
Conduent Business Services, a New Jersey based provider of back-office and technology services for healthcare organizations and government agencies, disclosed that the scope of its 2024 data breach has expanded sharply, with a new state filing indicating that nearly 14.8 million individuals in Texas alone were affected.
A breach notification submitted to the Texas Attorney General shows that the incident compromised the personal and protected health information of 14,791,500 Texas residents. The figure far exceeds earlier disclosures and indicates that the nationwide total will be significantly higher, as Texas residents represent only a portion of those impacted across the country.
Conduent had previously confirmed in a filing to the Oregon Attorney General that a hacking incident first detected in January 2025 affected approximately 10.5 million individuals nationwide. That disclosure already placed the incident among the largest healthcare data breaches announced in 2025. The Texas filing demonstrates that the scale of the breach has grown considerably as investigations and reporting continue.
The cyberattack has been linked to the SafePay ransomware group, which claimed responsibility for the intrusion and added Conduent to its dark web data leak site in early 2025. The group claimed to have stolen 8.5 terabytes of data and threatened to publish the information if a ransom was not paid. Conduent is no longer listed on the site, though no confirmation has been provided regarding the status of the data or any ransom demand.
Conduent provides mailroom operations, document processing, printing, and other administrative services for numerous HIPAA-covered entities and public agencies. Its healthcare clients include major insurers such as Humana, Premera Blue Cross, Blue Cross and Blue Shield of Texas, and Blue Cross and Blue Shield of Montana.
The intrusion was detected on Jan. 13, 2025. A forensic investigation later determined that unauthorized access began on Oct. 21, 2024, allowing the threat actor to remain inside Conduent’s network for nearly three months before containment. Investigators confirmed that files associated with multiple clients were exfiltrated during that period.
Compromised information varies by client and individual but may include names, dates of birth, Social Security numbers, treatment details, and health insurance or claims data. Conduent has offered to send notification letters on behalf of its affected healthcare clients, though it has not publicly confirmed a final nationwide victim count. As of the most recent update, the federal breach portal maintained by the HHS Office for Civil Rights continues to list the incident as affecting 42,616 individuals, a figure that does not reflect the more recent state-level disclosures.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543