Notice of potential personal information exposure due to Conduent data breach

More than 10 million individuals have been notified by Conduent, a business services provider, regarding a significant data breach that occurred in January. This breach allowed hackers to gain unauthorized access to the company’s servers, resulting in the compromise of personal information belonging to a large number of people. Conduent offers various services, including medical billing, automatic fee collection, and Medicaid screening, for both companies and government agencies.

The data breach incident unfolded in January 2025 when Conduent experienced a service disruption impacting government agencies across multiple states. Following this incident, Conduent revealed to the Securities and Exchange Commission that malicious actors had infiltrated their network, gaining access to sensitive personal information. The hackers managed to breach the network on October 21, 2024, but it wasn’t until January 13, 2025, that they were discovered and subsequently expelled from the system.

Reports from the Oregon state government revealed that over 10.5 million individuals had their personal data compromised in the cyberattack. This breach ranks as the eighth-largest healthcare data breach globally, as reported by HIPPAJournal.com, a medical service-related information provider.

Conduent has commenced the process of notifying the impacted individuals regarding the breach, informing them that their private information had been subject to unauthorized access by threat actors. Additionally, the company sent out notices to state Attorneys General to prepare them for the impending communication with thousands of residents affected by the incident.

During the approximate three-month period that the hackers had access to Conduent’s network, they managed to extract various files containing personal data of individuals who had utilized the company’s services. Information compromised in the breach includes names, addresses, dates of birth, Social Security numbers, health insurance particulars, and medical data.

Conduent has decided not to provide identity theft protection services to the victims of the data breach. Instead, they advise affected individuals to obtain a free credit report and implement credit freezes as a precautionary measure. The company, in its communication to the impacted users, expressed their commitment to addressing the incident promptly by restoring systems and alerting law enforcement. Moreover, they encouraged recipients to consider further protective actions to safeguard their private information.

Thus far, there have been no reported instances of the compromised data being utilized for fraudulent activities post the breach, according to Conduent’s statement. The company continues to closely monitor the situation and remain vigilant for any signs of fraudulent activity.