Monday, September 01, 2025

Bleeping Computer Headline Articles + Clips

Consumer credit reporting giant TransUnion warns it suffered a data breach exposing the personal information of over 4.4 million people in the United States, with BleepingComputer learning the data was stolen from it's Salesforce account.

https://www.cyfirma.com/media/2022/10/BleepingComputer.png 

TransUnion is one of the three major credit bureaus in the United States, alongside Equifax and Experian. It operates in 30 countries, employs 13,000 staff, and has an annual revenue of $3 billion.

TransUnion suffers data breach impacting over 4.4 million people

By Bill Toulas
August 28, 2025
10:10 AM
1

TransUnion

Update: Story updated with confirmation that this was another Salesforce data theft attack and the types of data stolen.

wave of Salesforce data theft attacks has impacted numerous companies this year, including GoogleFarmers Insurance, Allianz Life, Workday, Pandora, Cisco, Chanel, and Qantas.

These attacks have been conducted by the Shiny Hunters extortion group, and more recently, by a cluster tracked as UNC6395.

After publishing this story, BleepingComputer confirmed with two sources, including ShinyHunters, that TransUnion's data breach is linked to these Salesforce attacks.

The threat actor claims that the stolen data consists of over 13 million records, with 4.4 million records related to people in the US.

  • A sample of the stolen data shared with BleepingComputer contains quite a lot of sensitive personal information, including names, billing addresses, phone numbers, email addresses, dates of birth, and unredacted Social Security Numbers of TransUnion customers.

The data also includes the reason for the customer transaction, such as a request for a free credit report.

  • In addition to customer data, the threat actors also claim to have stolen customer support tickets and messages that were stored in Salesforce.

BleepingComputer contacted TransUnion with further questions about this breach, and we will update this article if we receive a response.

Two years ago, a threat actor claimed a data breach at TransUnion, which the company rejected, saying that the data had been stolen from a third party.

In previous years, the company's South African and Canadian branches suffered cybersecurity breaches that exposed customer information.

Update 8/28/26 2:13 PM ET: Added information about the types of data stolen from TransUnion's Salesforce instance. 

https://scontent-phx1-1.xx.fbcdn.net/v/t45.1600-4/521356390_24880325598236416_5037950304336050515_n.png?stp=cp0_dst-jpg_p526x296_q90_spS444_tt6&_nc_cat=1&ccb=1-7&_nc_sid=b81fdb&_nc_ohc=Rv0G5RIYECkQ7kNvwEQsk8f&_nc_oc=AdnBm1S0E_LX8xMLcPuFHF7Q88aphsSf-nT4S8J1LmgkBfVNeC_h9D4iXiiWPlgkBNQ&_nc_zt=1&_nc_ht=scontent-phx1-1.xx&_nc_gid=7KwQrmoev6JagzhXac9LQg&oh=00_AfXllVXYW4wlI_R6-GZndxxPaTnLaq5vK_1gxEi9ILceHg&oe=68BC4CF6 

Anthropic is testing GPT Codex-like Claude Code web app

By Mayank Parmar
August 31, 2025
11:00 AM

Claude

Anthropic is planning to bring the famous Claude Code to the web, and it might be similar to ChatGPT Codex, but you'll need GitHub to get started.

For those unaware, Claude Code, which works with paid plans, is an AI-powered coding assistant that runs inside your terminal. It is primarily designed for developers, and it can understand the entire codebase of your app.

Claude Code
Claude code in Windows Terminal
Source: BleepingComputer

With Claude Code, you can fix bugs, test new features, simplify Git operations, and automate your complex coding tasks.

Claude code

You'll find a new research preview of Claude Code on Claude.ai/code with a prompt composer.

As I mentioned, it requires you to set up a repository, which means you'll need to install the GitHub Claude app on your repository and then commit the "Claude Dispatch" GitHub workflow file. 

  • You can enable email and web notifications for Claude Code updates.
  • It's not clear if Claude Code in the terminal or web can access the content written in either of the places. 

Picus Blue Report 2025 is Here: 2X increase in password cracking

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

Related Articles:

Bitcoin Depot breach exposes data of nearly 27,000 crypto users

IdeaLab confirms data stolen in ransomware attack last year

Healthcare Services Group data breach impacts 624,000 people

Auchan retailer data breach impacts hundreds of thousands of customers

Major European healthcare network discloses security breach


LATEST ARTICLES 
  • Amazon disrupts Russian APT29 hackers targeting Microsoft 365

    Researchers have disrupted an operation attributed to Russian state-sponsored threat group Midnight Blizzard, who sought access to Microsoft 365 accounts and data.

  • New Whitepaper: The Evolution of Phishing Attacks

    Modern phishing has changed a lot in the past decade or so. The most sophisticated attacks — the ones that usually hit the headlines in the form of major breaches — come with a host of anti-analysis and obfuscation techniques making them increasingly difficult to detect.

    Get the whitepaper to learn about modern phishing detection evasion techniques and how to counteract them.

  • This thin new bluetooth item tracker deal is great for wallets and ID badges

    It's easy to misplace small items like your wallet or ID badge and finding them can turn into a huge hassle. The KeySmart SmartCard Lite is a slim trackers work just like AirTags, but they'll go where AirTags won't. It's also only $64.99 (reg. $99.96) for a four-pack.

    • BleepingComputer Deals
    • September 01, 2025
    • 08:12 AM
  • Brokewell Android malware delivered through fake TradingView ads

    Cybercriminals are abusing Meta's advertising platforms with fake offers of a free TradingView Premium app that spreads the Brokewell malware for Android.

     

  • OpenAI releases big upgrade for ChatGPT Codex for agentic coding

    OpenAI has announced a big update for Codex, which is the company's agentic coding tool.

  •  
     
     
     
     
     

    Zscaler data breach exposes customer info after Salesloft Drift compromise

    Cybersecurity company Zscaler warns it suffered a data breach after threat actors gained access to its Salesforce instance and stole customer information, including the contents of support cases.

     

    No comments: