Policy & Regulation
Conduent data breach grows to affect at least 25 million people
Conduent’s data breach has expanded to affect at least 25 million people, raising transparency concerns as the company attempts to obscure its incident notice from search engines.
A data breach at Conduent, a major government contractor in the United States, has expanded to affect at least 25 million people. The company provides printing, mailroom services, and document and payment processing services for state government benefit operations—such as food assistance—as well as workplace and unemployment benefits for large corporations. Because of these operations, the company handles a large volume of personal information belonging to a wide swath of the United States population. Conduent states that its technology and operational support services reach more than 100 million people.
The data breach, which followed a cyberattack in January 2025, compromised sensitive personal data. The stolen information includes names, dates of birth, addresses, Social Security numbers, health insurance information, and medical data. The scale of the incident became clearer following an update to the data breach notification page of Wisconsin, which showed the impact across the United States. A tally of data breach notification letters by TechCrunch also amounts to about 25 million people. The majority of those affected are in Texas, with 15.4 million people, and Oregon, with 10.5 million people. Other data breach notices seen by TechCrunch include another few hundred thousand individuals across Massachusetts, New Hampshire, and Washington.
Conduent has faced scrutiny over its transparency and disclosure practices following the incident. In October 2025, the company published an “Incident Notice” page on its website that does not explicitly mention a cybersecurity incident. Additionally, the page contains a “noindex” tag—an HTML tag used to instruct search engines not to index a webpage—effectively hiding the notice from public search results and making it difficult for anyone searching the web to find it. When reached by TechCrunch, Conduent spokesperson Sean Collins would not state how many notifications the company has sent to date, or explain why the company is hiding its incident notice from search engines.
Although the Conduent data breach is one of the largest on record, it remains smaller than the ransomware attack on Change Healthcare in February 2024. That incident, which involved a Russian-speaking ransomware gang stealing health and medical data, affected more than 190 million people. In that case, the healthcare tech giant paid at least two ransoms to keep most of the stolen data off the internet.
Why it matters
The data breach at a major government contractor handling sensitive information for millions of citizens highlights critical transparency failures in corporate incident response. The company’s use of technical mechanisms to obscure its public notice raises significant governance concerns for the public sector agencies relying on its services.