CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats

Conduent data breach grows, affecting at least 25M people - TechCrunch

TechCrunch Archived Mar 16, 2026 ✓ Full text saved

Conduent data breach grows, affecting at least 25M people TechCrunch

Full text archived locally
✦ AI Summary · Claude Sonnet


    The spillover from a ransomware attack on one of the largest government contractors in the United States keeps getting bigger: More than 25 million people have now had personal data stolen in the hack. Conduent provides printing, mailroom services, and document and payment processing services for state government benefit operations, such as food assistance, as well as workplace and unemployment benefits for large corporations. As such, the company handles a large amount of personal information belonging to a large swath of the United States. Conduent says its technology and operational support services reach more than 100 million people. But since the January 2025 cyberattack, which a ransomware group claimed credit for, the corporate giant has said little about the data breach, such as how it was caused and how many people are affected. An update to the state of Wisconsin’s data breach notification page now shows the Conduent breach affects at least 25 million people across the United States. TechCrunch’s ongoing tally from various data breach notification letters that we have seen also amounts to about 25 million people, with Oregon (10.5 million) and Texas (15.4 million) accounting for the majority of those affected. Other data breach notices seen by TechCrunch include another few hundred thousand individuals across Massachusetts, New Hampshire, and Washington. The breach is known to have compromised individuals’ names, dates of birth, addresses, Social Security numbers, health insurance information, and medical data. Conduent has said little outside of its data breach notifications, and in some cases has made it more difficult for affected individuals to learn about the breach. Disrupt 2026: The tech ecosystem, all in one room Your next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to save up to $400. San Francisco, CA | October 13-15, 2026 REGISTER NOW A page on Conduent’s website, titled “Incident Notice” that was published in October 2025 at the same time as its first data breach notification, does not explicitly mention a cybersecurity incident. The page contains a hidden “noindex” tag in its source code, which tells search engines to not list the page in search results, making it difficult for anyone searching the web to find it. When reached by TechCrunch, Conduent spokesperson Sean Collins would not say how many notifications the company has sent to date, or why the company is hiding its incident notice from search engines. Conduent’s breach has been billed as one of the “largest ever,” but likely trails behind the Change Healthcare hack, which affected more than 190 million people following a ransomware attack in February 2024. A Russian-speaking ransomware gang stole reams of health and medical data from Change Healthcare using a stolen credential that wasn’t protected with multi-factor authentication, prompting the healthcare tech giant to pay at least two ransoms to keep most of the stolen data off the internet. Topics Conduent, cybersecurity, data breach, ransomware attack, Security Zack Whittaker Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com. View Bio June 9 Boston, MA Actively scaling? Fundraising? Planning your next launch? TechCrunch Founder Summit 2026 delivers tactical playbooks and direct access to 1,000+ founders and investors who are building, backing, and closing. REGISTER NOW Most Popular The billionaires made a promise — now some want out US Army announces contract with Anduril worth up to $20B ‘Not built right the first time’ — Musk’s xAI is starting over again, again Lovable says it added $100M in revenue last month alone, with just 146 employees DOGE employee stole Social Security data and put it on a thumb drive, report says Meta acquired Moltbook, the AI agent social network that went viral because of fake posts Google rolls out new Gemini capabilities to Docs, Sheets, Slides, and Drive
    💬 Team Notes
    Article Info
    Source
    TechCrunch
    Category
    🛡 Active Threats
    Published
    Archived
    Mar 16, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗