Conduent Data Breach – Largest Data Breach in U.S. History As Ransomware Group Stolen 8 TB of Data
Conduent Business Services, LLC has reported a significant data breach, impacting a considerable number of individuals across the United States. The breach was initially disclosed in an April 2025 SEC filing, revealing that unauthorized access to its…
Conduent Business Services, LLC has reported a significant data breach, impacting a considerable number of individuals across the United States. The breach was initially disclosed in an April 2025 SEC filing, revealing that unauthorized access to its systems occurred over nearly three months from late 2024 to early 2025. This incident involved the exfiltration of files containing personal information of millions of Americans.
State regulatory reports indicate that at least 15.4 million individuals in Texas were affected, with an initial estimate of 4 million. In Oregon, 10.5 million were impacted, alongside hundreds of thousands in other states. The total number of affected individuals is now estimated to exceed 25 million, making this one of the largest data breaches disclosed in 2025.
Ransomware Group Claims Responsibility
The Safepay ransomware group has claimed responsibility for the breach, asserting that it stole over 8 terabytes of data. This includes sensitive information such as names, Social Security numbers, addresses, medical histories, and health insurance details. Conduent has not confirmed the ransomware group's claims or the exact volume of data taken but has acknowledged the exfiltration of client-related files.
October 21, 2024 – January 13, 2025 : Unauthorized access to Conduent's network. January 13, 2025 : The breach was discovered, causing temporary operational disruptions to government services. Conduent contained the breach with the help of third-party forensic experts, restored systems, and notified law enforcement. April 9, 2025 SEC 8-K Filing : Conduent reported that files tied to a limited number of clients were exfiltrated. The company engaged data-mining experts to confirm the datasets contained significant personal information related to clients' end-users. No material operational impact or public data release was noted at that time. The company reported non-recurring expenses for notifications and maintained cyber insurance. Late 2025 – February 2026 : Notifications to affected individuals began and are expected to be completed by mid-April 2026.
Conduent Business Services, LLC has reported a significant data breach, impacting a considerable number of individuals across the United States.
Conduent advises affected individuals to take the following steps to protect themselves against identity theft and fraud:
Monitor credit reports and accounts for suspicious activity. Place a fraud alert or credit freeze with major credit bureaus. Use strong, unique passwords and enable multi-factor authentication. Be cautious of phishing attempts referencing the breach.
Conduent has set up a call center for queries and emphasized that it regrets any inconvenience caused by this incident. As investigations continue, individuals are encouraged to stay informed through official state attorney general breach portals or by contacting Conduent directly using the information provided in their notification letters.
Based on reporting by Cyber Security News.
