Skip to main content
Breach Signal

Breach report

Healthcare

Conduent

Conduent data breach grows, affecting at least 25M people

A ransomware intrusion at government and health-benefits contractor Conduent spiraled into one of the largest U.S. breaches on record, exposing Social Security numbers and medical data for tens of millions of people who had never heard of the company.

Reported by TechCrunch

Records exposed

62.2M

At least 25 million people; later reported to HHS as about 62.2 million

Scale vs. largest on file

When
2025
How they got in
Ransomware and data theft (claimed by SafePay)
Sector
Healthcare

Conduent, a New Jersey-based business services company that processes state benefit programs, Medicaid and health insurance claims, and corporate benefits, suffered a cyberattack that began on October 21, 2024 and was detected on January 13, 2025. The intrusion caused outages that disrupted state payment systems in the United States, including delays to benefits and child-support payments in several states. Conduent was spun off from Xerox in 2017 and serves government agencies and large corporations across the country.

The SafePay ransomware group claimed responsibility in early 2025, saying it had stolen about 8.5 terabytes of data. The company confirmed that attackers had exfiltrated files during roughly three months inside its environment. Because Conduent works behind the scenes for state agencies, insurers and employers, most affected people had no direct relationship with it and learned of the breach only through notification letters.

The scale became clear slowly. Conduent began notifying people in late 2025, with early state filings pointing to roughly 10 million affected. By February 2026, TechCrunch counted more than 25 million people, including about 15.4 million in Texas and 10.5 million in Oregon, with others in Massachusetts, New Hampshire and Washington. TechCrunch also found that Conduent had added code to its incident notice page to keep it out of search engine results. A June 2026 filing with federal health regulators, reported by HIPAA Journal, put the total at about 62.2 million individuals, which would make it the third-largest U.S. healthcare breach after Change Healthcare and Anthem.

The exposed data included names, addresses, birthdates, Social Security numbers, health insurance details and medical information. Affected clients included Humana, Premera Blue Cross, and Blue Cross Blue Shield plans in Texas and Montana, as well as employer benefit programs. At least nine class actions were filed in New Jersey federal court by late 2025, and state officials pressed the company for faster disclosure.

Conduent's breach, like Change Healthcare's, shows how much sensitive data is concentrated in little-known intermediaries. Consumers cannot choose which contractors their state or insurer uses, yet a single vendor compromise can expose them. The case also raised questions about transparency, as the slow rollout of victim counts left millions uncertain about their risk for more than a year.

More from the wire

More in Healthcare.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.