Desk live·
ForensicPost
Breaches/Third party/File 26-0731

Conduent Breach Affected More Than 62 Million People, Final Count Shows

Conduent processes benefits and payments on behalf of state agencies and health plans. Its final count puts the 2024–25 intrusion at more than 62 million people — the third-largest healthcare breach on record, at a company almost none of them have a relationship with.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetConduent Business Solutions
ActorSafePay
D. Kennedy11 min readConfidence: high3 sources reviewed

The number that matters in this file is not the terabytes. It is 62,224,658 — the count of individuals Conduent Business Solutions ultimately reported to the Department of Health and Human Services, after a review that ran for more than a year across every client whose data the company held.

That places it behind only the 2024 Change Healthcare intrusion and the 2015 Anthem breach in the record of US healthcare data compromises. It reached that rank without Conduent being a hospital, an insurer, or a name most of the affected would recognise. The company processes benefits, payments and administrative work for state agencies and health plans. Its customers are institutions. Its exposure is people.

The Count Moved Four Times

Conduent has said it discovered in January 2025 that intruders had been inside parts of its network between 21 October 2024 and 13 January 2025, and that files containing protected health information were potentially taken. The SafePay group claimed the intrusion and said it removed around 8.5 terabytes.

What followed is the part worth studying. Early public estimates sat near ten million. Reporting through the first quarter of 2026 pushed the figure past twenty-five million. The filed total landed above sixty-two. None of those revisions indicate the intrusion grew; they indicate how long it takes a processor to work out whose records were in which archive.

The exposed fields, as described in the notifications, include names, Social Security numbers, dates of birth, health insurance policy numbers and medical information — the combination that makes identity remediation slow and expensive. Affected individuals were offered twelve months of credit monitoring.

The Business-Associate Problem

A person whose data moved through Conduent had no opportunity to evaluate Conduent. They chose a health plan, or they qualified for a state benefit. The processor was selected by the institution, under a contract they never saw, and the notification arrived from a company they have no memory of dealing with.

This is the structural reason business-associate breaches keep topping the annual tables. Concentration is efficient. It is also why a single intrusion at a company with no consumer brand can put more people at risk than a year of hospital ransomware.

We are not treating the 8.5-terabyte figure as established. It originates with the group that claimed the attack, and we have not seen it corroborated by the company. The 62.2 million figure is different: it comes from Conduent’s own regulatory filing, and it is the number the desk will cite.

How we reported this

This file is compiled from public reporting and regulatory disclosure, listed below. We did not review the exfiltrated data and we have not independently verified the actor’s volume claim. Where a figure originates with the attacker rather than the company, the text says so. Corrections: corrections@forensicpost.com.

Sources
  1. Conduent Business Solutions data breach affected more than 62.2 million individualsHIPAA Journal
  2. Conduent breach hits 62M, ranking third largest in US healthcare historyPaubox
  3. The Conduent breach; from 10 million to 25 million (and counting)Malwarebytes
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary