Nadia Dubois
August 5, 2026
13 min read
Conduent filed its final breach tally with federal regulators on The Conduent breach was first detected in January 2025, but the 62,224,658 figure is the confirmed exposure total; June 4, 2026 is when the HHS OCR portal listed that total, not the discovery date. That number makes the Conduent data breach the third-largest healthcare data breach in US history, behind only the 2024 Change Healthcare attack (192.7 million people) and the 2015 Anthem breach (78.8 million people), according to the Department of Health and Human Services Office for Civil Rights breach portal.
The final count didn’t arrive all at once. Conduent told regulators about 10.5 million affected people when notifications began in October 2025. By February 2026, that figure had grown to 25 million. Four months later, it more than doubled again. This kind of slow-motion escalation is becoming standard practice rather than the exception, and it’s happening against the backdrop of a record year for breach disclosures overall. The Identity Theft Resource Center’s first-half 2026 data breach report counted 471.2 million victim notices sent out in six months, up As of April 6, 2026, the relevant total is about 58% higher than the prior full-year figure only if you are comparing the 2026 first-half notice total to the 2025 full-year total; the claim is incomplete without the underlying totals. Conduent is one of two incidents responsible for most of that surge.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Happened: Inside the Conduent Data Breach Timeline
Conduent is not a household name, but it processes work for organizations that touch nearly every American. The New Jersey-based company handles back-office government and business processes: state Medicaid and SNAP administration, corporate HR services, tolling systems, and healthcare claims work, among other contracts. Conduent has said its systems have historically supported more than 100 million people and a majority of the Fortune 100, along with more than 500 government clients.
That footprint is what turned a single intrusion into one of the biggest breaches on record. According to reporting from Malwarebytes and TechCrunch, attackers linked to the SafePay ransomware group first accessed Conduent’s environment on October 21, 2024. The company didn’t detect the intrusion until January 13, 2025, exactly 84 days later. Secondary reporting has put the volume of stolen data at roughly 8.5 terabytes, though Conduent itself has not confirmed that specific figure in its own filings. What the company has confirmed is the type of data taken: names, dates of birth, home addresses, Social Security numbers, health insurance details, and medical information tied to healthcare claims.
From 10.5 Million to 62.2 Million: How the Victim Count Kept Growing
Few breaches have grown in public view the way Conduent’s has. The company’s first disclosures in October 2025, roughly nine months after discovering the intrusion, put the affected population at about 10.5 million people. TechCrunch reported on February 5, 2026 that the number had swelled past 25 million as more states and corporate clients completed their own review of affected records. Texas alone saw its estimate climb from roughly 4 million residents to 15.4 million. Oregon’s count reached about 10.5 million residents on its own.
What Data Was Exposed in the Conduent Data Breach
The categories of exposed information are broad enough to enable most forms of downstream fraud. Confirmed data types include full names, dates of birth, home addresses, phone numbers, Social Security numbers, health insurance policy details, medical diagnosis and treatment information, and claims data tied to government benefit programs. For some individuals, the exposure also touched employment records processed through Conduent’s HR outsourcing contracts.
That combination matters more than any single data point on its own. A Social Security number paired with a date of birth and address is enough to open fraudulent credit accounts. Add medical and insurance details, and the same data set supports healthcare fraud, including fraudulent claims filed under a real patient’s coverage. Security researchers generally treat breaches that combine financial, medical, and identity data as higher-risk than breaches limited to a single category, because the exposed records don’t expire the way a stolen credit card number does. A Social Security number stays valid for a lifetime. That’s why healthcare and government-adjacent breaches tend to produce years of downstream fraud instead of a short spike in complaints.
Who Is Conduent, and Why the Breach Reached So Many People
Conduent split off from Xerox in 2017 as an independent, publicly traded company focused on business process outsourcing. It runs the unglamorous infrastructure that state governments and large employers rely on rather than selling a consumer-facing product. That includes processing SNAP and Medicaid eligibility for more than 30 states, running toll collection systems, administering corporate HR and payroll functions, and handling healthcare claims on behalf of insurers.
That role as a middleman explains why so many people who never signed up for anything called Conduent ended up in its breach notifications. If a state contracts with Conduent to process Medicaid applications, every applicant’s data passes through Conduent’s systems no matter which health plan they eventually choose. The same logic applies to Conduent’s corporate clients. An employee never picks their employer’s HR vendor, yet that vendor ends up holding sensitive personal data anyway. It’s the same dynamic behind the EY vendor breach that exposed tax data earlier in 2026. When a downstream processor gets breached, the damage lands on people who had no direct relationship with the company at all.
Government Contracts at the Center of the Exposure
Conduent’s government work is what pushed the numbers into the tens of millions so quickly. State benefit programs process applications for large shares of a state’s population, and a single state contract can expose more people than a mid-sized company’s entire customer base combined. That concentration is also why state attorneys general, not just federal regulators, have taken such an active role in tracking how far the breach actually reached.
Conduent vs. History’s Biggest Healthcare Data Breaches
Even at 62.2 million people, the Conduent data breach isn’t the largest healthcare-related breach on record. It’s the third-largest, and the two breaches ahead of it both happened within the past decade, which says something about how concentrated risk has become across the healthcare data supply chain.
Two of the three biggest healthcare-related breaches in US history reached their final numbers within the same two-year stretch. Change Healthcare’s 192.7 million-person breach became public in 2024, and Conduent’s 62.2 million-person total was finalized in June 2026. That clustering isn’t a coincidence. Both companies process claims and eligibility data for large numbers of downstream clients, and both became attractive ransomware targets precisely because a single successful intrusion could yield records tied to tens of millions of people at once.
The ITRC’s H1 2026 Report: A Record First Half for Breach Notices
The Conduent data breach didn’t happen in isolation. The Identity Theft Resource Center’s first-half 2026 data breach report counted 1,803 total data compromises between January and June, of which 1,394, or 77%, were confirmed data breaches involving unauthorized access rather than exposure alone. Combined, those incidents generated 471.2 million victim notification letters in six months, more than double the same period a year earlier and 58% higher than the full-year 2025 total.
Two incidents account for most of that volume. The breach at education software provider Instructure, which affected roughly 275 million Canvas LMS records, made up about 58% of the entire first-half notice total on its own. Add Conduent’s 62.2 million, and two companies are responsible for the majority of every breach notice mailed to Americans in the first six months of 2026. If the current pace holds, the full year could end with more than 3,600 data compromises, which would make 2026 one of the busiest years on record for breach disclosures.
Why Data Breach Notices Are Doubling Nationwide
The headline number, a 58% jump in victim notices, deserves a closer look before anyone calls 2026 a uniformly worse year for data security. Much of the increase traces back to two mega-incidents rather than a broad-based surge across thousands of small breaches. That distinction matters for how organizations respond. A world where breach volume grows because of a handful of catastrophic vendor incidents calls for different defenses than a world where every company is getting hit equally.
Three structural factors explain why concentrated mega-breaches keep happening. First, ransomware groups increasingly target business-process outsourcers and software vendors instead of individual companies, because one successful intrusion can yield records belonging to dozens of downstream clients at once. Second, disclosure timelines have stretched out considerably. Conduent took roughly 17 months from discovering its breach to filing a final victim count, giving investigators, states, and corporate clients more time to keep finding additional exposed records as the review dragged on. Third, state and federal notification rules require companies to update disclosures as new information emerges, which produces the kind of headline-grabbing revisions Conduent has issued at least three separate times since 2025. None of that makes the underlying incidents less serious. It does mean the raw notice count is a noisier measure of actual risk than it looks at first glance.
Market Impact: Breach Costs, Lawsuits, and Regulatory Fallout
Conduent’s own financial disclosures put breach-related costs at roughly $9 million through September 2025, with another $16 million anticipated by the first quarter of 2026. That’s a total approaching $25 million, and it’s likely to climb further as litigation proceeds. As a publicly traded company, Conduent has had to disclose those figures in SEC filings, giving investors a rare direct look at the running cost of a mega-breach as it unfolds in real time.
The legal fallout has moved just as fast. More than 10 federal class-action lawsuits had been filed in the District of New Jersey by February 2026, according to HIPAA Journal’s tracking of the case, and additional suits typically follow as plaintiffs’ firms in other states file their own complaints. Texas Attorney General Ken Paxton opened a state-level investigation into the breach, and Missouri regulators said publicly in May 2026 that Conduent had not fully cooperated with the state’s inquiry into how the intrusion was handled. None of that activity has produced a settlement yet, but the pattern mirrors what happened after Change Healthcare and Anthem, both of which eventually resulted in nine-figure settlement costs for the companies involved.
Competitive Landscape: The Vendor Risk Problem Beyond Conduent
Conduent is far from the only company whose business model, processing sensitive data on behalf of other organizations, has turned it into a high-value ransomware target. The EY vendor breach that exposed tax data earlier in 2026 followed a similar pattern. A professional-services firm holding client data became the point of failure for organizations that had no direct security relationship with the attacker at all. So did the breach at One Medical, where the ShinyHunters group claimed to have stolen 8.8TB of data, and the Charter Spectrum breach that produced wildly disputed victim counts of its own.
How Security Vendors Are Responding
The enterprise security market is adjusting accordingly. Vulnerability management vendors compared in this breakdown of Tenable, Qualys, and Rapid7’s competing platforms have leaned harder into third-party and vendor risk scoring, rather than just scanning an organization’s own network perimeter. Endpoint detection vendors are making a similar pitch. The head-to-head results in this comparison of CrowdStrike, Microsoft Defender, and SentinelOne show all three vendors now market ransomware-specific detection as a headline feature, a direct response to SafePay-style attacks like the one that hit Conduent. None of these tools would have stopped a breach that started with stolen credentials or an unpatched flaw being exploited before a fix existed. They’re increasingly positioned as the second line of defense once an attacker is already inside a vendor’s network.
Historical Context: A Decade of Escalating Healthcare Data Breaches
This breach lands inside a much longer trend line. The HHS OCR breach portal, which has tracked healthcare data breaches since 2009, now shows more than 1 billion cumulative breach records tied to US healthcare entities and their vendors, per the agency’s own public reporting tool. Anthem’s 78.8 million-person breach in 2015 was treated as a watershed moment for the industry at the time. Nine years later, Change Healthcare’s 192.7 million-person breach was more than double that size. Now Conduent has added a third mega-breach to the list within a single two-year stretch.
That progression suggests the industry hasn’t found an effective ceiling on breach size. Larger data-processing contracts, continued consolidation among healthcare vendors, and ongoing reliance on decades-old back-office systems all point toward further growth rather than a plateau. Insurance industry researchers have tracked a version of the same climb from a different angle entirely, looking at overall compromise counts instead of any single incident.
Expert Perspective: What the Data Says About Breach Notification Trends
Federal survey data backs up what the Conduent numbers suggest anecdotally. The Bureau of Justice Statistics found that “in 2021, 12% of all persons age 16 or older were notified that an entity with their personal information experienced a data breach in the prior 12 months,” a share that has almost certainly grown as incidents on the scale of Conduent’s have piled up in the years since. The same report found that “victims of identity theft (24%) were twice as likely as nonvictims (11%) to learn that an entity with their personal information experienced a data breach in the past year,” a pattern that lines up with what security researchers already suspect. Once a person’s data circulates in one breach, it tends to resurface in the fallout from the next one too.
The trend line was already climbing before 2026 started. Triple-I, the insurance industry’s research arm, noted that “according to the Identity Theft Resource Center (ITRC) Annual Data Breach Report, 2024 had the second-highest number of data compromises in the U.S. in a single year since the ITRC began tracking data events in 2005.” Six months into 2026, this year’s pace suggests that record isn’t going to last much longer.
What This Means for the 62 Million People Affected
For the people whose data was part of the Conduent breach, the practical risk doesn’t disappear once the news cycle moves on. Security researchers generally recommend three steps after any breach involving Social Security numbers: placing a fraud alert or credit freeze with the three major credit bureaus, enrolling in whatever credit monitoring the breached company offers, and watching for phishing attempts that reference real account or claims details pulled from the stolen data.
That last risk is often underestimated. Attackers who obtain medical and insurance information can craft phishing emails that look like legitimate claims correspondence, and those are far more convincing than a generic scam message. Enabling phishing-resistant authentication wherever it’s offered closes off one of the most common paths attackers use once they have enough personal data to impersonate a trusted contact convincingly. The tradeoffs between different login methods, covered in this comparison of passkeys, passwords, and two-factor authentication, are a reasonable starting point for anyone deciding how to lock down accounts tied to the exposed information.
5 Predictions for Data Breach Disclosure Through the Rest of 2026
- More victim-count revisions are coming. Conduent’s estimate grew nearly sixfold across three separate disclosures, and other companies still finishing state-by-state reviews are likely to follow the same pattern before the year is out.
- Ransomware groups keep targeting business-process outsourcers over individual companies. The “one breach, many downstream clients” math produces bigger payouts than attacking a single organization directly.
- Full-year 2026 compromise totals will likely exceed the 3,600 pace the ITRC’s first-half data already points toward, making 2026 one of the busiest years on record for breach disclosures.
- Business associates handling healthcare data face more direct regulatory scrutiny. HIPAA’s liability provisions apply to vendors like Conduent just as much as they apply to insurers and hospitals.
- Enterprise adoption of vendor risk monitoring keeps expanding alongside traditional endpoint security, as companies try to gain visibility into the vendors now representing their single biggest source of breach exposure.
FAQ: Conduent Data Breach Questions Answered
What is the Conduent data breach?
It’s a ransomware attack against Conduent, a New Jersey-based government and business process outsourcing company, that exposed the personal and health information of 62,224,658 people. Conduent discovered the intrusion on January 13, 2025, and filed its final victim count with HHS OCR on June 4, 2026.
How many people were affected by the Conduent data breach?
The final confirmed figure is 62,224,658 individuals. That number grew from an initial estimate of about 10.5 million in October 2025, to 25 million in February 2026, before reaching its current total in June 2026 as more states and corporate clients completed their reviews.
What data was exposed in the Conduent breach?
Confirmed data types include full names, dates of birth, home addresses, Social Security numbers, health insurance information, medical and claims data, and in some cases employment records processed through Conduent’s HR contracts.
When did the Conduent ransomware attack happen?
Attackers first accessed Conduent’s systems on October 21, 2024. The company discovered the intrusion 84 days later, on January 13, 2025. The SafePay ransomware group has been linked to the attack in reporting from multiple outlets.
Is Conduent facing lawsuits over the data breach?
Yes. More than 10 federal class-action lawsuits had been filed in the District of New Jersey by February 2026, and Texas Attorney General Ken Paxton opened a separate state investigation into the incident.
How does the Conduent breach compare to other major healthcare breaches?
It ranks third-largest in US healthcare data breach history, behind the 2024 Change Healthcare breach (192.7 million people) and the 2015 Anthem breach (78.8 million people), according to HHS OCR’s breach portal.
Why did the Conduent breach affect so many people who never used Conduent directly?
Conduent processes data on behalf of state governments, healthcare insurers, and large employers rather than serving consumers directly. Anyone whose Medicaid application, insurance claim, or HR record passed through a Conduent-run system was potentially exposed, regardless of whether they had ever heard of the company.
What should people affected by the Conduent breach do now?
Security researchers recommend placing a fraud alert or credit freeze with the major credit bureaus, enrolling in any credit monitoring Conduent offers, and watching closely for phishing messages that reference real claims or account details drawn from the stolen data.
![Conduent Data Breach Hits 62.2M: 3rd-Largest Ever [2026] Conduent Data Breach Hits 62.2M: 3rd-Largest Ever [2026]](https://tech-insider.org/wp-content/uploads/2026/08/conduent-data-breach-2026.webp)