FR
live

Conduent lost 8 TB in an 84-day breach — and millions of Americans are paying the price

The SafePay ransomware group exfiltrated 8.5 terabytes of data from BPO giant Conduent between October 2024 and January 2025, exposing over 25 million individuals. It's the costliest supply chain breach of the year for US governments — and a wake-up call for any CISO who depends on a critical third party.

Conduent a perdu 8 To de données dans une brèche de 84 jours — et des millions d’Américains en paient le prix — ETTAYEB illustration

October 21, 2024. An unauthorized actor walks into the network of Conduent, the US business process outsourcing giant. Nobody notices.

January 13, 2025. Conduent detects the intrusion. 84 days have passed.

February 2026. Breach notifications hit mailboxes across the country. 15.4 million Texas residents affected. 10.5 million in Oregon. Over 25 million individuals total. The SafePay ransomware group claims credit — and says it stole 8.5 terabytes of data.

This is not just another breach. This is a supply chain catastrophe: a contractor that processed payroll, EBT cards, Medicaid claims, toll systems, and HR data for nearly half the Fortune 100 was quietly drained over three months. Every one of its clients — states, insurers, global corporations — is exposed by proxy.

Conduent: the subcontractor everyone uses and no one audits

Conduent spun off from Xerox in 2017. It employs over 60,000 people across 40 countries. Its core business is Business Process Outsourcing — it runs administrative, financial, and public-health workflows on behalf of its clients.

The scope is staggering:

  • Medicaid and Medicare payment processing for dozens of US states
  • Electronic toll collection (E-ZPass and equivalents)
  • Benefits administration (EBT, SNAP) for millions of recipients
  • HR and payroll services for nearly half of the Fortune 100

When Conduent goes down, welfare payments stop, hospital reimbursements freeze, and employees don’t get paid. On January 13, 2025, that is exactly what happened: the intrusion detection triggered a multi-day service outage that disrupted mailrooms, payment processing, and benefits administration.

Operational impact is not a footnote. It proves that a single, non-redundant vendor can paralyze essential public services.

SafePay: a new name, an old playbook

The SafePay group claimed the attack on its dark-web leak site in early 2025. It is a relatively new player, but its code tells an older story.

ThreatLocker researchers analyzed a SafePay malware sample and found a telling kill-switch: the malware checks the system language before executing. If it detects Russian, Ukrainian, Belarusian, or any other Cyrillic layout, it terminates immediately. The unwritten rule of Russian-speaking cybercrime — “don’t defecate where you eat” — is still in force.

SafePay’s technical DNA points to shared lineage with BlackCat (ALPHV) and DarkSide, two major ransomware strains. SafePay is likely a rebrand or splinter group — a pattern that has become standard after law-enforcement takedowns: DarkSide was disrupted in 2021, BlackCat in 2024.

The most probable initial vector, according to threat intelligence analysts, was a Citrix gateway without multi-factor authentication (MFA). Compromised credentials, a remote-access portal with no MFA, and the door swung open.

84 days of dwell time: how 8.5 TB vanished without a single alert

Three months. That is the dwell time — the gap between initial compromise and detection. SafePay did not rush. The group executed a patient, methodical playbook.

Phase 1 — Access and persistence (October–November 2024). The attackers relied on legitimate administrative tools already present on the network — a technique known as Living off the Land (LotL). No exotic malware, no red-flag signatures. They blended into normal traffic.

Phase 2 — Reconnaissance and privilege escalation (November–December 2024). Once persistence was baked in, SafePay mapped the infrastructure, located sensitive data repositories, and elevated its access.

Phase 3 — Silent exfiltration (December 2024 – January 2025). This is the most disturbing part. Moving 8.5 terabytes out of a network without tripping alarms requires genuine tradecraft. SafePay reportedly used custom throttling scripts to limit transfer speeds during business hours and ramp them up overnight, mimicking routine backup behavior. Conduent’s network team saw outbound traffic, but nothing looked out of place.

The haul: names, Social Security numbers, dates of birth, health insurance IDs, medical records, bank details, client contracts. All told, over 25 million people.

The regulatory and financial cascade

On April 9, 2025, Conduent filed an 8-K with the SEC. The document acknowledged data exfiltration but played down the impact: no evidence of data published on the dark web, no material operational disruption. The company accrued “material non-recurring expenses” and invoked its cyber insurance policy.

Then the real numbers started surfacing.

February 2026. Texas Attorney General Ken Paxton launched an investigation and issued Civil Investigative Demands (CIDs) against Conduent and its clients, including Blue Cross Blue Shield of Texas. The Texas AG called it “potentially one of the largest healthcare data breaches in US history.”

State-level notifications stacked up:

  • Texas: 15.4 million residents
  • Oregon: 10.5 million
  • Delaware, Massachusetts, and others each in the hundreds of thousands

Immediate response costs are pegged at roughly $2 million — a figure that covers emergency containment only. It excludes fines, class-action settlements, long-term remediation, and lost contracts. For comparison, the Change Healthcare breach (2024), which affected 193 million people, ultimately cost UnitedHealth Group over $1 billion.

The supply chain lesson: your security is your vendor’s security

The Conduent breach is not another entry in a long list. It exposes a systemic weakness in the outsourcing model: hundreds of organizations — governments, insurers, Fortune 500s — entrust their most sensitive data to a single provider, with no real visibility into that provider’s security controls.

Conduent’s clients were not hacked. They saw nothing. They simply inherited the breach through their contract.

Five concrete steps for CISOs and legal teams:

  • Audit third-party access with strict Least Privilege. Every vendor service account must be scoped to the minimum necessary, with mandatory MFA — ideally FIDO2 to resist phishing.
  • Monitor outbound data volume from vendor tunnels. A BPO provider has no legitimate reason to move terabytes to unknown destinations. A baseline of outbound traffic, with alerts on deviation, is non-negotiable.
  • Require incident notification within 24 to 48 hours in contractual clauses — not “as soon as reasonably practicable.”
  • Simulate a total critical-vendor failure. A yearly tabletop exercise with the scenario “your BPO is compromised, systems offline for 7 days” will tell you whether your business continuity plan actually works.
  • Ensure the contract includes robust indemnification for vendor-side data breaches.

The verdict

The Conduent breach confirms what CISOs have known for years but boards still struggle to fund: you are only as strong as your weakest link. When your service provider handles payroll, healthcare reimbursements, and welfare benefits for your citizens or employees, its attack surface is your attack surface.

If you depend on a third party to process personal or health data, start auditing its access controls today — not at the next contract renewal. And if that vendor won’t agree to an independent security audit, find one that will.

SafePay is not done. BPOs remain the perfect target: concentrated data, wide attack surface, multiplied impact. The question is not whether the next Conduent will happen — it is whether your organization will be on the exposed client list when it does.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

← Back to the feed

Type at least two characters.

navigate open esc dismiss