DisclosureLens
MisuseFinancial ServicesFinancePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountFinancial credentialsMediumContained

CONDUENT INCORPORATED

bd_de94237e28e5311f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 6, 2020

Filed

Jan 19, 2021

To disclose

15 weeks

Affected

1state residents only

Confidence

66%
Full breach record for CONDUENT INCORPORATED8 incidents on file

Conduent, Inc. disclosed a security breach involving one New Hampshire resident. An internal employee used valid credentials to make unauthorized changes to email and bank account details, resulting in fraudulent withdrawals. The incident occurred between May 7, 2019, and October 28, 2020, and was discovered on October 6, 2020. Conduent notified the NH Attorney General on January 19, 2021, and affected individuals on November 25, 2020. Data exposed included names, emails, banking info, HSA numbers, and partial SSNs. Conduent terminated the employee, froze accounts, restored funds, and offered one year of credit monitoring.

Incident timeline

undetected · 518 days
discovery → filing · 15 weeks / 105 days

May 7, 2019

Begins

Oct 6, 2020

Discovered

Jan 19, 2021

Filed

vs. sector median

+7 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.