Monday, August 3, 2026

Markets & Business

Conduent data breach impacts millions more than initially reported

A data breach at government technology contractor Conduent appears to affect millions more people than first disclosed, with at least 15.4 million victims in Texas alone.

Conduent data breach impacts millions more than initially reported
Photo: Conduent

A data breach at Conduent, a government technology contractor, appears to affect significantly more people than the company initially disclosed. The security incident stems from a January 2025 ransomware attack that compromised the company’s systems. According to updated disclosures, the breach affects at least 15.4 million people in Texas alone. This figure represents an increase from the previous estimate of 4 million affected individuals in Texas, which Conduent had provided in October. The company first disclosed the cyberattack in April, several months after the initial breach occurred, indicating a prolonged timeline between the incident and the full realization of its scope.

The impact of the data breach extends well beyond Texas, highlighting the broad geographic reach of the contractor’s operations across the United States. In Oregon, official records show that 10.5 million people are affected by the breach. Conduent has also sent out data breach notifications to residents in Delaware, Massachusetts, and New Hampshire. Because Conduent provides technology and operational support services that reach more than 100 million people in the United States, the potential scope of the exposure is broad. When contacted regarding the incident, Conduent spokesperson Sean Collins did not confirm whether the total number of affected individuals across the United States exceeds that 100 million threshold, nor did he clarify the exact number of notifications sent to date.

Responsibility for the ransomware attack has been claimed by the Safeway ransomware gang, a cybercriminal group that claims to have stolen over 8 terabytes of data from Conduent’s systems. In a subsequent regulatory filing with the SEC (the U.S. Securities and Exchange Commission), Conduent acknowledged the exposure. The company stated that the stolen datasets “contained a significant number of individuals’ personal information associated with our clients’ end-users.” Conduent is continuing to conduct a detailed analysis of the affected files to identify the personal information taken in the breach. The company is continuing to notify individuals whose data was stolen, a process it plans to finish by early 2026, though it has not provided a more specific timeline.

Why it matters

The data breach at government technology contractor Conduent has expanded significantly, highlighting the scale of the incident for a government contractor and the vulnerability of personal data held by third-party service providers.