---
title: "Conduent Business Services data incident"
description: "Evidence-backed account of Conduent Business Services data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/conduent-business-services-data-incident-2024"
markdown_url: "https://www.ally.security/incidents/conduent-business-services-data-incident-2024.md"
stix_url: "https://www.ally.security/incidents/conduent-business-services-data-incident-2024/stix.json"
---

# Conduent Business Services data incident

Unauthorized access to a limited portion of Conduent's environment and exfiltration of client-associated files. Exposure of personal information in files associated with Conduent clients and their end users.

Last modified Aug 9, 2026 · 10 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** Conduent incurred and accrued $25 million in notification-related non-recurring expenses and had disbursed that amount by March 31, 2026.

## What happened

Unauthorized access to a limited portion of [Conduent](https://www.conduent.com/)'s environment and exfiltration of client-associated files. [5](#source-5) [9](#source-9) [10](#source-10)

## Impact

Exposure of personal information in files associated with Conduent clients and their end users. [7](#source-7) [8](#source-8)

Documented data types include:

- Financial account information — Reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Payment card information — Credit or debit card information reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Dates of birth — Reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Names — Reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Contact information — Postal addresses reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Health insurance information — Reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Clinical information — Medical information reported by Texas and Massachusetts; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Social Security numbers — Reported by Texas and Massachusetts; affected elements may vary by individual. [7](#source-7) [8](#source-8)
- Driver's license numbers — Reported by Texas; affected elements may vary by individual. [7](#source-7) [8](#source-8)

A cited record reports 12,784,367 individuals (Texans affected according to revised Texas report BR-0005045; regulator-reported and not independently verified; as of 2026-05-20). [7](#source-7) [8](#source-8)

A cited record reports 72,066 individuals (Massachusetts residents in report 2026-150; jurisdiction scoped and non-additive to the national total; as of 2026-02-02). [7](#source-7) [8](#source-8)

A cited record reports 62,486,662 individuals (Total individuals affected according to revised Texas report BR-0005045; regulator-reported, not independently verified, and not additive to jurisdiction-specific populations; as of 2026-05-20). [7](#source-7) [8](#source-8)

As of May 11, 2026, Conduent said it knew of no release of the exfiltrated data on the dark web or otherwise publicly. [9](#source-9)

Conduent said the disruption did not materially affect its operations. [9](#source-9)

The threat actor exfiltrated files associated with a limited number of Conduent clients. [9](#source-9)

## Timeline

### October 21, 2024 — Activity began

Start of the unauthorized-access interval reported by Conduent. [5](#source-5)

### January 13, 2025 — Documented activity ended

End of the unauthorized-access interval reported by Conduent. [5](#source-5)

### January 13, 2025 — Discovery

Unauthorized access to a limited portion of Conduent's environment and exfiltration of client-associated files. [5](#source-5)

### January 2, 2026 — Public disclosure

First Conduent filing in the California Attorney General's 2026 directory. [2](#source-2) [6](#source-6)

### January 30, 2026 — Public disclosure

Additional Conduent filing in the California Attorney General's directory. [3](#source-3) [6](#source-6)

### February 2, 2026 — Public disclosure

Massachusetts report 2026-150. [8](#source-8)

### February 12, 2026 — Public disclosure

Texas Attorney General public investigation announcement. [10](#source-10)

### March 24, 2026 — Public disclosure

Additional Conduent filing in the California Attorney General's directory. [4](#source-4) [6](#source-6)

### April 27, 2026 — Public disclosure

Additional Conduent filing in the California Attorney General's directory. [1](#source-1) [6](#source-6)

### May 20, 2026 — Public disclosure

Publication date of revised Texas report BR-0005045. [7](#source-7)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Most United States lawsuits had been consolidated in the District of New Jersey, and plaintiffs filed a consolidated complaint on March 18, 2026. An unauthorized third party accessed a limited portion of Conduent's network during the reported interval. Individual and regulatory notifications began in October 2025 and were substantially concluded by May 11, 2026. Conduent restored affected systems and returned to normal operations within days and, in some cases, hours. Conduent incurred and accrued $25 million in notification-related non-recurring expenses and had disbursed that amount by March 31, 2026. Conduent notified federal law-enforcement authorities. As of May 11, 2026, Conduent was responding to subpoenas, information requests, and investigations from government agencies and other stakeholders. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [5](#source-5) [9](#source-9)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/conduent-business-services-data-incident-2024/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Conduent Business Services breach notification page — April 27, 2026

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-622398>

<a id="source-2"></a>

### Conduent Business Services breach notification page — January 2, 2026

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-616545>

<a id="source-3"></a>

### Conduent Business Services breach notification page — January 30, 2026

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-617969>

<a id="source-4"></a>

### Conduent Business Services breach notification page — March 24, 2026

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-620757>

<a id="source-5"></a>

### Notice of Data Incident — California sample notice

official · Conduent Business Services, LLC

<https://oag.ca.gov/system/files/Template%20Notice%20to%20Consumers%20%2801%29%28529003458.1%29__.pdf>

<a id="source-6"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-7"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-8"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-9"></a>

### Quarterly Report on Form 10-Q for the period ended March 31, 2026

regulatory · Conduent Incorporated · May 11, 2026

<https://www.sec.gov/Archives/edgar/data/1677703/000167770326000059/cndt-20260331.htm>

<a id="source-10"></a>

### Attorney General investigation of Blue Cross Blue Shield of Texas and Conduent

regulatory · Office of the Attorney General of Texas · Feb 12, 2026

<https://www.oag.state.tx.us/news/releases/attorney-general-ken-paxton-demands-information-blue-cross-blue-shield-texas-and-conduent-part>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: In re: Conduent Business Services Data Breach Litigation
2. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-02-02
3. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: As of May 11, 2026, Conduent said it knew of no release of the exfiltrated data on the dark web or otherwise publicly.
4. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Financial account information
5. **Ended At · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: 2025-01-13
6. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-01-02
7. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent client, individual, public, and regulator notifications
8. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Payment card information
9. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Dates of birth
10. **Resulted In · 100% confidence · current**  
   In re: Conduent Business Services Data Breach Litigation: Most United States lawsuits had been consolidated in the District of New Jersey, and plaintiffs filed a consolidated complaint on March 18, 2026.
11. **Affected Individual Count · 100% confidence · current**  
   Conduent client end-user data exposure: 12,784,367 individual
12. **Began At · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: 2024-10-21
13. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: An unauthorized third party accessed a limited portion of Conduent's network during the reported interval.
14. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent said the disruption did not materially affect its operations.
15. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent client end-user data exposure
16. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: The threat actor exfiltrated files associated with a limited number of Conduent clients.
17. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-01-30
18. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-04-27
19. **Affected Organization · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent Incorporated
20. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Names
21. **Resulted In · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: Individual and regulatory notifications began in October 2025 and were substantially concluded by May 11, 2026.
22. **Affected Organization · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Blue Cross and Blue Shield of Texas
23. **Discovered At · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: 2025-01-13
24. **Affected Organization · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent Business Services, LLC
25. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent restored affected systems and returned to normal operations within days and, in some cases, hours.
26. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent incurred and accrued $25 million in notification-related non-recurring expenses and had disbursed that amount by March 31, 2026.
27. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Contact information
28. **Resulted In · 100% confidence · current**  
   October 2024–January 2025 Conduent cyber incident: Conduent notified federal law-enforcement authorities.
29. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Health insurance information
30. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-03-24
31. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-02-12
32. **Affected Individual Count · 100% confidence · current**  
   Conduent client end-user data exposure: 72,066 individual
33. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Clinical information
34. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Social Security numbers
35. **Disclosed At · 100% confidence · current**  
   Conduent client, individual, public, and regulator notifications: 2026-05-20
36. **Resulted In · 100% confidence · current**  
   In re: Conduent Business Services Data Breach Litigation: As of May 11, 2026, Conduent was responding to subpoenas, information requests, and investigations from government agencies and other stakeholders.
37. **Exposed Data Category · 100% confidence · current**  
   Conduent client end-user data exposure: Driver's license numbers
38. **Affected Individual Count · 100% confidence · current**  
   Conduent client end-user data exposure: 62,486,662 individual

</details>
