The Register Home Page

back to article TransUnion admits 4.5M affected after third-party support app breached

Credit scoring and monitoring biz TransUnion says that it recently suffered a breach affecting nearly 4.5 million individuals. Readers may notice the irony of a credit monitoring company, whose services are so often given "free of charge" to victims of data breaches in order to "secure" their identity and credit score, being …

  1. elDog

    "the exposed information "was limited to specific data elements."

    Almost sounds like TransUnion supplied the data schema to the miscreants.

    "TransUnion takes the protection of personal information seriously, which is why we engage in robust, proactive security measures," its letter to consumers read. "We continue to enhance our security controls as appropriate to minimize the risk of any similar incident in the future."

    Newspeak boilerplate (c).

    1. Yet Another Anonymous coward Silver badge

      Re: "the exposed information "was limited to specific data elements."

      The bank robbery was limited to specific denominations

  2. Anonymous Coward
    Anonymous Coward

    In all likelihood, you can avail yourself of the free data protection service AFTER

    you provide even more details proving your identity.

    To the company that

    leaked the data that

    they already had.

  3. sitta_europea

    "Readers may notice the irony of a credit monitoring company ... being popped itself."

    Well they might if it didn't happen so often.

  4. John Brown (no body) Silver badge

    They aren't too concerned as they are only admitting to what is effectively "public" data, not the valuable, proprietary credit scores etc., so why would they care? The money data is still safe, screw the users and their "personal" details.

  5. CaptainDorkOfTheWeeniePatrol

    Oh, the irony ...

    TransUnion sells identity protection services that monitor for exposure of exactly the same kinds of data (name, DOB, SSN) that were themselves stolen in the breach. In other words:

    What they promise to watch for → unauthorized exposure of your personal identifiers.

    What hackers actually took from them → those same identifiers.

    That’s a bit like a lock company being robbed of its own keys.

    It highlights a fundamental problem: once those “static” identifiers (SSN, DOB, etc.) are stolen, they can’t really be changed. Unlike a password, you can’t just “reset” your Social Security number.

    That’s why breaches at credit bureaus are particularly concerning — they’re custodians of the most sensitive personal data, and when they get breached, the damage is both widespread and long-lasting.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like