← Conduent Business Services

2025 Conduent Business Services — confirmed breach; 62.2M+ PHI (HHS OCR); SafePay ransomware

2025 62.2M records affected Share on X

Data compromised

Varies by client and individual: names, dates of birth, addresses, Social Security numbers, treatment information, claims information, and health insurance details per state AG filings and company notices; 62,224,658 individuals per HHS OCR update reported June 2026

Technical writeup

Verified HIPAA business-associate breach — Conduent Business Services, a Conduent Inc. unit providing printing, mailing, document processing, and payment-integrity services to major U.S. health insurers and government agencies, discovered unauthorized access on January 13, 2025. Forensics placed initial compromise on October 21, 2024, with roughly three months of dwell time before containment. Conduent disclosed via SEC Form 8-K (April 2025) that a threat actor exfiltrated files containing customer information and data from those customers' members. The SafePay ransomware group claimed responsibility in February 2025, advertising 8.5 terabytes stolen; Conduent later dropped from the leak site. Victim notifications began October 2025—nearly a year after first access—with state attorney general tallies climbing from ~10.5 million (Oregon filing) to 25 million+ and then 62,224,658 individuals per an updated filing to HHS Office for Civil Rights reported by HIPAA Journal (June 4, 2026). That count ranks third among U.S. healthcare breaches behind Change Healthcare (~192.7M, 2024) and Anthem (~78.8M, 2015). Known downstream clients include Humana, Premera Blue Cross, Blue Cross Blue Shield of Texas (15.49M+ Texans per Texas AG), Blue Cross Blue Shield of Montana (~462K), and others; Conduent offered to mail notices on clients' behalf. Texas AG Ken Paxton and Missouri Department of Commerce launched investigations in 2026; Missouri regulators accused Conduent of insufficient cooperation. Conduent said it found no evidence of public misuse of stolen data at reporting time and offered 12 months of credit monitoring to many affected individuals.

Root cause

Threat actor maintained access to Conduent Business Services network Oct 21, 2024–Jan 13, 2025; detected Jan 13, 2025; SafePay ransomware group claimed 8.5 TB exfiltration; SEC 8-K disclosed client and downstream customer data theft

References