CONDUENT INCORPORATED
bd_b39f4b52b4d871fe · schema v1 · pii pii-v1
Full breach record for CONDUENT INCORPORATED →8 incidents on filePress / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedThis IT supplier was hacked, causing public services in multiple US states to be disrupted for several days - Security Insider | The cybersecurity knowledge base for decision-makers. Conduent: The IT services company Conduent was the victim of a cyberattack, which resulted in the disruption of public services in several US states, affecting thousands of families who rely on these services. The attack was quickly contained, but required a secure restoration that took several days. The details of the attack are not yet known, but Conduent clarified that its security was compromised by a "third-party intrusion." Linked ransomware group: safepay.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 15, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitesafepaybd_da57970c8e98a6452025-01-09 · +6dVerified
Regulatory filings (2) · sorted by filing gap
- SEC 8-Kbd_6a28511dac1d715a2025-04-14 · +89dVerified
- Illinois State AGbd_1e232a462b71d0e32025-05-01 · +106dVerified
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Jan 15, last May 1 (IL) — a 106-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
safepay
According to ransomware.live, SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.