The Conduent Data Breach Timeline: 84 Days Undetected, 4 Million to 62.2 Million Victims

The Conduent data breach is the third-largest healthcare data breach ever posted to the federal government's breach portal, and it got there in stages. Attackers linked to the SafePay ransomware group were inside Conduent's network for 84 days before anyone noticed. The first public count, filed with the Texas attorney general in October 2025, covered about 4 million Texans. By June 4, 2026, the figure Conduent reported to the U.S. Department of Health and Human Services was 62,224,658 people. The gap between those two numbers, and the nineteen months it took to close, is the story, and it is a fair preview of how most large breaches unfold.

How the Conduent data breach happened

Conduent is a New Jersey-based business process outsourcer. It prints and mails documents, processes claims and payments, and runs back-office systems for health plans, state Medicaid programs and large employers. Almost nobody is a Conduent customer directly, which is why a breach of this size took so long to register with the public: the names on the notification letters were Blue Cross Blue Shield of Texas, Blue Cross Blue Shield of Montana, Humana, Premera and state benefits agencies, with Conduent as the vendor behind them.

According to Conduent's 8-K filed with the SEC on April 14, 2025, the company discovered on January 13, 2025 that a threat actor had gained access to a portion of its environment, after an operational disruption that day. The forensic work later placed the start of the intrusion at October 21, 2024, an 84-day window. The filing confirms the attacker exfiltrated files associated with a limited number of clients, containing "a significant number of individuals' personal information associated with our clients' end-users," and says that as far as Conduent knew the data had not been published.

SafePay, a ransomware group that surfaced in late 2024, claimed the attack in February 2025 and said it held 8.5 terabytes of Conduent data. HIPAA Journal notes that Conduent has since disappeared from the group's leak site, which usually means a deal or a decision not to publish, and neither has been confirmed.

What was taken, and who it actually affects

The data elements in the notices are names, addresses, dates of birth, Social Security numbers, health insurance details and medical claims information, including diagnosis and treatment codes. SSN plus medical claims plus home address is close to the worst-case combination for both financial and medical identity theft.

Because Conduent worked for insurers and state programs, the affected people are the members and beneficiaries of those clients: Medicaid recipients in Texas, Blue Cross members in several states, and employees of companies whose benefits Conduent administered. If you never heard the company's name before a letter arrived, that is normal. The exposure follows the data, not the brand on your insurance card.

Conduent data breach timeline: how 4 million became 62.2 million

  • October 21, 2024. Intrusion begins, per Conduent's later forensic findings.
  • January 13, 2025. Conduent detects the intrusion during an operational disruption and takes systems offline.
  • In February 2025, SafePay lists Conduent on its leak site and claims 8.5 TB.
  • April 14, 2025. Conduent's 8-K confirms exfiltration of files holding a "significant number" of individuals' data. No count is given.
  • October 2025. First individual notifications go out. The Texas attorney general's breach portal shows about 4 million Texans; on October 28, Oregon's regulators are told 10,515,849 of its residents are affected.
  • On December 22, 2025, with at least nine class actions already filed in the District of New Jersey, Judge Michael A. Hammer appoints an eight-member Plaintiffs' Steering Committee in In re: Conduent Business Services Data Breach Litigation.
  • February 2, 2026. Texas updates its portal entry to 15,494,592 residents, roughly half the state. A Wisconsin filing and the other state totals push the running national count past 25 million, as Malwarebytes tallied on February 26.
  • Ten days later, on February 12, Texas Attorney General Ken Paxton issues civil investigative demands to Conduent and Blue Cross Blue Shield of Texas, calling it "likely the largest breach in U.S. history." His own release still cites the old figure of "approximately four million Texans," ten days after the state's portal had moved to 15.5 million.
  • On May 12, 2026, Missouri's Department of Commerce says publicly that Conduent has not provided the information the state's own breach investigation requires, per HIPAA Journal.
  • June 4, 2026. Conduent files its updated total with HHS: 62,224,658 individuals. On the HHS breach portal only Change Healthcare (192.7 million, 2024) and Anthem (78.8 million, 2015) are larger.

From the first day of the intrusion to the final count is more than nineteen months. From detection to final count is nearly seventeen.

Why the number surfaced in pieces

The jump from 4 million to 62.2 million was not Conduent hiding a number and then confessing. It is what U.S. breach disclosure produces by design.

There is no single federal law that forces one clean total. Each state has its own thresholds and its own attorney general portal, and each filing counts only that state's residents. HIPAA adds a federal filing for health data, but a business associate like Conduent can post an initial figure and amend it as the review of exfiltrated files continues. So Texas reported Texans, Oregon reported Oregonians, and the Texas number itself nearly quadrupled once the client-by-client review reached more files. None of those filings was wrong when made. They were partial, and the only place they added up was the HHS portal, nineteen months after the attackers got in.

There is a second reason the number lagged, and it is specific to vendor breaches. Conduent did not know whose data it held in the way a hospital knows its patients. It held files for clients, and each client had to be matched to its own members before anyone could be counted or notified. That is why the letters came from Conduent but named an insurer, and why some people received two.

What Conduent is offering, and what to do now

If you received a letter, it came from Conduent on behalf of a named client and offered credit monitoring and identity restoration through Kroll; Blue Cross Blue Shield of Texas's employer notice describes the arrangement, and HIPAA Journal reports the term as 12 months. The enrollment deadline is printed on the letter and differs by mailing batch; several batches' deadlines have already passed, so if yours has, skip to the steps below, which do not depend on Conduent.

  1. Freeze your credit at all three bureaus. It is free and takes a few minutes each: Equifax, Experian and TransUnion. A credit freeze stops new accounts being opened with your SSN; you lift it temporarily when you apply for something yourself.
  2. Read every Explanation of Benefits. The FTC's medical identity theft page lists the signs: a bill or EOB for care you did not receive, a collector chasing a medical debt you do not owe, a notice that you have hit a benefit limit. Report errors to the provider and the insurer in writing.
  3. If you or a family member is on Medicaid or Medicare, report suspected misuse to HHS-OIG at 1-800-HHS-TIPS or through its fraud reporting page. Medicaid IDs are a credential for billing government programs, and they are watched far less closely than credit cards.
  4. If anything does go wrong, file at IdentityTheft.gov. It generates the affidavit and recovery plan that banks, bureaus and providers accept.
  5. Keep watching past the monitoring window. An SSN does not expire. Fraud tied to breaches of this size tends to show up when someone finally uses the credential, often a year or more later, and 12 months of monitoring will not cover that.

Where the data goes next

Stolen files are not the only place your information sits after a breach. The people-search sites publish the parts of a record that make a scam call convincing (current and past addresses, age, relatives, phone numbers) to anyone, for free, and they publish them whether or not you were ever breached. In our removal work, PeopleSearchNow shows that whole set on its free preview page before asking for anything. Someone holding your SSN from the Conduent files and your address history from a preview page has everything a caller needs to "verify" they are from your insurer.

The other lesson comes from a broker breach, not a vendor one. National Public Data lost an estimated 270 million Social Security numbers in 2024, went bankrupt, and came back online in 2025 under new ownership as a free people-search engine. Opting out of the relaunched site removes today's listing; it does nothing about what left with the hackers. The same applies here. Freezing your credit handles the SSN. Getting your address history and relatives off the people-search layer is a separate job, and our data broker opt-out guide covers it site by site.

Delist My Data is being built for that second job: finding your listings across the people-search sites and re-filing when they regenerate. We're in pre-launch; join the waitlist for founding-member access.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.