2026 Volvo Group North America — Conduent HR/benefits supplier intrusion (Oct 2024–Jan 2025); ~17k US individuals
Data compromised
Employee benefits, insurance identifiers, and associated demographic fields
Technical writeup
Conduent, a benefits and document-services outsourcer, told clients it discovered January 13, 2025 network activity stretching back to October 21, 2024, with SafePay ransomware marketing tied to the leak cluster. Volvo Group North America subsequently confirmed to Maine regulators that 16,991 US persons—mostly benefits enrollees—needed notification for SSNs, DOBs, and health-plan metadata handled inside Conduent workflows. The Register unpacked the lag between vendor discovery and OEM-specific tallying, illustrating systemic fourth-party latency risks for `volvo-group` pages.
Root cause
Long-dwell ransomware/extortion operation against HR outsourcer serving multiple Fortune‑500 clients