TransUnion
| Primary URL | Location | Industry | www[.]transunion[.]com |
Country
South Africa
|
Financial Services
|
|---|
Profile
TransUnion functions as a consumer credit reporting agency that gathers, analyses, and distributes credit-related data on individuals and businesses. Its primary offerings consist of credit reports, credit scores, and ongoing credit monitoring services that assist lenders in risk assessment and enable consumers to track their financial standing. In addition to reporting, the company provides identity protection and fraud detection tools, which are frequently extended to affected parties after a security incident. While the United States represents its largest market, TransUnion also operates in South Africa, Canada, and several other African nations, delivering services to both local and international clients.
The scope of TransUnion’s data holdings is highlighted by the figures disclosed in its breach notifications. In the United States, the company states it maintains files on nearly every credit‑active consumer, a number estimated at approximately two hundred million people. In South Africa, a 2022 incident exposed roughly four terabytes of information belonging to an estimated fifty‑four million customers, a set that also included clients in other African countries. A separate 2019 event noted that about thirty‑seven thousand Canadians may have had personal information accessed through fraudulent use of a legitimate business customer’s credentials. These figures illustrate the breadth of the firm’s consumer database across multiple jurisdictions.
The 2022 South Africa breach occurred when attackers obtained stolen credentials and brute‑forced an SFTP account protected only by the weak password 'Password,' allowing them to exfiltrate approximately four terabytes of data. The intruders, identifying themselves as N4ughtysecTU, demanded a fifteen‑million‑dollar Bitcoin ransom and threatened to release the data or extort individual clients unless paid. TransUnion refused to meet the ransom demand, engaged external cybersecurity and forensic experts, cooperated with law‑enforcement authorities, and subsequently offered free identity‑protection services to all affected individuals. Notification letters were sent after the company reviewed the compromised records and reported the breach to relevant regulators.
Earlier, in June 2019, TransUnion disclosed that unauthorized access via fraudulent credentials had potentially compromised the personal data of around thirty‑seven thousand Canadians; the breach was detected months after the initial exposure window, prompting notifications to affected individuals and privacy regulators while the company asserted that neither its own systems nor the customer’s infrastructure had failed. The 2022 United States incident, reported in November, described unauthorized access to a consumer credit reporting database that could have exposed names, Social Security numbers, financial account details, and driver’s licence information, though the exact number of impacted individuals was not specified. Together, these episodes underscore the company’s role as a custodian of extensive consumer credit information and its obligations to safeguard that data under varying regulatory regimes.
