Government technology company Conduent experiences major data breach, impacting millions more Americans
A significant data breach at the government technology giant Conduent reveals that the number of affected individuals is much higher than initially reported. The ransomware attack in January of 2025 disrupted Conduent’s operations for several days and has now been confirmed to impact approximately 15.4 million people in Texas, which makes up around half of the state’s population. This number is a significant increase from the previously disclosed 4 million affected individuals in the state.
Moreover, an additional 10.5 million people in Oregon have also been affected by the breach, according to the state’s attorney general. Data breach notifications reviewed by TechCrunch indicate that hundreds of thousands of people in Delaware, Massachusetts, New Hampshire, and other states have also been notified of their compromised information.
The stolen data includes sensitive details such as names, Social Security numbers, medical information, and health insurance data. As one of the largest government contractors in operation, Conduent is responsible for processing vast quantities of personal and confidential data on behalf of numerous large corporations, government agencies, and multiple states in the U.S. The company estimates that its technology and support services impact over 100 million individuals in the U.S. through various government healthcare programs.
However, when questioned about the extent of the breach, a Conduent spokesperson offered a general statement that did not address specific queries. The company did not confirm the total number of individuals affected by the cyberattack, nor did they provide details on the measures being taken to address the breach. They did reveal that efforts are underway to analyze the compromised files to identify the stolen personal information but did not disclose the total number of data breach notifications issued thus far.
In April, Conduent disclosed the cyberattack, which was carried out by the Safeway ransomware gang and resulted in significant disruptions to the company’s systems and services provided to various government entities. The stolen datasets reportedly contain substantial amounts of personal information belonging to the company’s clients and end-users, both corporate and governmental.
Conduent is actively communicating with individuals impacted by the breach and aims to complete the notification process by early 2026, without providing a precise timeline. The company remains tight-lipped about further details of the breach, leaving many questions unanswered. Should you have additional information on the Conduent cyberattack, you may contact Zack Whittaker through Signal or email for further discussion.