TransUnion holds credit information for millions of people, so a breach can raise serious questions about privacy and identity theft.
In July 2025, an attacker accessed personal details stored in a third-party application used for U.S. consumer support.
TransUnion said its main credit reporting systems were not affected. Still, more than 4.46 million people received notices.
This blog explains what happened, who qualified for protection, and what steps affected consumers should take. Check your letter and protect your credit today.
Is TransUnion Safe?
TransUnion is a real nationwide credit reporting company. Consumers can use its services to view credit reports, dispute errors, freeze files, and place fraud alerts.
The 2025 breach still gives people a reason to be careful with personal data. The incident began in a third-party support application rather than the main credit reporting system.
Use addresses typed directly into your browser, check the sender before opening a message, and avoid requests for payment tied to the breach.
Scammers often exploit breach news to launch follow-up attacks, so understanding common types of phishing can help you spot fake emails pretending to be from TransUnion.
Credit monitoring can help spot changes, while a credit freeze places a stronger barrier against many new-account fraud attempts made in your name.
What Happened in the TransUnion Data Breach?
The breach involved a third-party consumer support application and exposed personal data linked to millions of people. TransUnion said core credit reports were not accessed.
- Breach Date: An unauthorized party accessed a third-party consumer support application on July 28, 2025.
- Detection Date: TransUnion found the activity on July 30 and began mailing notices on August 26.
- Exposed Data: Some records included names, birth dates, and Social Security numbers. The data varied by person.
- Credit Data: TransUnion said credit reports and core credit information were not accessed.
- People Affected: The breach affected 4,461,511 people, including 16,828 Maine residents.
- Protection Offered: Eligible recipients received 24 months of MyTrueIdentity credit monitoring and identity theft support.
- Enrollment: Recipients needed the personal code from their notice and had 90 days to activate the service.
TransUnion Data Breach Timeline
The TransUnion breach took place in July 2025 and involved a third-party application used for U.S. consumer support.
| Date | What Happened |
|---|---|
| July 28, 2025 | An unauthorized party accessed the third-party consumer support application. |
| July 30, 2025 | TransUnion found the activity and began reviewing the breach. |
| August 26, 2025 | TransUnion started mailing notices to affected consumers. |
| Late 2025 | Many MyTrueIdentity enrollment periods ended after the 90-day signup limit. |
| After the breach | Consumers were advised to check credit reports, freeze credit files, and watch for scams. |
What Information was Exposed?
The exposed data varied from person to person, and each notice listed the details associated with that recipient,t and reported records included names, dates of birth, and Social Security numbers.
TransUnion said the affected third-party application did not contain credit reports or core credit information. That statement does not mean the breach carried no risk.
Personal details can still be used for identity theft, fake account applications, tax fraud, phishing, and other scams.
This is not the first time a consumer app has exposed sensitive user data; the Tea app data breach showed how quickly leaked personal information can spread once it is in the wrong hands.
Consumers should read their notices closely, monitor their credit reports, and act quickly if they find an unfamiliar account, inquiry, address, or collection entry on any of their files.
Has MyTrueIdentity Enrollment Deadline Passed?
The sample notice gave recipients 90 days from the date printed on the letter.
Since notices began going out in August 2025, the original enrollment window ended in late 2025 for many recipients.
The MyTrueIdentity activation page may still open, yet an old code may no longer work. Enter the code only on the official page named in the letter.
If it is rejected, call the dedicated number printed in the notice. TransUnion may explain the code status, but consumers should not assume that an expired offer will be reopened.
Credit freezes and fraud alerts remain free for all consumers.
What Should You Do After the TransUnion Breach?

Credit monitoring may alert you to changes on your credit file, but it cannot stop every type of identity fraud. Take these steps to lower your risk.
- Freeze Your Credit With All Three Bureaus: Place free freezes with Equifax, Experian, and TransUnion to restrict access to your credit reports. Lift them when applying for credit.
- Add a Fraud Alert: Contact one nationwide credit bureau to request extra identity checks from lenders. The bureau should notify the other two.
- Review All Three Credit Reports: Check for unfamiliar accounts, inquiries, collections, addresses, or contact details. Report suspicious entries to the lender and credit bureau.
- Watch for Social Security Number Misuse: Look for unexpected tax notices, employment records, benefits changes, loans, or collection calls. Contact the listed agency using verified details.
- Secure Your Online Accounts: Use unique passwords, multifactor authentication, account alerts, and updated recovery details. Remove old phone numbers and email addresses.
What Protection Did TransUnion Offer?
Affected consumers were offered 24 months of free MyTrueIdentity service from the date they enrolled.
The package included TransUnion credit monitoring, a credit report and score, identity protection, identity recovery help, and up to $1 million in identity theft insurance. It also included fraud support through Cyberscout.
These services began only after the person entered the code from the notice and passed the required identity checks.
Credit monitoring can alert users to changes in their files, but it cannot prevent every case of identity theft or misuse of personal information.
How to Enroll in MyTrueIdentity
Go to the official MyTrueIdentity activation page by typing the address shown in your TransUnion letter.
Enter the unique code from the notice, complete the identity checks, and create an account with a secure email address and password.
Save the confirmation and enrollment date for your records. Avoid opening activation links sent through unexpected emails or text messages.
Has the Enrollment Deadline Passed?
The notice gave recipients 90 days from the date of the letter to enroll. Codes from August 2025 letters may have expired, so contact the number listed in your notice if the code is rejected.
Conclusion
The TransUnion data breach exposed personal details linked to millions of consumers, though the company said core credit reports were not accessed.
Affected people should read their notice, check which data was involved, and watch for unfamiliar accounts or inquiries.
Credit freezes, fraud alerts, and regular report checks can help lower the risk of identity theft.
Have you received a TransUnion breach notice or used MyTrueIdentity? Drop a comment below and share your experience with other readers.
Frequently Asked Questions
Does a Breach Notice Lower Your Credit Score?
Receiving a notice or joining a monitoring service does not lower your credit score. Your score changes based on information recorded in your credit file.
Can Children Become Victims of Identity Theft?
Yes, stolen child identity details may be used to open false accounts. Parents can check for a credit file and request a freeze when needed.
Should You Close Your Trans Union Account?
Closing an online account does not remove the credit file TransUnion keeps about you. It may also end access to reports, alerts, or monitoring tools.












