TransUnion — one of the three national credit bureaus that compile Americans' credit files — disclosed a breach that hit 4,461,511 U.S. consumers, and the documentary trail you can actually verify is short: a mailed letter dated August 26, 2025, state attorney general filings from early September 2025, and an enrollment code for 24 months of free monitoring.
There is no settlement and no claim form; the consolidated lawsuits are still pending, so the only money on the table today is the monitoring TransUnion is paying for itself. This guide covers what the filed notices say, how to check whether you were notified, what the exposed data justifies doing, and what evidence to keep if a claim becomes possible later. It relies on the breach notices TransUnion filed with state regulators and on federal consumer guidance, not on any private assessment of the company's systems.
Table of Contents
- What the filed notices actually say happened
- Were you notified, and how do you confirm it?
- What was exposed, and why a freeze beats monitoring
- Placing freezes and the monitoring offer
- The litigation, and why no claim form exists yet
- What to keep, starting now
- Frequently Asked Questions
What the filed notices actually say happened
TransUnion's breach notice filed with the Iowa Attorney General dates the intrusion to July 28, 2025 and detection to July 30, 2025. The access was to a third-party application supporting U.S. consumer support operations. TransUnion states its core credit database and the credit reports themselves were not involved.
That distinction matters, and it is TransUnion's characterization, not an independent audit finding. The support application still held identity data, which is why the exposure is serious even if your credit file was untouched. The entry point was people, not software. Reporting by The Record describes social engineering against support staff — a caller posing as a help-desk technician — consistent with the 2025 ShinyHunters campaign against Salesforce-connected customer environments. No patch would have prevented it, which is worth knowing when you judge whether the same trick could work on another company holding your data.
Were you notified, and how do you confirm it?
The anchor date is August 26, 2025. The maine Attorney General's breach database entry records 4,461,511 individuals affected nationally, 16,828 of them Maine residents, with written notice mailed that day.
If a TransUnion letter reached you in late August or early September 2025, the timing fits. State AG breach databases are the verification tool most people overlook. Maine and New Hampshire publish the filings and, in many cases, the sample notice letter itself — so you can compare the letter in your hand against the version the company filed with a regulator.
- Compare your letter's wording and date against the state-filed sample.
- Check that it directs you to myTrueIdentity, TransUnion's monitoring service.
- Treat any letter demanding payment, a Social Security number by reply, or a wire transfer as fraudulent.
- If you never received a letter, absence of one is not proof you were excluded — call TransUnion's dedicated line printed in the public notice.
What was exposed, and why a freeze beats monitoring
TransUnion's notice to the New Hampshire Department of Justice lists names, dates of birth, Social Security numbers, billing addresses, email addresses, phone numbers, and the contents of customer-support tickets. Social Security numbers change the calculus. credit monitoring tells you after someone opens an account in your name; a security freeze stops the account from being opened.
With an SSN and a date of birth in circulation, the preventive option is the proportionate one. The support-ticket contents are the quietly nasty part. Those can include whatever you wrote or said while disputing something — account numbers, employer details, explanations of financial hardship — and nobody can tell you generically what is in yours.
Placing freezes and the monitoring offer
Under federal law effective September 21, 2018, freezes and unfreezes are free at all three bureaus, and an online or phone request must be honored within one business day. The FTC's guidance on freezes and fraud alerts also sets out the asymmetry people get wrong: a freeze must be placed separately at Equifax, Experian and TransUnion, while a fraud alert placed at one bureau propagates to the other two. TransUnion is offering 24 months of free credit monitoring and identity protection through myTrueIdentity, with identity restoration support and $1 million in identity theft insurance.
Enrollment requires the activation code printed in the mailed letter — which is the practical reason not to throw the letter away. Michigan Attorney General Dana Nessel reissued a consumer data-breach alert on September 22, 2025 in direct response to this incident, telling residents to monitor accounts and use free freezes rather than wait for a letter. That is the right sequencing: freeze first, enroll when the code arrives.
The litigation, and why no claim form exists yet
On December 16, 2025 the Judicial Panel on Multidistrict Litigation centralized the resulting suits as *In re Trans Union, LLC, Customer Data Security Breach Litigation*, MDL No. 3170, in the Northern District of Illinois before Judge Robert W. Gettleman. An MDL consolidates similar federal cases before one judge for pretrial handling; it is not a settlement and does not by itself pay anyone.
As of August 2026 the MDL still had roughly 63 pending actions and no approved class fund, according to a docket tracker for MDL 3170. Any site offering a "TransUnion breach claim form" today is not distributing court-approved money — at best it is collecting leads, at worst it is harvesting the same identity data the breach already exposed. When a real settlement arrives, it comes with a court-approved notice and an administrator named in the order. Until then, the useful move is preserving evidence, not filling in forms.
What to keep, starting now
Evidence for a later claim is mostly boring and mostly yours to create. Keep the mailed notice letter — envelope included, since the postmark corroborates the date.
Then keep dated records of anything the breach cost you. If actual misuse shows up, the FTC's IdentityTheft.gov generates a personalized recovery plan and an identity theft affidavit. That affidavit is the standard documentation banks, creditors and courts expect — file it when something happens, not preemptively, and store it with the letter.
- Out-of-pocket losses: fraudulent charges, credit report fees, notary or postage costs.
- Time spent: dates, durations, and what you were doing (calls, freezes, disputes).
- Copies of any fraud you report, with case or reference numbers.
- Screenshots of unfamiliar accounts or inquiries on your credit reports.
Frequently Asked Questions
Does the breach mean my credit report was altered?
TransUnion's Iowa filing states the core credit database and credit reports were not involved; the access was to a third-party support application. Your report can still be misused by someone opening accounts with the exposed SSN, which is what a freeze blocks.
I lost the letter. Can I still enroll in the free monitoring?
Enrollment requires the activation code printed in the mailed letter, so you need a replacement. Contact TransUnion through the dedicated number in its public breach notice rather than a number from a search result or email.
Should I place a fraud alert instead of a freeze?
A fraud alert is easier — placing it at one bureau propagates to the other two — but it only asks lenders to verify identity. With Social Security numbers exposed, the FTC's freeze, which must be placed at each bureau separately, is the stronger control.
Will joining the MDL get me a payout?
Not yet and not automatically. MDL 3170 had roughly 63 pending actions and no approved class fund as of August 2026, and any distribution would be announced through a court-approved notice naming a settlement administrator.
You Might Also Like
- Cybersecurity — UnitedHealth Breach Investigation Guide: Evidence, Notices, and Verification
- How to Verify Financial Sector Data Breach News Claims in 2026: breach notices and security advisories, Evidence, and Red Flags
- Financial Sector Data Breach News Explained for 2026: Who It Affects, Key Evidence, and What to Do Next