Data leak β›“ Supply Chain

TransUnion Third-Party Salesforce App Breach - 4.4M Consumers

πŸ“… 2025-07-28 🏒 Salesforce; third-party support application
Primary Source β†—

Incident Details

TransUnion disclosed on August 28, 2025, that unauthorized actors accessed a third-party application serving its US consumer support operations between July 28–30, 2025. The attack is attributed to ShinyHunters/UNC6395 as part of their broader campaign targeting Salesforce environments via the SalesLoft Drift OAuth token compromise (see 2025-08_salesloft-drift-oauth-salesforce.yaml). Approximately 4.4 million US consumers had names, dates of birth, and Social Security numbers exposed. TransUnion’s core credit database and credit reports were not compromised. Notifications were sent August 26, 2025 with two years of complimentary credit monitoring via myTrueIdentity.

Technical Details

Initial Attack Vector
Attackers (attributed to ShinyHunters/UNC6395) gained access to a third-party Salesforce-based application used by TransUnion for US consumer support operations, likely via the SalesLoft Drift OAuth token supply chain attack
Vendor / Product
Salesforce; third-party support application
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-07-28 Breach occurred
  2. 2025-08-28 Publicly disclosed
  3. 2025-08-26 Customers notified