Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Conduent breach: 62M people and third-party risk

A ransomware attack on Conduent exposed data on 62M+ people. What it says about third-party risk and what to do when a processor holds your data.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
12 June 2026
READING TIME
9 min read
TOPIC
Threats and Incidents
Conduent breach: 62M people and third-party risk

One of the largest data breaches of 2026 didn’t hit a bank or a retail chain everyone has heard of — it hit a company most of the victims had never heard of. Conduent is a US business-process outsourcing (BPO) provider that processes data on behalf of public institutions, insurers and healthcare organisations. After a ransomware attack, the number of people with exposed data grew for months — from early estimates around 10 million all the way to more than 62 million. It’s a textbook lesson about a risk you can’t see on your own firewall: the risk of your vendors.

What happened

Conduent confirmed a security incident that disrupted part of its services, and then determined that attackers had stolen data. The SafePay ransomware group claimed responsibility, asserting it had exfiltrated multiple terabytes. The scope of the stolen information was serious: per the disclosures it included names, dates of birth, addresses, Social Security numbers (SSNs), and health-insurance and medical information.

The most instructive part is how the scale grew. Early estimates spoke of the low tens of millions; in February 2026 Conduent revised the figure to about 25.5 million, and in an update filed with the US regulator (the HHS Office for Civil Rights) in early June 2026 the final number appeared: 62,224,658 people. This is no accident — in large breaches the victim count almost always grows over time, because working out whose data exactly was in the stolen sets is painstaking analysis that continues long after the intrusion itself.

It’s also worth noting what was not confirmed: in early 2026 the company and its partners reported no evidence of the stolen data being sold or published online. That matters for risk assessment, but it doesn’t remove the threat — data that has once left an organisation is beyond its control.

Why it matters for companies in Europe too

“It’s an American story” — easy to think, but the mechanism is universal. Your organisation almost certainly entrusts data to processors: a payroll provider, a hosting company, a newsletter operator, an external call centre. In GDPR terms those are processors, and you as the controller are responsible for choosing such a vendor and for what happens to the data. A breach at your vendor is your breach — notification obligations and reputational damage included.

It’s the same logic we describe in third-party risk management (TPRM): you don’t control someone else’s infrastructure, but you do control whom you trust, what you put in the data-processing agreement, and how quickly you learn about an incident. Conduent shows why that isn’t a formality.

What to do if your data may have leaked at a vendor

As an individual you can’t secure someone else’s server, but you can limit the impact:

Assume the data is circulating. With breaches involving SSNs, contact details and medical data, the real risks are identity theft and targeted phishing — including by phone, impersonating an insurer or a government office. Heightened vigilance matters more than any single password. Check whether your address appears in known leaks — we’ve written how to do it.

Beware of “incident support.” After high-profile breaches, scammers appear impersonating the company that lost the data and offering “protection” or “verification.” That’s a second-stage attack vector — don’t click links in such messages; go to sites directly.

Watch the medical and insurance angle. Health and insurance data can be used for fraud that’s harder to detect than ordinary credit fraud. React to inconsistencies in correspondence from providers.

What your organisation should do

Map your processors. Build a list of every vendor that touches your data and what data you entrust to each. You can’t manage a risk you can’t see.

Tighten contracts. Data-processing agreements should include security requirements, a right to audit and — crucially — a short, hard incident-notification deadline. The Conduent story shows how long scoping can take; the earlier you get the signal, the better.

Rehearse response to someone else’s incident. Your response plan must cover the “it leaked at a vendor” scenario: who assesses the impact on your customers, who evaluates the obligation to notify the authority, who communicates. Walk through it in advance — exactly as in our guide to the first hours after a breach.

Frequently asked questions (FAQ)

Why did the victim count grow from 10 to 62 million? Because determining whose data exactly was in the stolen sets is a long analysis. First statements give cautious estimates, and final figures — reported to the regulator — can be many times higher. That’s the normal, if unsettling, arc of large breaches.

We’re not a Conduent customer — does this affect us? Possibly indirectly: companies like Conduent operate on behalf of many institutions, so data reaches them “through” an insurer or agency you have a relationship with. The exact circle of victims depends on contracts you can’t see from the outside.

What does it mean for us as a data controller in the EU? That you’re responsible for choosing and overseeing your processors. A breach at a vendor can trigger your GDPR obligations, including assessing whether to notify the supervisory authority and the affected individuals. That’s why the processing agreement and fast incident notice are so important.

How do we vet our own vendors before it’s too late? Start with an inventory and classification of the data you entrust to them, then assess their security in proportion to the risk. Get in touch if you want to put your vendor-assessment process and contractual requirements in order.

Summary

The Conduent breach is a reminder that your attack surface doesn’t end at your network edge — it includes every vendor you entrust with data. More than 62 million victims and months of rising estimates show how hard it is to gauge the impact and how long cleaning up after someone else’s incident takes. If you want to know which of your vendors is the weak link and how to reduce that risk — let’s start with a vendor-risk map.


Sources and further reading: U.S. HHS Office for Civil Rights — Breach Portal, Malwarebytes Labs, BleepingComputer.

SHARE / COPY