Back to Exposure Report
Healthcare / Government Services June 4, 2026 (final count) United States

Conduent Business Services

First report: 10.5 million. February revision: 25.5 million. Final count: 62.2 million. The third-largest healthcare-linked breach in US history.

Social Security numbersMedical recordsHealth insurance dataMedicaid informationChild support recordsFood assistance dataToll collection records
1

What happened?

Between October 2024 and January 2025, the Safepay ransomware group infiltrated Conduent's network and maintained access for three months. They stole 8 terabytes of data including Social Security numbers, medical records, and government services information.

When Conduent filed its final breach update with HHS OCR on June 4, 2026, the number stood at 62,224,658 individuals—more than double the 25.5 million reported just four months earlier. The scope kept expanding as forensics continued.

2

What data was actually inside?

8 terabytes of data spanning multiple government programs. Social Security numbers. Medical records. Health insurance information. Medicaid data. Child support records. Food assistance information. Electronic toll collection details.

Conduent manages essential public services for numerous US states. The data represents a cross-section of Americans who interact with government benefit programs—not just healthcare patients, but citizens receiving any of dozens of services Conduent administers.

3

Who gets hurt and how?

62.2 million Americans. People on Medicaid. Families receiving child support payments. Individuals using food assistance programs. Drivers whose toll records passed through Conduent systems. The exposure spans government services that touch vulnerable populations.

SSN exposure combined with medical records enables comprehensive identity theft. Tax fraud. Medical identity fraud. Benefit fraud. The data types enable attackers to impersonate victims across government and financial systems—affecting people who often have the fewest resources to recover.

4

What did they think they were doing right?

Conduent is a major government services contractor. They handle compliance requirements for multiple state and federal programs. HIPAA for healthcare data. Security requirements for government contracts. Regular audits and assessments.

But Safepay maintained network access for three months. Quarterly security reviews don't catch intruders who arrive between assessment windows. The compliance framework was in place; the detection that matters—finding attackers before they extract 8 terabytes—failed.

5

What did they not know about their own data?

The number grew from 10.5 million to 25.5 million to 62.2 million. Each revision reflects additional data discovery during forensic investigation. Conduent kept finding more affected individuals because they kept discovering more data existed.

Government services contractors accumulate data across programs, states, and years. Medicaid records. Child support payments. Food assistance applications. Each program has its own data, its own retention requirements, its own historical accumulation. The 62.2 million represents the full scope of what Conduent actually held.

If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?

6

What does attribution look like the morning after?

Texas Attorney General Ken Paxton launched an investigation. Missouri demanded information Conduent couldn't provide. $25 million in response costs. Class action lawsuits multiplying. HIPAA breach notifications to 62.2 million individuals across multiple states.

Each state where Conduent operates has its own notification requirements, its own attorney general, its own potential enforcement actions. The regulatory response multiplies across every affected jurisdiction. Government contractors face scrutiny from the governments they serve.

7

What would have changed the outcome?

Comprehensive data inventory across all government programs—knowing what sensitive data existed where before attackers spent three months finding out.

The number shouldn't have grown from 10 million to 62 million during investigation. That expansion represents discovery, not the breach itself. Organizations that know their data inventory can assess breach scope immediately. The ones that don't spend months discovering what they actually held—while attackers already have it.

Conduent found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.