Data leak

TransUnion Salesforce Platform Breach (44M+ Records)

πŸ“… 2025-07-01 🏒 Salesforce
Primary Source β†—

Incident Details

In August 2025, TransUnion confirmed it had been affected by the ShinyHunters/Scattered Spider Salesforce social engineering campaign, with limited personal information exposed for an estimated 44 million or more individuals. TransUnion, as one of the US’s three major credit bureaus, holds extensive consumer credit and financial records. The breach was part of a broader wave of ShinyHunters vishing attacks against enterprises using Salesforce, in which attackers impersonated IT support staff to obtain Salesforce administrator credentials. Other confirmed victims of the same campaign include Air France-KLM, Cisco, Pandora, Chanel, Stellantis, and Farmers Insurance.

Technical Details

Initial Attack Vector
ShinyHunters compromised TransUnion's Salesforce environment through social engineering / vishing of a Salesforce-privileged user, part of the broader 2025 Scattered Spider/ShinyHunters Salesforce campaign targeting major enterprises
Vendor / Product
Salesforce

Timeline

  1. 2025-07-01 Breach occurred
  2. 2025-08-20 Publicly disclosed
  3. 2025-08-20 Customers notified