Data Breaches

10 Million Impacted by Conduent Data Breach

The hackers stole names, addresses, dates of birth, Social Security numbers, and health and insurance information.

Conduent data breach

Business services provider Conduent is notifying more than 10 million people that their personal information was stolen in a January 2025 data breach.

The incident was disclosed publicly in late January, when Conduent confirmed system disruptions that affected government agencies in multiple US states.

In April, the company notified the Securities and Exchange Commission (SEC) that the attackers had stolen personal information from its systems.

Last week, Conduent started notifying users that their personal information was stolen in the incident, and submitted notices to Attorney General’s Offices in multiple states.

The hackers accessed Conduent’s network on October 21, 2024 and were evicted on January 13, 2025, after the attack was identified, the company says in the notification letter to the affected individuals.

During the time frame, the attackers exfiltrated various files from the network, including files containing personal information such as names, addresses, dates of birth, Social Security numbers, health insurance details, and medical information.

Advertisement. Scroll to continue reading.

Conduent is not providing the affected people with free identity theft protection services, but encourages them to obtain free credit reports, place fraud alerts on their credit files, and place security freezes on their credit reports.

“Upon discovery of the incident, we safely restored our systems and operations and notified law enforcement. We are also notifying you in case you decide to take further steps to protect your information should you feel it appropriate to do so,” the notification letter reads.

Based on the data breach notice submitted with the authorities in Oregon, it appears that 10,515,849 individuals were impacted, with the largest number in Texas (4 million).

Conduent serves over 600 government and transportation organizations, and roughly half of Fortune 100 companies, across financial, pharmaceutical, and automobile sectors. The company supports roughly 100 million US residents across 46 states.

While the company has not shared details on the threat actor behind the attack, the Safepay ransomware group claimed the incident in February.

SecurityWeek has emailed Conduent for additional information and will update this article if the company responds.

*Updated with the number of impacted individuals from the Oregon Department of Justice.

Related: Toys ‘R’ Us Canada Customer Information Leaked Online

Related: Prosper Data Breach Impacts 17.6 Million Accounts

Related: Hackers Steal Sensitive Data From Auction House Sotheby’s

Related: On Demand: Threat Detection & Incident Response (TDIR) Summit

Related Content

Data Breaches

Kodak told SecurityWeek it believes there is no threat to its systems or operations as a result of the cybersecurity incident.

Malware & Threats

The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.

Data Breaches

The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom.

Data Breaches

The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant.

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Data Breaches

The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. 

Data Breaches

French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign...

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version