CONDUENT INCORPORATED
ent_019dd17c77fb86a6d3b73b1844af3bea
Disclosures
11
SEC 10-K Item 1C · State AG · SEC 8-K · Leak Site · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
969
nationwide · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- CONDUENT INCORPORATED
- Normalized
- conduent— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300SFJ2D2CYY6CQ11
- SEC EDGAR CIK
- 0001677703
- Domain
- conduent.com
Disclosure history (11)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-19
Conduent Incorporated (CNDT) disclosed a cybersecurity incident in its 2025 10-K filing, referred to as the January 2025 Cyber Event. The company processes substantial volumes of personal information and financial transactions for commercial and government customers. While specific technical details of the breach are not provided, Conduent maintains a liability on its balance sheet for expected remaining cash outlays related to the event. The company describes a robust cybersecurity risk management program aligned with NIST, PCI-DSS, and HIPAA standards, including active monitoring, third-party assessments, and an incident response plan.
- Illinois State AGas victim2025-05-01
CONDUENT filed a data-breach notice with the Illinois Attorney General in May 2025 (case 25-05-136). The register records the breach as discovered on April 10, 2025. Personal information types reported: drivers license, medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALSEC 8-Kas victim2025-04-14
On January 13, 2025, Conduent Incorporated experienced an operational disruption after a threat actor gained unauthorized access to a limited portion of its environment. The Company subsequently determined that the actor exfiltrated files associated with a limited number of clients, containing personal information of clients' end-users. Affected systems were restored within days; federal law enforcement was notified. Material non-recurring expenses were accrued in Q1 2025.
- GLOBALLeak Siteas victim2025-01-09
Conduent is a global company specializing in business process services. They provide digital platforms and services for both businesses and governments. Conduent's expertise covers sectors like healthcare, transportation, and financial services among others. Their services aim to improve user experiences, boost operational efficiency and increase client satisfaction. They were formerly a part of Xerox.
- Indiana State AGas victim2022-08-22
Conduent, Inc reported a data breach to the Indiana Attorney General. 1 Indiana residents were affected.
- Indiana State AGas victim2022-08-03
Conduent, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-07-26 and was reported on 2022-08-03. 2 Indiana residents were affected.
- Indiana State AGas victim2021-12-09
Conduent reported a data breach to the Indiana Attorney General. 1 Indiana residents were affected.
- New Hampshire State AGas victim2021-01-19
Conduent, Inc. disclosed a security breach involving one New Hampshire resident. An internal employee used valid credentials to make unauthorized changes to email and bank account details, resulting in fraudulent withdrawals. The incident occurred between May 7, 2019, and October 28, 2020, and was discovered on October 6, 2020. Conduent notified the NH Attorney General on January 19, 2021, and affected individuals on November 25, 2020. Data exposed included names, emails, banking info, HSA numbers, and partial SSNs. Conduent terminated the employee, froze accounts, restored funds, and offered one year of credit monitoring.
- Indiana State AGas victim2020-11-25
Conduent, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-05-07 and was reported on 2020-11-25. 9 Indiana residents were affected. 22 individuals affected in total.
- Indiana State AGas victim2020-06-09
Conduent reported a data breach to the Indiana Attorney General. The breach occurred on 2020-05-22 and was reported on 2020-06-09. 20 Indiana residents were affected. 969 individuals affected in total.
- Massachusetts State AGas victim2020-02-07
Conduent HR Services LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-02-07. 8 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CONDUENT INCORPORATED — not by CONDUENT INCORPORATED itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- FEDERALSEC 8-Kvia CONDUENT BUSINESS SERVICES, LLC2026-09-10
Conduent Inc. filed an 8-K regarding a previously disclosed cybersecurity incident from January 2025 affecting Conduent Business Services, LLC. The filing discloses a settlement agreement in principle reached in August 2026 to resolve consolidated lawsuits from individuals who allegedly received notification letters that their personal information may have been affected. The settlement was not yet court-approved as of September 10, 2026.
- New Hampshire State AGvia CONDUENT BUSINESS SERVICES, LLC2026-04-27
Conduent Business Services, LLC filed a supplemental notice with the New Hampshire Attorney General on April 27, 2026, regarding a prior security incident. The filing discloses that notifications were sent to 4 additional New Hampshire residents. The affected data included names and Social Security numbers. The incident involves one or more covered entities for which Conduent acts as a service provider.
- California State AGvia CONDUENT BUSINESS SERVICES, LLC2026-04-27
Conduent Business Services, LLC disclosed a cyber incident where an unauthorized third party accessed its network from October 21, 2024, to January 13, 2025. The attacker obtained files containing personal information, including names, of clients served by Conduent. Conduent secured its networks, engaged forensic experts, restored systems, and notified law enforcement. No evidence of misuse was found.
- Illinois State AGvia CONDUENT BUSINESS SERVICES, LLC2026-04-01
CONDUENT STATE & LOCAL SERVICES, INC. filed a data-breach notice with the Illinois Attorney General in April 2026 (case 26-04-1159). The register records the breach as discovered on January 13, 2025. Personal information types reported: financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGvia CONDUENT BUSINESS SERVICES, LLC2026-03-24
Conduent Business Services, LLC filed a supplemental security incident notice with the New Hampshire Attorney General on March 24, 2026. The filing reports that notifications were sent to an additional 112,325 New Hampshire residents regarding a data security incident involving names and Social Security numbers. Conduent acts on behalf of covered entities/data owners and continues to provide notices.
- California State AGvia CONDUENT BUSINESS SERVICES, LLC2026-03-24
Conduent Business Services, LLC, a third-party printing, document processing, and back-office support services provider, discovered on January 13, 2025, that an unauthorized third party had accessed a limited portion of its network from October 21, 2024, to January 13, 2025, and obtained files containing personal information belonging to clients' customers. Conduent secured its network, engaged third-party forensic experts, restored operations, and notified law enforcement.
- Vermont State AGvia CONDUENT BUSINESS SERVICES, LLC2026-03-24
Conduent Business Services, LLC notified Vermont consumers of a cyber incident where an unauthorized third party accessed its network from October 21, 2024, to January 13, 2025. The breach exposed names and government identifiers (SSN, DOB, driver's license). Conduent engaged forensic experts, secured systems, notified law enforcement, and offered 24 months of credit monitoring.
- Massachusetts State AGvia CONDUENT BUSINESS SERVICES, LLC2026-02-10
Conduent Business Services, LLC disclosed a cyber incident where an unauthorized third party accessed its network from October 21, 2024, to January 13, 2025. The breach was discovered on January 13, 2025. Affected data includes names and potentially Social Security numbers for individuals associated with current or former health plans. Conduent secured its networks, engaged forensic experts, notified law enforcement, and is offering credit monitoring services.
- Maine State AGvia CONDUENT BUSINESS SERVICES, LLC2026-02-09
Conduent Business Services, LLC reported a cyber incident where an unauthorized third party accessed its network from October 21, 2024, to January 13, 2025. The breach affected 16,991 individuals, including 3 Maine residents. Personal information, including names and government identifiers, was obtained. Conduent engaged forensic experts, secured its network, and notified law enforcement. Affected individuals were offered credit monitoring services.
- Vermont State AGvia CONDUENT BUSINESS SERVICES, LLC2026-02-05
Conduent Business Services, LLC notified Vermont residents of a cyber incident discovered Jan 13, 2025, involving unauthorized access from Oct 21, 2024, to Jan 13, 2025. The incident affected files containing personal information (name, SSN, DOB, etc.) of individuals associated with health plans served by Conduent. Conduent engaged forensic experts, secured systems, notified law enforcement, and offered credit monitoring services.