SYS::ONLINE
Wasteland.
Briefs1605
Issues21
SinceFeb 2026
LIVE
▣ Breach CONDUENT-DATA-BREA 2026-07-30

Conduent: SafePay Ransomware Data Theft at Scale

"A ransomware intrusion at Conduent Business Services, the New Jersey based business process outsourcing firm that handles claims, payments and correspondence for health plans and state benefit agencies, has become one…"

A ransomware intrusion at Conduent Business Services, the New Jersey based business process outsourcing firm that handles claims, payments and correspondence for health plans and state benefit agencies, has become one of the largest data breaches in U.S. history. The victim count has moved repeatedly. Conduent's early disclosures put the impact at roughly 10 million to 10.5 million people, a baseline that TMC Insight attributes to a September 2025 SEC statement and HIPAA Journal reporting. By February 2026, state attorney general filings had confirmed at least 25 million people across just two states, with Mashable reporting about 15 million in Texas and more than 10 million logged by the Oregon Department of Justice. Multiple outlets, including Paubox, Breached.Company, Sentinel and The Financial Wire, now report that Conduent filed a consolidated figure of 62,224,658 affected individuals with the HHS Office for Civil Rights on June 4, 2026. Treat the 25 million number as a floor confirmed by state regulators and the 62.2 million number as the aggregated federal filing reported by secondary press. Texas Attorney General Ken Paxton has called it the largest data breach in U.S. history, per The Financial Wire.

What Happened

The intrusion window is consistent across every source: attackers accessed Conduent's network on October 21, 2024 and remained until the company detected them on January 13, 2025, a dwell time of roughly three months. Conduent disclosed the incident in an April 9 SEC filing described by The Financial Wire as characterizing unauthorized access to a "limited portion" of its environment, with exfiltrated files tied to a limited number of clients containing a "significant number" of individuals' personal information. TMC Insight notes the January 2025 attack also caused operational disruption to administrative services across multiple states, not just data theft.

The scope grew because Conduent is a processor sitting beneath dozens of covered entities, each of which had to independently determine whose records were in the stolen files. Breached.Company, which has tracked the incident since late 2025, describes the progression as 10.5 million in November 2025, a climb past 25 million through February 2026 state filings, and 62,224,658 in the consolidated June filing, nearly a sixfold expansion over eight months. Paubox reports Conduent submitted an initial HHS OCR entry in October 2025 with a placeholder figure, then state filings progressively revealed larger totals: 10.5 million in Oregon and 15.5 million in Texas.

State-level figures should be read with care. Oregon DOJ lists roughly 10.5 million affected residents against a state population of about 4.9 million, and TMC Insight reports Conduent has not explained that discrepancy. Texas counts also differ slightly between reports, ranging from about 15 million (Mashable) to 15.4 million (PrivacyOn) to 15.5 million (Paubox). The likeliest explanation is that state filings reflect records or notification obligations rather than unique residents, but no source confirms that, so the arithmetic across states does not cleanly sum.

What Was Taken

Conduent's own notice, as cited by Mashable, lists names, Social Security numbers, medical information and health insurance information. Sentinel and PrivacyOn additionally report Medicaid claims data, and The Financial Wire says the Texas Attorney General's office confirmed that Texas residents' protected health information, including Medicaid recipients' data, was accessed. TMC Insight reports a later SEC filing detailing Social Security numbers, patient records and health insurance information.

On volume, the SafePay ransomware group claimed responsibility and asserted it exfiltrated multiple terabytes. Breached.Company, Sentinel and PrivacyOn all put the figure at 8.5 TB; Paubox, citing Cybersecurity Dive, says only "multiple terabytes." The 8.5 TB claim originates with the threat actor and has not been independently confirmed by Conduent in any source here.

Affected clients named across sources include Humana, Blue Cross Blue Shield plans in Texas, Illinois, New Mexico and Montana, and Premera Blue Cross. Mashable, citing NJ.com, lists Humana and the Illinois, New Mexico and Texas Blue Cross plans; Paubox adds Premera and Montana. PrivacyOn reports that Conduent's government program footprint spans Medicaid, SNAP and child support disbursement, meaning benefits recipients are disproportionately represented.

Why It Matters

This is a processor breach, not an insurer breach, and that distinction drives the blast radius. One intrusion at a vendor propagated to dozens of downstream organizations whose members never had a direct relationship with Conduent and in most cases had never heard of it. Breached.Company puts the 62.2 million figure at roughly one in five Americans.

If the federal filing holds, the ranking reported by Paubox, Breached.Company and Sentinel places Conduent third among U.S. healthcare breaches, behind the 192.7 million record Change Healthcare breach of 2024 and the 78.8 million record Anthem breach of 2015. Two of the top three are now clearing houses and processors rather than care providers or insurers, which is the structural lesson for defenders: concentration risk in the administrative layer of healthcare now exceeds that of most individual health systems.

The exposed data is also non revocable. Social Security numbers, medical histories and Medicaid enrollment cannot be reissued the way a payment card can, and The Financial Wire argues Medicaid recipients are least equipped to monitor credit or absorb identity theft losses. Conduent's dual role as commercial insurance processor and state Medicaid contractor means single files can combine private membership rolls with public benefits records.

The disclosure timeline is drawing its own scrutiny. Sentinel reports individual notifications did not begin until late October 2025, roughly nine months after detection. LegalClarity reports dozens of class actions consolidated into a single federal case in New Jersey, heading toward mediation with no settlement as of mid 2026, a separate Montana suit against Health Care Service Corporation, and investigations by HHS OCR and state regulators including Texas and Missouri. The Financial Wire reports Paxton issued formal demands to both Conduent and Blue Cross Blue Shield of Texas.

The Attack Technique

Initial access vector is not established in any of these sources. What is documented is the outcome pattern: a three month undetected foothold followed by mass exfiltration, consistent with SafePay's double extortion tradecraft of dwelling, staging and stealing bulk data before deploying encryption or issuing extortion demands. SafePay's public claim of responsibility and its multi terabyte exfiltration assertion are the actor's own statements. Note that TMC Insight renders the group name as "SAFEEPAY," which appears to be a transcription artifact rather than a distinct actor.

No source in this set names an exploited CVE, a phishing lure, a compromised credential set or a specific lateral movement technique. Anyone modelling this intrusion should treat the entry point as unknown and plan around the observable: an adversary that held access to a document processing environment for approximately 84 days and moved 8.5 TB out of it without triggering a detection that stopped them.

What Organizations Should Do

Sources: Conduent data breach already one of largest in U.S. history ... | Conduent breach hits 62M, ranking third largest in US healthcare hi... | 10.5 Million Became 62.2 Million: Conduent Is Now the Third-Largest... | Conduent Breach Hits 62 Million in Healthcare Data Theft | Conduent Expands Scope of 2025 Ransomware Breach as Notifications C... | A breach at Conduent exposed the Social Security numbers of more th... | What to Do After the Conduent Data Breach PrivacyOn PrivacyOn | Conduent Data Breach Class Action Lawsuit: Status and Updates - Leg...