TransUnion reported a breach in July 2025 affecting the data of more than 4.4 million people, following unauthorised access to a Salesforce database.
A Credit Bureau Is The Purest Case Of Absent Consent
The corpus has filed several: crash-report subjects at 25-0612, declined loan applicants at 25-1105, employees at 25-0704, children at 25-0927.
A credit bureau exceeds all of them. Nobody applies to be in a credit file. The data is compiled from lenders and public records about a person who has no relationship with the bureau, cannot decline inclusion, cannot leave, and in most cases cannot correct it without a formal dispute process.
The bureau’s customers are lenders. The people in the database are its product.
And The Standard Remedy Is Supplied By This Industry
This desk has noted repeatedly — at 25-0530 and 25-1031 — that the near-universal remedy after a breach is credit monitoring, frequently provided by a company in the credit-data business.
When the breached organisation is itself a credit bureau, that arrangement becomes difficult to describe without irony. The corpus states it flatly: the remedy offered for a breach at a credit bureau is a subscription to credit-bureau data.
The Route Was A Sales System, Not The Bureau
Reporting places the access in a Salesforce database rather than in core bureau infrastructure. That is consistent with the campaign at 25-0923, and it is a distinction worth preserving: the bureau’s central files are not what was reached.
It also demonstrates the point at 25-1006 — a CRM at an organisation of this kind holds a substantial population regardless of what the "real" database contains, because the sales and support estate accumulates the same people.
Compiled from public reporting, listed below. The affected figure is as reported. We do not assert that core bureau systems were reached. Corrections: corrections@forensicpost.com.