Description

Conduent Business Services, LLC (“Conduent”), a major back-office services provider to government agencies, insurers and healthcare organisations, has confirmed a large-scale data breach that may have impacted more than 10 million individuals. The incident stems from unauthorised access to Conduent’s network between 21 October 2024 and 13 January 2025. During that period the attacker(s) allegedly exfiltrated data files containing personally identifiable information (PII) and protected health information (PHI) of clients and downstream beneficiaries/customers. The types of data compromised reportedly include names, dates of birth, Social Security numbers (SSNs), treatment/claims data, health insurance details, and other sensitive elements. Several states’ attorney-general offices and clients of Conduent have begun publishing breach notifications or filings estimating impacted populations. For example, Texas disclosed more than 4 million individuals affected in relation to Conduent’s services. Conduent has indicated it restored normal operations shortly after discovery, engaged third-party cybersecurity investigators, and reported the matter to law enforcement.