Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: Conduent incurred and accrued $25 million in notification-related non-recurring expenses and had disbursed that amount by March 31, 2026.
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Exposure of personal information in files associated with Conduent clients and their end users. [7][8]
Documented data types include:
- Financial account information — Reported by Texas; affected elements may vary by individual. [7][8]
- Payment card information — Credit or debit card information reported by Texas; affected elements may vary by individual. [7][8]
- Dates of birth — Reported by Texas; affected elements may vary by individual. [7][8]
- Names — Reported by Texas; affected elements may vary by individual. [7][8]
- Contact information — Postal addresses reported by Texas; affected elements may vary by individual. [7][8]
- Health insurance information — Reported by Texas; affected elements may vary by individual. [7][8]
- Clinical information — Medical information reported by Texas and Massachusetts; affected elements may vary by individual. [7][8]
- Social Security numbers — Reported by Texas and Massachusetts; affected elements may vary by individual. [7][8]
- Driver’s license numbers — Reported by Texas; affected elements may vary by individual. [7][8]
A cited record reports 12,784,367 individuals (Texans affected according to revised Texas report BR-0005045; regulator-reported and not independently verified; as of 2026-05-20). [7][8]
A cited record reports 72,066 individuals (Massachusetts residents in report 2026-150; jurisdiction scoped and non-additive to the national total; as of 2026-02-02). [7][8]
A cited record reports 62,486,662 individuals (Total individuals affected according to revised Texas report BR-0005045; regulator-reported, not independently verified, and not additive to jurisdiction-specific populations; as of 2026-05-20). [7][8]
As of May 11, 2026, Conduent said it knew of no release of the exfiltrated data on the dark web or otherwise publicly. [9]
Conduent said the disruption did not materially affect its operations. [9]
The threat actor exfiltrated files associated with a limited number of Conduent clients. [9]
Timeline
Activity began
Start of the unauthorized-access interval reported by Conduent.
[5]Documented activity ended
End of the unauthorized-access interval reported by Conduent.
[5]Discovery
Unauthorized access to a limited portion of Conduent’s environment and exfiltration of client-associated files.
[5]Public disclosure
Massachusetts report 2026-150.
[8]Public disclosure
Texas Attorney General public investigation announcement.
[10]Public disclosure
Publication date of revised Texas report BR-0005045.
[7]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Most United States lawsuits had been consolidated in the District of New Jersey, and plaintiffs filed a consolidated complaint on March 18, 2026. An unauthorized third party accessed a limited portion of Conduent’s network during the reported interval. Individual and regulatory notifications began in October 2025 and were substantially concluded by May 11, 2026. Conduent restored affected systems and returned to normal operations within days and, in some cases, hours. Conduent incurred and accrued $25 million in notification-related non-recurring expenses and had disbursed that amount by March 31, 2026. Conduent notified federal law-enforcement authorities. As of May 11, 2026, Conduent was responding to subpoenas, information requests, and investigations from government agencies and other stakeholders. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [5][9]
