gaining limited access on July 28-29, 2025. Consumer Social Security Numbers were exfiltrated. Approximately 16,508 New Hampshire residents were affected. TransUnion contained the breach, notified the FBI, and is offering 24 months of complimentary credit monitoring to affected individuals.
- ⭐Texas State AGas victim2025-09-04
TransUnion LLC based in Chicago, Illinois, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-07-29 and reported on 2025-09-04. 377,357 Texas residents were affected. 4,461,511 individuals affected in total. Types of information involved: Social Security Number Information. Consumers were notified via U.S. Mail.
- 🌴South Carolina State AGas victim2025-09-04
TransUnion LLC notified South Carolina consumers of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. No credit reports or core credit information were accessed. TransUnion is offering 24 months of credit monitoring and fraud assistance.
- 🦬Montana State AGas victim2025-09-03
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2025-09-03. The breach occurred from 07/28/2025 to 07/29/2025. 9,410 Montana residents were affected.
- 🦫Oregon State AGas victim2025-09-02
TransUnion LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-09-02. 4,461,511 individuals were affected.
- 🌽Iowa State AGas victim2025-09-02
TransUnion LLC, a financial services sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-09-02.
- 🍁Vermont State AGas victim2025-09-01
TransUnion notified Vermont consumers of a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident involved limited PII but explicitly excluded credit reports. TransUnion is offering 24 months of credit monitoring and fraud assistance via Cyberscout. No specific count of affected individuals was provided in the notice.
- 🐻California State AGas victim2025-08-27
TransUnion LLC reported a cybersecurity incident involving unauthorized access to a third-party application used for U.S. consumer support operations. The breach exposed limited personal information (PII) but explicitly excluded credit reports or core credit data. TransUnion engaged Cyberscout for investigation and remediation, offering 24 months of complimentary credit monitoring and fraud assistance to affected individuals. The incident was reported to the California Office of the Attorney General under SB 24 on July 28, 2025.
- 🦞Maine State AGas victim2025-08-27
TransUnion LLC reported a cyber incident occurring on July 28, 2025, discovered July 30, 2025, involving unauthorized access to personal data stored on a third-party application supporting U.S. consumer operations. No credit reports or core credit information was accessed. Approximately 4,461,511 individuals were affected nationally, including 16,828 Maine residents. Consumers were notified August 26, 2025 and offered 24-month credit monitoring via myTrueIdentity.
- 🏎️Indiana State AGas victim2025-08-26
TransUnion LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-28 and was reported on 2025-08-26. 88,898 Indiana residents were affected. 4,461,511 individuals affected in total.
- 💎Delaware State AGas victim2025-08-26
TransUnion, LLC disclosed a cyber incident involving unauthorized access to personal data stored on a third-party application used for U.S. consumer support operations. The incident did not involve credit reports or core credit information. TransUnion provided 24 months of complimentary credit monitoring and fraud assistance via Cyberscout. The notification was filed with the Delaware Attorney General.
- GLOBALLeak Siteas victim2025-06-28
TransUnion is a global credit reporting agency that provides credit information and analytics services to businesses and individual consumers. It collects and aggregates information on over a billion individual consumers in over thirty countries including "Big Three" credit-reporting agencies in the United States. The data they handle includes credit history, credit scoring, and personal information protection services.
- ⛰️New Hampshire State AGas victim2023-09-01
TransUnion LLC filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access attempts to consumer credit files. Between June 13-20, 2023, actors used personal information from non-TransUnion sources to impersonate consumers. Three New Hampshire residents were identified as impacted. TransUnion's systems were not compromised. The company is offering credit monitoring services.
- GLOBALLeak Siteas victim2023-08-23
- 🍁Vermont State AGas victim2023-03-10
TransUnion LLC notified consumers in Vermont of a cybersecurity incident where unauthorized actors exploited a bypass in individual verification measures for direct-to-consumer products. Actors impersonated consumers using personal information from non-TransUnion sources to access the consumer portal. The incident affected individuals between December 1, 2022, and January 13, 2023. TransUnion stopped the bypass, conducted an investigation, and offered one year of complimentary credit monitoring.
- 🦞Maine State AGas victim2023-03-10
TransUnion LLC reported a data breach affecting 67 individuals, including 1 Maine resident, occurring between December 1, 2022, and January 13, 2023. The breach involved the acquisition of Social Security Numbers. Notification was sent on March 10, 2023, offering one year of credit monitoring.
- 🦞Maine State AGas victim2022-11-07
TransUnion LLC reported an "impersonation event" that occurred between January 16, 2022, and July 15, 2022. The breach, discovered on October 26, 2022, affected 3 Maine residents. The compromised information included names and Social Security numbers. The company offered one year of credit monitoring to those affected.
- 🦬Montana State AGas victim2022-11-04
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-11-04. The breach occurred from 1/16/2022 to 7/15/2022. 2 Montana residents were affected.
- 🦬Montana State AGas victim2022-08-05
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-05. The breach occurred from 9/21/2021 to 3/28/2022. 3 Montana residents were affected.
- 🦬Montana State AGas victim2022-08-05
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-05. The breach occurred from 6/20/2021 to 12/16/2021. 5 Montana residents were affected.
- 🐻California State AGas victim2022-08-04
TransUnion LLC reported a data breach in California involving unauthorized access to consumer credit files. Between August 4, 2021, and January 31, 2022, unauthorized actors used personal information from non-TransUnion sources to impersonate consumers and access TransUnion products. Systems were not compromised, but consumer data (names, potentially SSNs) was accessed. TransUnion offered one year of complimentary credit monitoring and identity theft protection.
- 🦬Montana State AGas victim2022-08-04
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-04. The breach occurred from 5/7/2021 to 8/6/2021. 7 Montana residents were affected.
- 🦬Montana State AGas victim2022-08-04
TransUnion LLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-04. The breach occurred from 4/9/2021 to 10/6/2021. 3 Montana residents were affected.
Subsidiary disclosures (5)filed by group companies
◈ These filings were made by or about subsidiaries of TransUnion — not by TransUnion itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🌲Washington State AGvia TRANS UNION LLC2025-08-27
Trans Union LLC., a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2025-07-30 and filed notice on 2025-08-27. 88,689 Washington residents were affected. 28 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- ⛰️New Hampshire State AGvia TransUnion Risk and Alternative Data Solutions2024-10-03
TransUnion Risk and Alternative Data Solutions (TRADS) notified New Hampshire residents that individuals misrepresented themselves to gain unauthorized access to consumer data between June 1, 2023, and August 7, 2024. The incident involved 570 NH residents' personal information. TRADS terminated access, contacted authorities, and offered credit monitoring services.
- 🦬Montana State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-02. The breach occurred from 6/1/2023 to 8/7/2024. 191 Montana residents were affected.
- 🍁Vermont State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions (TRADS) notified Vermont consumers of unauthorized access to personal data. Suspicious activity began July 24, 2024; investigation concluded Sept 10, 2024. Attackers misrepresented themselves to access consumer accounts. Data involved: name and impacted data elements. TRADS offered free credit monitoring.
- 🏎️Indiana State AGvia TransUnion Risk and Alternative Data Solutions2024-10-02
TransUnion Risk and Alternative Data Solutions reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-01 and was reported on 2024-10-02. 1,182 Indiana residents were affected. 86,569 individuals affected in total.