Connect with us

Technologies

More Than 4.4 Million Exposed in Credit Bureau TransUnion Breach: What to Know

The breach appears related to a wave of attacks on companies’ Salesforce databases.

Sensitive personal information belonging to 4.4 million customers, including their names and Social Security numbers, was exposed in a data breach on credit bureau TransUnion, in what is believed to be the latest in a string of attacks targeting companies’ Salesforce databases. 

The data breach, which occurred on July 28, was identified and contained within hours, a TransUnion spokesperson told CNET. TransUnion is one of three credit bureaus — along with Equifax and Experian — that compile your financial activity into credit reports that are then used to create your credit scores. The credit bureau said it’s notifying people who may have been affected and sharing the actions the company is taking. 


Don’t miss any of our unbiased tech content and lab-based reviews. Add CNET as a preferred Google source on Chrome.


Two separate state filings shed more details on the situation. A court filing in Maine shows that TransUnion acknowledged unauthorized access from a third-party application that stored personal customer data. While the notice to consumers says that no credit information was accessed, «limited personal information» was exposed. However, another filing from Texas states that names of individuals, Social Security numbers and birthdates were exposed in the breach. 

The TransUnion spokesperson further clarified that the breach involved a third-party application serving its US consumer support operations but did not include its core credit database or credit reports. The bureau has engaged third-party cybersecurity experts for an independent forensics review. 

The breach came after Google reported in June that hackers were using a modified version of a Salesforce-related app to steal vast stores of data, infiltrate other cloud systems and extort compromised companies. The same report named the cybercriminal hacking group ShinyHunters, which it said was linked to extortion demands to employees of the victim organizations.

Several global organizations have already been caught in a wave of Salesforce-linked attacks, according to BleepingComputer, including Google, Farmers Insurance, Allianz Life, Workday, Pandora, Cisco, Chanel and Qantas. Salesforce said social engineering, and not its platform, were to blame for the attacks.

«The Salesforce platform has not been compromised, and this issue is not due to any known vulnerability in our technology,» Salesforce said in a statement in August, adding that customers can mitigate the risk by enabling multi-factor authentication and closley managing connected applications.

Consumer rights law firm Wolf Haldenstein issued an alert on the breach and encouraged those who have received a notice and spot unusual activity on their credit report to reach out.

If you’re not sure if your private data was leaked or you haven’t received any communication from TransUnion, you can check by calling its Fraud Victim Assistance Department at 800-680-7289.  

Even if you haven’t received a notice, if you’ve experienced unusual activity on your credit report, you can always freeze your credit for free, enable two-factor authentication or add a security key to your accounts.

Technologies

Here’s How Much Tesla’s New Affordable Electric Cars Cost

What do you get with the stripped-down Model Y and Model 3? A lower price, for starters.

Continue Reading

Technologies

This New Car Feature Uses AI to Keep You From Missing Your Exit

Google Maps’ live lane guidance is being integrated into Polestar’s head-up display.

Continue Reading

Technologies

Hurry to Nab the Baseus Bowie MH1 Headphones for Over Half Off With This Early Black Friday Deal

This deal drops the price of this premium pair to just $47, but this discount ends soon.

High-quality noise-canceling headphones can cost a pretty penny, especially if you are after adaptive ANC, all-day comfort, and a reliable battery life. Most options with all these features sit well over $100, but we just found a way to score a premium pair for less than $50.

Amazon has a solid early Black Friday deal on the Baseus Bowie MH1 headphones. You can get them for 20% off right now, which drops the price to $80. But stack that with the $25 on-page coupon and use the promo code 8JWTGEUN at checkout, and you slash another $33 off. That brings the final price down to just $47, which is a steal considering all the features you are going to enjoy.

The headphones come with cloud-soft protein leather earcups with resilient memory foam for cloud-like comfort. The pair is capable of blocking up to 99.8% of noise with –48 dB deep noise cancellation, and it adapts to your surroundings as needed.

Hey, did you know? CNET Deals texts are free, easy and save you money.

The 36mm drivers and full-range LCP diaphragms give you clear, rich sound no matter what you listen to. In addition, with Baseus Immersive Spatial Acoustics, the audio surrounds you for a more natural listening experience. For clearer calls, the headphones also pack 5-mic sound sensors with AI-powered voice enhancement and wind-noise reduction. You won’t have to repeat yourself constantly.

Battery-wise, you get up to 80 hours of playtime with ANC off, and 55 hours with it on. A quick 10-minute top-up can also get you up to an additional 10 hours of playback, which is great for when you’re out and about.

Why this deal matters

High-end audio gear doesn’t come cheap. This deal takes over 50% off a powerful pair of headphones, making the upgrade easy. It won’t last long, though, so it’s best to snap it up sooner rather than later.

Join Our Daily Deals Text Group!

Get hand-picked deals from CNET shopping experts straight to your phone.

By signing up, you confirm you are 16+ and agree to receive recurring marketing messages at the phone number provided. Consent is not a condition of purchase. Reply STOP to unsubscribe. Msg & data rates may apply. View our Privacy Policy and Terms of Use.

Continue Reading

Trending

Copyright © Verum World Media