2025 TransUnion — Salesforce third-party app breach; 4.4M consumers’ SSNs and support data
Data compromised
Names, dates of birth, email, mailing addresses, phone numbers, unredacted SSNs, customer support ticket notes
Technical writeup
Attackers exploited vulnerabilities in a Salesforce-connected third-party application used in TransUnion's consumer support operations. Unauthorized access July 28, detected July 30; contained within hours. Core credit databases and credit reports were not accessed. ShinyHunters and UNC6395 probed OAuth tokens and app integrations.
Root cause
Third-party Salesforce-connected application vulnerability; OAuth token exploitation.