TransUnion Data Breach Class Action Lawsuit: Claims and Standing

The class action lawsuits over the 2025 TransUnion data breach have been consolidated into a single federal proceeding, In re Trans Union, LLC, Customer Data Security Breach Litigation, MDL No. 3170, pending in the U.S. District Court for the Northern District of Illinois. As of mid-2026, the case is active but early: no settlement has been reached, no rulings on dispositive motions have been publicly reported, and 63 of the 67 filed actions remain pending.1MDL Update. MDL 3170 Trans Union LLC Data Security Breach Litigation

Where the Case Stands

The Judicial Panel on Multidistrict Litigation consolidated the individual suits on December 16, 2025, and assigned them to Senior District Judge Robert W. Gettleman.2Judicial Panel on Multidistrict Litigation. MDL 3170 Transfer Order One of the earlier-filed cases, Herships v. TransUnion LLC (Case No. 1:25-cv-15428), was brought on December 19, 2025, by plaintiff Howard Herships, represented by DiCello Levitt LLP and Stueve Siegel Hanson LLP.3Top Class Actions. TransUnion Faces Second Class Action Over Data Breach Involving 4.4 Million Individuals Dozens of similar suits from other jurisdictions were rolled into the MDL.

No settlement negotiations are known to be underway, and no motions to dismiss have been ruled on. The resolution rate reported for the MDL sits at roughly six percent.1MDL Update. MDL 3170 Trans Union LLC Data Security Breach Litigation

What the Lawsuits Allege

The consolidated complaints allege that TransUnion failed to adequately secure the personally identifiable information of the people affected by the July 2025 breach. Claims include negligence, negligence per se, breach of implied contract, and unjust enrichment.3Top Class Actions. TransUnion Faces Second Class Action Over Data Breach Involving 4.4 Million Individuals Plaintiffs are seeking monetary damages along with injunctive relief that would require TransUnion to improve its vendor oversight and internal security controls.4Security.org. TransUnion Data Breach

Who Is Covered

The breach affected 4,461,511 people in the United States.5Fox News. TransUnion Becomes Latest Victim of Major Wave of Salesforce-Linked Cyberattacks According to breach notification filings, the exposed data included full names, dates of birth, Social Security numbers, billing addresses, phone numbers, email addresses, and in some cases customer support interaction histories.6ASIS International. TransUnion ShinyHunters Hack TransUnion said the attackers did not reach its core credit database or access consumer credit reports; the intrusion involved a third-party application connected to its U.S. consumer support operations.7Infosecurity Magazine. TransUnion Data Breach US Customers

If you received a notification letter from TransUnion dated on or after August 26, 2025, you are within the pool of people the lawsuits are meant to represent.6ASIS International. TransUnion ShinyHunters Hack No class has been certified yet, and no claims process exists because there is no settlement.

The Standing Hurdle

The biggest obstacle for the plaintiffs comes from a 2021 Supreme Court decision that also involved TransUnion. In TransUnion LLC v. Ramirez, the Court held that every member of a class seeking damages in federal court must show a concrete harm. A bare statutory violation is not enough.8Supreme Court of the United States. TransUnion LLC v. Ramirez, No. 20-297 The case arose under the Fair Credit Reporting Act, but its logic reaches data breach litigation directly: courts may require proof that stolen information was actually misused or exposed to third parties, not simply that it was taken.9Congressional Research Service. TransUnion LLC v. Ramirez

In Ramirez itself, the Court found that only the 1,853 class members whose inaccurate credit files had actually been sent to third parties suffered concrete reputational harm; the remaining 6,332 lacked standing.10Harvard Law Review. TransUnion v. Ramirez Lower courts applying that ruling have split on how much risk of future misuse counts as concrete harm.11Harvard Journal of Law and Technology. Time for SCOTUS To Step In

The 2025 breach plaintiffs may sit in a stronger position than plaintiffs in some earlier cases. The stolen records include Social Security numbers, which security experts describe as the kind of information criminals need to commit identity theft and open fraudulent accounts.4Security.org. TransUnion Data Breach A sample of the stolen data, with unredacted Social Security numbers, was verified by journalists, indicating the records are already circulating among criminal actors.6ASIS International. TransUnion ShinyHunters Hack Whether that is enough to establish concrete harm across millions of class members will likely be tested when TransUnion files its expected motions to dismiss.

What You Can Do Now

TransUnion began mailing breach notification letters to affected individuals on August 26, 2025.6ASIS International. TransUnion ShinyHunters Hack The letter offered 24 months of free credit monitoring and identity protection through TransUnion’s myTrueIdentity platform. The package includes:

  • Credit monitoring, credit report, and credit score with ongoing alerts for changes to your TransUnion file.
  • Identity protection and resolution services.
  • Up to $1 million in identity theft insurance.
  • Fraud assistance from Cyberscout, a TransUnion subsidiary.

Enrollment runs through mytrueidentity.com using the unique code printed in your letter, and you have 90 days from the date on that letter to sign up.12California Office of the Attorney General. TransUnion U.S. Adult Consumer Notification Letter Enrolling in the monitoring does not waive your right to participate in the class action if one is later certified or settled.

Because no settlement exists, there is no claim form to fill out and no payment to expect at this stage. If a settlement is reached, class members would typically be notified by mail or email at the address TransUnion has on file, and a claims administrator would set up a dedicated website. Watch for that notification rather than acting on any unsolicited message claiming to represent the settlement, since data breach settlements attract phishing attempts.

Regulatory Activity

TransUnion disclosed the breach to the attorneys general of Maine and Texas.6ASIS International. TransUnion ShinyHunters Hack Michigan Attorney General Dana Nessel issued a consumer alert in September 2025, noting that Michigan law does not require companies to report breaches directly to her office and using the incident to press for pending state legislation (Michigan Senate Bills 360–364) that would strengthen breach notification and identity theft protections. Those bills had passed the Michigan Senate and were awaiting action in the state House as of that alert.13Michigan Attorney General. Attorney General Nessel Reissues Consumer Alert on Data Breaches No federal enforcement action by the FTC or another agency has been publicly announced.