Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Security

Conduent's breach count went from 4.3 million to 62.2 million in eight months of filings

Conduent Business Services filed a figure of 62,224,658 affected individuals with US health regulators on 4 June 2026, for an intrusion that ended on 13 January 2025. Public breach trackers still carry the 4.3 million figure it reported to California in October 2025.

Hubert H. Humphrey Building, located at the foot of Capitol Hill, Washington, D.C LCCN2013634632
Hubert H. Humphrey Building, located at the foot of Capitol Hill, Washington, D.C LCCN2013634632. Photograph: Carol M. Highsmith, Public domain

The number Conduent Business Services eventually filed with the United States Department of Health and Human Services Office for Civil Rights was 62,224,658. According to HIPAA Journal, which tracks the federal breach register, that filing was made on 4 June 2026 and makes the incident the third largest healthcare data breach recorded in the United States, behind Change Healthcare in 2024 at 192.7 million people and Anthem in 2015 at 78.8 million.

The intrusion it describes was over before most of those people existed in the public record as victims. Conduent, an outsourcing company based in New Jersey that processes claims and benefits payments for state governments and health insurers, was accessed from 21 October 2024 until 13 January 2025, when the company detected the activity and secured its network. That January date is also when the breach became visible to the public as an operational event: a multi day outage that, as Cybersecurity Dive reported, temporarily disrupted child support payments in Wisconsin.

What happened between January 2025 and June 2026 is the story. Conduent disclosed the incident in a filing with the Securities and Exchange Commission in April 2025, which Cyber Security News dates to 9 April 2025. No victim count accompanied it. Notification letters to individuals did not start going out until October 2025, roughly nine months after the intrusion was contained. The count reported to the California Attorney General at that point, and still carried by the technology news site Tech.co in its running breach list, was nearly 4.3 million.

In February 2026 the figure moved again. TechCrunch reported on 5 February 2026 that Texas alone had been told 15.4 million residents were affected, revised upward from an October notification of around 4 million, and that Oregon had been told 10.5 million. HIPAA Journal records slightly different state numbers for the same period, giving Texas as 14,791,500 in one filing and 15,494,592 in another, alongside 10,515,849 in Oregon and much smaller counts in Indiana, Maine and New Hampshire. The two accounts agree on the shape and disagree on the decimals, which is itself a feature of a disclosure process conducted state by state rather than centrally.

By the time the June 2026 federal filing landed, the total had risen roughly fourteenfold from the October 2025 California figure in eight months. Conduent has not published a narrative explaining the revisions. Asked in February 2026 to confirm the total, whether it exceeded 100 million, or how many notifications had been sent, a company spokesperson named by TechCrunch as Sean Collins declined to answer and provided a statement that did not address the questions.

Attribution is not seriously contested. The SafePay ransomware group claimed the attack in February 2025 and posted Conduent to its dark web leak site, alleging it had taken more than 8 terabytes of data. HIPAA Journal puts the claim at 8.5 terabytes and notes that Conduent is no longer listed on that site. Neither the company nor the group has published an explanation for the removal. The data types are consistent across sources: names, addresses, dates of birth, Social Security numbers, medical records, treatment information and health insurance claims.

The reason the count is so large is structural rather than technical. Conduent does not hold this data because those 62 million people are its customers. It holds it because it is a contractor, and the company says its technology and operational support services reach more than 100 million people in the United States across various government healthcare programmes. The victims are the customers of its customers. That is why the breach surfaced first as a series of client disclosures: Cybersecurity Dive reported that Premera Blue Cross and Blue Cross Blue Shield of Montana confirmed exposure, with up to 462,000 Montana residents potentially affected, and that the Montana State Auditor and Commissioner of Securities and Insurance opened an investigation into how that was handled.

The financial disclosures are more precise than the victim counts. Conduent accrued about 25 million US dollars in non recurring expenses in the first quarter of 2025, had disbursed 9 million US dollars in cash through September 2025, and anticipated a further 16 million US dollars through the first quarter of 2026. In a filing reported on 9 November 2025 it warned investors of further exposure from litigation, reputational harm and regulatory action, and said its cyber insurance policy should cover notification expenses.

What is still not known is why the number moved as it did. Conduent has not said whether the increases reflect newly discovered files, a slower forensic review of files already known to be taken, or client by client confirmations arriving over eighteen months. It has not said whether 62,224,658 is final. And because trackers, journalists and regulators each sampled the count at different moments, the figure a reader encounters still depends largely on which month their source last checked.

Sources

Every factual claim above rests on the 7 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. HIPAA JournalConduent Business Services data breach affected more than 62.2 million individuals
  2. TechCrunchData breach at govtech giant Conduent balloons, affecting millions more Americans
  3. Cybersecurity DiveConduent warns of further financial risks from cyberattack
  4. UpGuardThe biggest data breaches in US history
  5. Tech.coData breaches: an updated list
  6. Cyber Security NewsConduent data breach
  7. US Department of Health and Human Services, Office for Civil RightsBreach portal: notice to the Secretary of HHS breach of unsecured protected health information

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.