Data Breach

Conduent Data Breach: What Happened and What to Do Now

Share
Conduent data breach - abstract secure document vault with shield outline and a small group of exposed files
Editorial illustration of protected digital records with a small group of exposed files.

In short

The Conduent data breach involved unauthorized access to files between October 21, 2024, and January 13, 2025. As of October 6, 2026, Wisconsin’s breach registry lists 25+ million people affected. If you received a notice, verify it independently, freeze credit when sensitive identifiers are involved, and watch accounts for misuse. SEC filing Wisconsin breach registry

Quick answer: The Conduent data breach involved unauthorized access to files between October 21, 2024, and January 13, 2025. As of October 6, 2026, Wisconsin’s breach registry lists 25+ million people affected. If you received a notice, verify it independently, freeze credit when sensitive identifiers are involved, and watch accounts for misuse.

Table of Contents
  1. What happened in the Conduent data breach?
  2. Why do reports use different affected-person totals?
  3. What information may have been exposed?
  4. Is a Conduent data breach notice legitimate?
  5. What should you do after a Conduent breach notice?
  6. What is happening with Conduent data breach lawsuits?
  7. What else do people ask about the Conduent data breach?
  8. What should you remember first?

What happened in the Conduent data breach?

Abstract secure document system with one highlighted group of accessed files
The incident involved files associated with Conduent client services, not necessarily a direct account relationship with every affected person.

Conduent said it discovered an operational disruption and unauthorized access to a limited part of its environment on January 13, 2025. A client substitute notice says the unauthorized party accessed Conduent’s environment between October 21, 2024, and January 13, 2025, and obtained certain files containing protected health information. Conduent’s April 2025 SEC filing Client substitute notice

Conduent’s SEC filing says the files were associated with a limited number of clients, but contained personal information relating to a significant number of those clients’ end users. The company said it engaged cybersecurity data-mining experts to assess the exfiltrated files, notified law enforcement, and continued working with clients on legally required notices.

The key point is that Conduent is a service provider. A person may receive a notice because a health insurer, employer, government benefit program, or other organization used Conduent for back-office services, even if that person has never knowingly opened an account with Conduent.

Why do reports use different affected-person totals?

There is no single public number that fully explains the Conduent data breach across every client, state, and notification round. The official records reviewed for this guide range from client-level notices to a Wisconsin registry entry listing 25+ million affected people nationwide. Wisconsin breach registry

That difference does not automatically mean one report is false. It more likely reflects different reporting dates, different client populations, and the distinction between people covered by a notification process and people represented in one client’s notice. This is an inference from the records, not a confirmed explanation from Conduent.

The Wisconsin registry lists names, addresses, dates of birth, Social Security numbers, health insurance details, and medical information among the data accessed, while noting that the information varied by person. Texas Attorney General Ken Paxton’s office said in February 2026 that its investigation concerned sensitive data of approximately four million Texans, including protected health information. Wisconsin breach registry Texas attorney general notice

Treat a headline total as context, not as a substitute for reading the information listed in your own notice.

What information may have been exposed?

Illustration of personal profile, health insurance card, and protected medical file icons
The information potentially involved varied by individual and notice recipient.

The information potentially exposed varies by person and by the organization connected to the notice. A client substitute notice lists contact information, date of birth, Social Security number, health-plan member ID, and treatment-payment amount among the possible data elements. Client substitute notice

That matters because the right response depends on the specific information named in your letter. A notice involving only contact details calls for a different level of urgency than one naming a Social Security number, health insurance ID, or financial information.

Public notices reviewed for this guide do not list passwords among the potentially accessed data elements. Still, do not assume that a breach notice eliminates account risk. Personal details can make phishing messages more convincing, especially when scammers know a recipient’s name, insurer, employer, or partial identifying information.

One client substitute notice said Conduent was not aware of misuse of the relevant data when that notice was published. That statement is not proof that misuse has never happened, and it does not replace checking your own accounts. Client substitute notice

Is a Conduent data breach notice legitimate?

A Conduent-related breach notice can be legitimate, but a letter, email, text, or phone call should not be trusted solely because it uses a recognizable company name. California’s attorney general maintains a submitted sample notice for Conduent Business Services, LLC that identifies the October 21, 2024, to January 13, 2025 incident window. California attorney general sample-notice record

Use independent checks before entering personal information or activating any service. The Federal Trade Commission advises people not to click links in unexpected messages and to contact an organization through a phone number, email address, app, or website they already know is genuine. FTC phishing guidance

Use these four checks:

A breach letter can be authentic and still be followed by fake messages that copy its language. Treat any pressure to pay, disclose a password, provide a one-time verification code, or give remote computer access as a warning sign.

What should you do after a Conduent breach notice?

Locked credit file beside a verified notice and secured email account
The highest-priority actions depend on the sensitive information named in the notice.

Start with the information actually listed in your notice, then take the protective steps that match that information. If your Social Security number or similar high-risk identifier was involved, a credit freeze is one of the strongest actions available because it makes it harder for someone to open a new credit account in your name. FTC credit-freeze guidance

A credit freeze is free, does not affect your credit score, and stays in place until you lift it. You must contact Equifax, Experian, and TransUnion separately to place a freeze, and you will need to temporarily lift it when a legitimate lender needs access to your report. FTC credit-freeze guidance

Use this response checklist:

The best response is not panic or blanket password resets. It is a documented, proportionate plan based on the exact data named in your notice.

What is happening with Conduent data breach lawsuits?

Multiple lawsuits brought by people who allegedly received Conduent notification letters were consolidated in the U.S. District Court for the District of New Jersey. Conduent’s second-quarter 2026 filing says plaintiffs filed an amended consolidated complaint on June 12, 2026, and that the litigation was stayed through September 7, 2026, while the parties explored a potential resolution. Conduent’s Q2 2026 Form 10-Q

The same filing says Conduent denies the plaintiffs’ allegations, says it believes it has strong defenses, and cannot predict the outcome. The filing did not announce a settlement or a consumer payout, so do not rely on posts or advertisements claiming a confirmed payment amount without checking current court documents.

Separately, the Texas attorney general announced an investigation on February 12, 2026, and said its office had requested documents from Conduent and Blue Cross Blue Shield of Texas. An investigation is not a finding of liability, but it is a reason to watch official updates rather than rumor-driven posts. Texas attorney general notice

What else do people ask about the Conduent data breach?

What are the top 10 data breaches of all time?

There is no single official top-10 ranking that resolves every breach because organizations and regulators report different populations and data types at different times. Wisconsin lists the Conduent incident as affecting 25+ million people, while Texas described it as likely among the largest U.S. breaches. Those statements do not create one definitive ranking. Wisconsin breach registry Texas attorney general notice

Is Conduent Notice of data breach legit?

A Conduent notice may be legitimate, and California’s attorney general has a submitted sample notice for the October 2024 to January 2025 incident. Still, verify any notice through an independently found official channel before entering personal details, using an activation code, or calling a number from an unexpected email or text. California attorney general sample-notice record FTC phishing guidance

What is a Conduent?

Conduent is a business-services provider that supports commercial and government clients. Wisconsin’s breach registry says Conduent operates back-end systems for state programs, including Medicaid claims and eligibility systems, child-support payments, food assistance, and unemployment insurance. That service-provider role explains why a recipient may recognize a client organization but not Conduent itself. Wisconsin breach registry

What is the average payout for a data breach?

There is no verified Conduent payout figure in the latest company filing reviewed for this article. Conduent’s second-quarter 2026 filing says the consolidated litigation was paused while parties explored a potential resolution and that the company could not predict the outcome. Treat any claimed average payout as non-incident-specific unless a court-approved settlement states otherwise. Conduent’s Q2 2026 Form 10-Q

What should you remember first?

Read the data elements named in your own notice, verify the notice through an independent official channel, and freeze your credit if high-risk identifiers such as a Social Security number were involved. For ongoing official-source reporting on security incidents, follow Veritya Daily’s data breach coverage.

Sources

J

Jai

Jai covers consumer cybersecurity and data-breach response at Veritya Daily. He reads the SEC filings, state registries and regulator guidance so you can act on the notice in your mailbox with confidence.

Read Next