Yes, the Conduent breach is real. Conduent says an unauthorized party accessed part of its environment between October 21, 2024, and January 13, 2025, and took files linked to some clients. Some affected records included Social Security numbers (SSNs), but the exposed information differed by client and person. The often-repeated 10.5 million figure is an estimate—not a definitive nationwide total that Conduent has confirmed in its public filings.
Last updated: October 1, 2026. Public counts remain subject to change as client notices, state filings and investigations continue.
What happened in the Conduent breach?
Conduent is a business-process and technology-services provider. It performs administrative, payment, document-processing, mailing, benefits, insurance and health-related work for other organizations. That means a person can receive a Conduent notice even without ever signing up for a Conduent product; the relevant relationship may be with an insurer, government program, benefits administrator, employer or another client.
Conduent’s filings describe unauthorized access to a limited portion of its environment and the exfiltration of files associated with some clients. The public record does not establish a particular ransomware family, ransom demand or payment. Conduent says affected systems were restored quickly, while identifying the people and data elements in the files required a lengthy review by internal and outside specialists.
#1 Best Overall
Conduent’s 2026 Form 10-K describes a “significant number” of client end-users, rather than one final national count.
When did the incident occur?
- October 21, 2024: The earliest unauthorized-access date listed in consumer notices submitted to California.
- January 13, 2025: Conduent says it discovered the incident, secured affected systems and identifies this as the end of the access period in notices.
- April 2025: Conduent disclosed the event to the Securities and Exchange Commission.
- October 2025 onward: Notifications began for some client populations.
- 2026: Additional state filings, investigations, notices and litigation added information about the scope.
The California sample notice lists the access period as October 21, 2024, through January 13, 2025 (California Attorney General notice). A notice arriving months later does not mean the breach happened when the letter was mailed. Conduent says each client’s files had to be analyzed before an individual notification could be prepared; its third-quarter 2025 filing said notifications could continue into early 2026.
How many people were affected?
There is no single, authoritative public total yet. The figures below describe different estimates or populations and should not be treated as interchangeable.
| Figure | What it represents | How to read it |
|---|---|---|
| 10.5 million | Widely circulated media or early regulatory estimate | Not a final nationwide number confirmed by Conduent |
| Approximately 4 million | Texas residents cited by the Texas Attorney General | Official state estimate for a particular population |
| 25 million or more | Estimate referenced by Missouri regulators as appearing in media reports | Not independently confirmed as the final total |
| “Significant number” | Conduent’s description in its SEC filing | Official but non-specific |
The Texas Attorney General said approximately four million Texans were affected. A Missouri Department of Insurance bulletin referenced reports estimating 25 million or more Americans. State figures may cover only residents of that state or one Conduent client population. One person could also appear in more than one client file.
Recommended Free Tools
Were Social Security numbers exposed?
Some affected records included SSNs. Missouri regulatory material identifies names, addresses and Social Security numbers among affected information. Other notices list combinations such as dates of birth, health-insurance numbers, treatment dates and treatment-cost information. A California sample notice lists name, treatment-cost information, treatment-date information and a health-insurance number without listing an SSN.
Therefore, “SSNs were included” is accurate for at least some data sets, but it is not evidence that every person in a 10.5-million estimate had an SSN exposed. The categories in your own notice are the best indication of what applied to you.
Why did notification take so long?
The access period, discovery date, file-review date and mailing date are separate events. Conduent says the files were complex and required specialized data-mining and review to determine which client, person and information type each record involved. Notifications were sent as that client-specific work was completed.
Pending lawsuits and regulatory inquiries may challenge Conduent’s handling or notification process, but allegations are not final findings. The company’s Q1 2026 Form 10-Q says multiple lawsuits were consolidated in federal court in New Jersey.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsHow to verify a Conduent breach letter
Because notices may direct you to a monitoring provider, verify the message before entering sensitive information.
- Check that the letter names Conduent, gives the access dates, identifies the relevant client and lists data categories matching your situation.
- Find contact information independently on Conduent’s official website or through the insurer, agency, employer or benefits administrator named in the letter.
- Do not click an unexpected email link or scan a QR code. Type a verified address yourself.
- Confirm any credit-monitoring enrollment URL independently and check the deadline.
- Do not submit a full SSN, driver’s-license image, bank login or identity documents merely to prove you received a notice.
- Use the three credit bureaus’ official websites for freezes and fraud alerts rather than links supplied in an unsolicited message.
Consumer reports have raised concerns about confusing enrollment instructions, but the official records reviewed here do not establish that Conduent’s notification program itself was fraudulent.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected people should do now
1. Freeze your credit
A security freeze is free and blocks prospective creditors from accessing your credit report. Place freezes directly with:
A freeze does not stop account takeover, tax fraud, medical-identity fraud or misuse of an existing account, so protect those areas separately.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
2. Review your credit reports
Use AnnualCreditReport.com, the federally authorized site. Look for new accounts, hard inquiries, unfamiliar addresses, collection accounts, incorrect employers and changes to existing accounts. Save copies and dispute anything you do not recognize.
3. Add a fraud alert if appropriate
A fraud alert asks creditors to take extra steps before opening new credit. It is not a substitute for a freeze, but may help if you are actively applying for credit or investigating suspicious activity.
4. Protect tax and government-benefit accounts
- Create or review an IRS online account and consider filing taxes early where practical.
- Review Social Security records and report unrecognized changes.
- If the notice lists health or insurance information, review explanation-of-benefits statements and contact the insurer or administrator about unfamiliar services.
5. Report suspected identity theft
Use the Federal Trade Commission’s official recovery portal at IdentityTheft.gov. Keep the notice, envelope, enrollment instructions, account records and a timeline of suspicious activity.
What this breach does—and does not—prove
- Unauthorized access and file exfiltration do not prove that every affected person has suffered identity theft.
- Receiving a notice does not by itself establish that your SSN was exposed; read the listed data categories.
- A monitoring offer is not the same as compensation and does not prevent misuse.
- A state estimate is not automatically the final national total.
- Conduent’s role does not mean you were a direct Conduent customer.
Investigations and continuing updates
The Texas Attorney General has sought information from Conduent and Blue Cross Blue Shield of Texas regarding the incident and the affected population. Federal lawsuits have been consolidated in New Jersey, according to Conduent’s Q1 2026 filing. Those proceedings and additional state notices may change the public count or clarify which clients and data sets were involved.
For now, the most accurate summary is: the breach is genuine; access occurred from October 21, 2024, through January 13, 2025; some records contained SSNs; and 10.5 million is an estimate rather than a settled nationwide total.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




