[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0FjCc1oHxY0ZkXZH0ipfJNef7myggDQjF6YDJQ79mlo":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66c6cae28e9bd82db7d8b4","Conduent2024","Conduent 2024 Data Breach","conduent-2024","conduent.com",{"name":12,"sector":13,"country":14,"website":10},"Conduent Business Services LLC","Technology","United States","2024-10-21T00:00:00.000Z","2026-07-27T02:47:38.557Z",62224658,[19,20,21,22,23,24],"Names","Dates of birth","Physical addresses","Social Security numbers","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The Conduent 2024 data breach\u003C\u002Fstrong> began when a threat actor entered the business-process and healthcare-services provider's network on October 21, 2024 and maintained access until January 13, 2025. Conduent confirmed in its SEC annual report that the attacker exfiltrated files associated with a subset of company clients and that the files contained substantial personal information tied to those clients' end users.\u003C\u002Fp>\n\u003Cp>The current breach list maintained by the US Department of Health and Human Services Office for Civil Rights shows 62,224,658 affected individuals for Conduent Business Services. pwnCount and totalRecords use the current figure in that single regulatory row. The incident involved data processed for health plans, healthcare organizations, and government agencies; LeakData imports none of the personal records.\u003C\u002Fp>\n\u003Ch2>How Was the Data Theft Confirmed?\u003C\u002Fh2>\n\u003Cp>Conduent's fiscal 2025 Form 10-K says the company experienced an operational disruption on January 13, 2025 and learned that a threat actor had gained unauthorized access to a limited part of its environment. Its investigation with outside cybersecurity specialists determined that the attacker exfiltrated files associated with a subset of clients. This disclosure moves the event beyond a mere possibility of access.\u003C\u002Fp>\n\u003Cp>The company said detailed analysis confirmed that the files contained a significant volume of personal information belonging to its clients' end users. HHS classifies the event as a Hacking\u002FIT Incident, the location as Network Server, and Conduent as a Business Associate. HIPAA Journal independently assembled the regulatory count and timeline, reporting that protected health information for more than 62.2 million people was compromised.\u003C\u002Fp>\n\u003Ch2>When Did the Unauthorized Access Occur?\u003C\u002Fh2>\n\u003Cp>The forensic investigation placed the threat actor in Conduent's network from October 21, 2024 through January 13, 2025. breachDate is October 21, the beginning of that verified window. The company discovered the event on the final access day, activated its response plan, and returned affected systems to normal operation within hours in some cases and days in others.\u003C\u002Fp>\n\u003Cp>Because the files were complex, Conduent engaged data-review specialists to identify the personal information they contained. Notifications to affected clients and end users began in October 2025, and the company told the SEC it expected them to conclude in early 2026. The HHS row retains an original submission date of October 8, 2025, while its current population reflects later scope updates.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>Publicly disclosed fields include names, dates of birth, mailing addresses, and Social Security numbers. Medical information and health-insurance information were also among the affected data types. Conduent provides back-office, document-processing, mailing, and payment-integrity services to many health plans, healthcare providers, and public programs, so the exact combination varied by client and person.\u003C\u002Fp>\n\u003Cp>Sources do not say every affected person had every category. They also do not establish that passwords, payment cards, bank accounts, email contents, or detailed prescription data were present for all 62,224,658 people. The data classes state the disclosed possible scope; client-level population counts and field mappings are not invented when they are not public.\u003C\u002Fp>\n\u003Ch2>What Does the Total of 62,224,658 Mean?\u003C\u002Fh2>\n\u003Cp>The open-investigation list at HHS OCR shows one Conduent Business Services LLC row with 62,224,658 individuals. It is a newer federal total than the interim figures of 10.5 million, 25 million, and other counts previously published in state notices. This record does not add those older figures together; it uses only the latest HHS value from the expanding review of the same event.\u003C\u002Fp>\n\u003Cp>Because Conduent is a business associate, some affected healthcare organizations may also have fulfilled notification duties separately. HIPAA Journal notes that the total could rise further, but LeakData does not estimate unconfirmed additional people. pwnCount and totalRecords remain 62,224,658 and can be reassessed if the HHS row changes again.\u003C\u002Fp>\n\u003Ch2>How Are Attacker and Publication Claims Treated?\u003C\u002Fh2>\n\u003Cp>Some reporting associated the event with the SafePay ransomware group, but Conduent did not confirm a group name or ransom payment in its SEC disclosure. The company said that, as of the end of 2025, its dark-web monitoring had found no evidence that personal information tied to the event had been released. That statement does not negate exfiltration, which Conduent confirmed separately and explicitly.\u003C\u002Fp>\n\u003Cp>LeakData therefore does not attribute the event to an unverified group or state a stolen volume or ransom amount. The established facts are roughly three months of unauthorized network access, exfiltration of client files, and personal information inside those files. A lack of detected dark-web publication does not eliminate the risks of identity fraud or misuse of healthcare information.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Conduent offered twelve months of complimentary credit monitoring to affected people. Notice recipients should verify the relationship with the health plan or institution named in the letter, review credit reports, and consider a security freeze if a Social Security number was involved. Unfamiliar services, claims, or providers in medical and insurance statements should be reported through the plan's official channel.\u003C\u002Fp>\n\u003Cp>Before using links in messages claiming to be from Conduent, a health plan, or a government agency, contact details should be obtained independently from an official source. Tax and public-benefit accounts can also be watched for unexplained changes. importedRecordCount is zero; LeakData does not store or publish names, addresses, birth dates, Social Security numbers, medical data, or insurance information.\u003C\u002Fp>","Unauthorized network access and confirmed exfiltration of client files",false,"Critical","completed","\u002Fuploads\u002Flogo\u002Fconduent_com.png"]