TransUnion Data Breach 2025: 4.4 Million Consumers, Stolen SSNs, and the Salesforce App TransUnion Didn't Control

7 minute read
July 28, 2025 (disclosed August 2025)
Share Article
BREACH INTELLIGENCE
breach date

July 28, 2025 (disclosed August 2025)

Industry

Credit Reporting / Financial Data

Severity

High

Records Exposed

4.4M

Financial Impact

13M claimed

Breach Summary

On July 28, 2025, one of the three major US credit bureaus had the data of 4.4 million Americans stolen, and the breach did not touch a single TransUnion server that TransUnion fully controlled. The attackers came in through a third-party application connected to TransUnion's Salesforce environment, the Salesloft Drift integration, using stolen OAuth tokens and social engineering rather than any exploit of TransUnion or Salesforce themselves. The exposed data included names, dates of birth, billing addresses, phone numbers, and unredacted Social Security numbers. TransUnion described the exposure as limited personal information for a very small percentage of US consumers. Four and a half million people with their Social Security numbers in a criminal's hands is a strange definition of limited.

What Happened

According to TransUnion's filing with the Maine Attorney General, the incident occurred on July 28, 2025 and affected 4,461,511 US consumers. The company said it identified and contained the event within hours and formally set a discovery date of July 30. The attackers, an affiliate cluster tied to ShinyHunters and tracked by some researchers as UNC6395, claimed roughly 13 million records in total.

The access path was not TransUnion's core systems. It was a third-party application, Salesloft Drift, integrated with TransUnion's Salesforce environment for customer-support operations. The attackers obtained valid OAuth tokens for that integration and used them to pull data from the connected Salesforce instance. TransUnion has stressed that its core credit database and credit reports were not compromised, and Salesforce has stated its own platform was not breached. Both can be true while 4.4 million consumers still lose their Social Security numbers, because the weakness lived in the connection between trusted systems, not inside any one of them.

The exposed data included names, dates of birth, Social Security numbers, billing addresses, email addresses, phone numbers, and customer-support records. TransUnion offered affected consumers 24 months of credit monitoring and identity-theft protection.

Attack Vector Detail

The TransUnion breach is one node in the largest third-party campaign of 2025: a coordinated assault on the Salesloft Drift integration that touched roughly 760 companies connected to Salesforce. The mechanics are the now-familiar logged-in pattern. Attackers compromised OAuth tokens for the Drift application, then used those tokens to authenticate to each victim's connected Salesforce instance and exfiltrate data. No password was cracked. No firewall was defeated. The application was trusted, so the access looked legitimate.

This is the same class of attack behind the wider ShinyHunters wave, including the Snowflake customer campaign a year earlier. It is also the precise mechanism described in our explainer on credential harvesting: steal the token, skip the login alert, and walk out with the data. When negotiations with Salesforce failed, the attackers stood up a leak site naming dozens of the breached companies, turning a quiet token theft into a public extortion campaign.

Breach Pattern Timeline

  • July 28, 2025 — Attackers access TransUnion data via the Salesloft Drift Salesforce integration; contained within hours.
  • July 30, 2025 — Formal discovery date set.
  • August 2025 — TransUnion files with the Maine AG; 4,461,511 US consumers affected.
  • October 2025 — Attackers demand ransom from Salesforce, which refuses; a leak site names dozens of the ~760 affected companies.
  • Pattern — Part of the broader ShinyHunters / Salesloft Drift campaign, alongside Allianz, Farmers Insurance, and others.

Executive Lessons

  1. Inventory every OAuth grant and integration. The breach entered through an app most of TransUnion's customers had never heard of. Every connected application that can read production data is part of the attack surface and needs the same scrutiny as a core system. This is the work of third-party risk management.
  2. Tokens are credentials. An OAuth token is a key to your data. It needs the same lifecycle controls as a password: scoping, expiry, rotation, and monitoring for anomalous use.
  3. 'Limited' is a word regulators remember. Calling 4.4 million exposed records, including SSNs, limited may be technically defensible as a share of the customer base, but it ages badly once the notification letters and class actions arrive.
  4. The pattern is the warning. TransUnion was not singled out; it was one of hundreds of companies hit through the same integration. This breach is part of the campaign documented in our analysis of the 2026 extortion wave.

Private Equity Implications

For sponsors, the lesson is that a portfolio company's security posture is only as strong as the third-party integrations no one is auditing. A SaaS-dependent business can have a hardened core and still lose its most sensitive data through a marketing or support app connected to its CRM. Quality-of-earnings work catches revenue concentration; it rarely catches integration concentration.

Diligence should enumerate every OAuth connection and SaaS integration touching customer data at the target, and treat them as part of the data-protection review rather than an IT detail. The question to ask is direct: which third-party apps can read our customer data, who controls them, and what happens when one of their tokens is stolen? See cyber due diligence.

How Cloudskope Can Help

Cloudskope maps the integration and OAuth attack surface that breaches like this exploit: which third-party apps connect to your CRM and data platforms, what data they can reach, and whether their tokens are scoped, monitored, and revocable. For PE sponsors, we build this into diligence and hold-period monitoring so an inherited integration does not become an inherited breach.

Frequently Asked Questions

Frequently asked questions

Was TransUnion's credit database hacked?
No. TransUnion states its core credit database and credit reports were not compromised. The breach occurred through a third-party Salesforce-connected application (Salesloft Drift), not its core systems.

How many people were affected?
4,461,511 US consumers per TransUnion's Maine AG filing. The attackers claimed roughly 13 million records in total across their broader campaign.

What data was exposed?
Names, dates of birth, Social Security numbers, billing addresses, email addresses, phone numbers, and customer-support information.

Who was responsible?
An extortion cluster tied to ShinyHunters (tracked by some researchers as UNC6395), as part of a wave of attacks against the Salesloft Drift Salesforce integration.

What should affected consumers do?
Enroll in the offered credit monitoring, consider a credit freeze given the exposed SSNs, and stay alert to phishing referencing credit or identity services.