The number that matters in this file is not the terabytes. It is 62,224,658 — the count of individuals Conduent Business Solutions ultimately reported to the Department of Health and Human Services, after a review that ran for more than a year across every client whose data the company held.
That places it behind only the 2024 Change Healthcare intrusion and the 2015 Anthem breach in the record of US healthcare data compromises. It reached that rank without Conduent being a hospital, an insurer, or a name most of the affected would recognise. The company processes benefits, payments and administrative work for state agencies and health plans. Its customers are institutions. Its exposure is people.
The Count Moved Four Times
Conduent has said it discovered in January 2025 that intruders had been inside parts of its network between 21 October 2024 and 13 January 2025, and that files containing protected health information were potentially taken. The SafePay group claimed the intrusion and said it removed around 8.5 terabytes.
What followed is the part worth studying. Early public estimates sat near ten million. Reporting through the first quarter of 2026 pushed the figure past twenty-five million. The filed total landed above sixty-two. None of those revisions indicate the intrusion grew; they indicate how long it takes a processor to work out whose records were in which archive.
The exposed fields, as described in the notifications, include names, Social Security numbers, dates of birth, health insurance policy numbers and medical information — the combination that makes identity remediation slow and expensive. Affected individuals were offered twelve months of credit monitoring.
The Business-Associate Problem
A person whose data moved through Conduent had no opportunity to evaluate Conduent. They chose a health plan, or they qualified for a state benefit. The processor was selected by the institution, under a contract they never saw, and the notification arrived from a company they have no memory of dealing with.
This is the structural reason business-associate breaches keep topping the annual tables. Concentration is efficient. It is also why a single intrusion at a company with no consumer brand can put more people at risk than a year of hospital ransomware.
We are not treating the 8.5-terabyte figure as established. It originates with the group that claimed the attack, and we have not seen it corroborated by the company. The 62.2 million figure is different: it comes from Conduent’s own regulatory filing, and it is the number the desk will cite.
This file is compiled from public reporting and regulatory disclosure, listed below. We did not review the exfiltrated data and we have not independently verified the actor’s volume claim. Where a figure originates with the attacker rather than the company, the text says so. Corrections: corrections@forensicpost.com.