Original Article Text

Click to Toggle View

Govtech giant Conduent confirms client data stolen in January cyberattack. American business services giant and government contractor Conduent disclosed today that client data was stolen in a January 2025 cyberattack. Conduent is a business services company that provides digital platforms and solutions for government and commercial clients in transportation, healthcare, customer experience, and human resources. The company has over 33,000 employees and provides services to half of Fortune 100 companies and over 600 government and transportation agencies.  In January, the company suffered a cyberattack that impacted customers' operations across the U.S., including local government agencies. In a new FORM-8K filing with the SEC today, Conduent has now confirmed that threat actors had stolen files containing information about the company's customers. "As part of its ongoing investigation, the Company determined that the threat actor exfiltrated a set of files associated with a limited number of the Company's clients." reads the 8-K filing. "Due to the complexity of the files, the Company engaged cybersecurity data mining experts to evaluate the exfiltrated data and was recently informed of its nature, scope and validity, confirming that the data sets contained a significant number of individuals' personal information associated with our clients' end-users." "The Company is continuing to further analyze and document the precise and detailed impact of the data exfiltrated, and clients are being informed as appropriate in order to determine next steps as required by federal and state law." Conduent says there are no indications that the stolen data has been published on the dark web or in another public manner. BleepingComputer has also not been able to find any ransomware gangs or threat actors leaking or offering the data for sale. The company says that the attack has not had any material impact on its operations, but it has incurred expenses in the first quarter related to the attack. Conduct previously suffered a breach in 2020, when the Maze ransomware gang encrypted the company's devices and stole corporate data. Top 10 MITRE ATT&CK© Techniques Behind 93% of Attacks Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

Daily Brief Summary

DATA BREACH // Conduent Reports Data Theft in January Cyberattack Incident

American business services company, Conduent, confirmed client data was stolen during a cyberattack in January 2025.

Conduent, serving government and commercial clients in various sectors, disclosed the breach in an SEC FORM-8K filing.

The attack resulted in the exfiltration of files containing personal information of numerous individuals linked to client services.

Cybersecurity experts were consulted to assess the complexity and extent of the compromised data.

There have been no indications that the stolen data has surfaced on the dark web or has been misused publicly.

Despite the breach, Conduent noted the incident did not materially affect their operations but led to some expenses in Q1.

The company is conducting ongoing analysis to fully determine the impact and is communicating with affected clients to comply with legal obligations.

This breach follows a previous incident in 2020 involving the Maze ransomware gang.