Conduent lost 8 TB in an 84-day breach — and millions of Americans are paying the price
The SafePay ransomware group exfiltrated 8.5 terabytes of data from BPO giant Conduent between October 2024 and January 2025, exposing over 25 million individuals. It's the costliest supply chain breach of the year for US governments — and a wake-up call for any CISO who depends on a critical third party.
October 21, 2024. An unauthorized actor walks into the network of Conduent, the US business process outsourcing giant. Nobody notices.
January 13, 2025. Conduent detects the intrusion. 84 days have passed.
February 2026. Breach notifications hit mailboxes across the country. 15.4 million Texas residents affected. 10.5 million in Oregon. Over 25 million individuals total. The SafePay ransomware group claims credit — and says it stole 8.5 terabytes of data.
This is not just another breach. This is a supply chain catastrophe: a contractor that processed payroll, EBT cards, Medicaid claims, toll systems, and HR data for nearly half the Fortune 100 was quietly drained over three months. Every one of its clients — states, insurers, global corporations — is exposed by proxy.
Conduent: the subcontractor everyone uses and no one audits
Conduent spun off from Xerox in 2017. It employs over 60,000 people across 40 countries. Its core business is Business Process Outsourcing — it runs administrative, financial, and public-health workflows on behalf of its clients.
The scope is staggering:
- Medicaid and Medicare payment processing for dozens of US states
- Electronic toll collection (E-ZPass and equivalents)
- Benefits administration (EBT, SNAP) for millions of recipients
- HR and payroll services for nearly half of the Fortune 100
When Conduent goes down, welfare payments stop, hospital reimbursements freeze, and employees don’t get paid. On January 13, 2025, that is exactly what happened: the intrusion detection triggered a multi-day service outage that disrupted mailrooms, payment processing, and benefits administration.
Operational impact is not a footnote. It proves that a single, non-redundant vendor can paralyze essential public services.
SafePay: a new name, an old playbook
The SafePay group claimed the attack on its dark-web leak site in early 2025. It is a relatively new player, but its code tells an older story.
ThreatLocker researchers analyzed a SafePay malware sample and found a telling kill-switch: the malware checks the system language before executing. If it detects Russian, Ukrainian, Belarusian, or any other Cyrillic layout, it terminates immediately. The unwritten rule of Russian-speaking cybercrime — “don’t defecate where you eat” — is still in force.
SafePay’s technical DNA points to shared lineage with BlackCat (ALPHV) and DarkSide, two major ransomware strains. SafePay is likely a rebrand or splinter group — a pattern that has become standard after law-enforcement takedowns: DarkSide was disrupted in 2021, BlackCat in 2024.
The most probable initial vector, according to threat intelligence analysts, was a Citrix gateway without multi-factor authentication (MFA). Compromised credentials, a remote-access portal with no MFA, and the door swung open.
84 days of dwell time: how 8.5 TB vanished without a single alert
Three months. That is the dwell time — the gap between initial compromise and detection. SafePay did not rush. The group executed a patient, methodical playbook.
Phase 1 — Access and persistence (October–November 2024). The attackers relied on legitimate administrative tools already present on the network — a technique known as Living off the Land (LotL). No exotic malware, no red-flag signatures. They blended into normal traffic.
Phase 2 — Reconnaissance and privilege escalation (November–December 2024). Once persistence was baked in, SafePay mapped the infrastructure, located sensitive data repositories, and elevated its access.
Phase 3 — Silent exfiltration (December 2024 – January 2025). This is the most disturbing part. Moving 8.5 terabytes out of a network without tripping alarms requires genuine tradecraft. SafePay reportedly used custom throttling scripts to limit transfer speeds during business hours and ramp them up overnight, mimicking routine backup behavior. Conduent’s network team saw outbound traffic, but nothing looked out of place.
The haul: names, Social Security numbers, dates of birth, health insurance IDs, medical records, bank details, client contracts. All told, over 25 million people.
The regulatory and financial cascade
On April 9, 2025, Conduent filed an 8-K with the SEC. The document acknowledged data exfiltration but played down the impact: no evidence of data published on the dark web, no material operational disruption. The company accrued “material non-recurring expenses” and invoked its cyber insurance policy.
Then the real numbers started surfacing.
February 2026. Texas Attorney General Ken Paxton launched an investigation and issued Civil Investigative Demands (CIDs) against Conduent and its clients, including Blue Cross Blue Shield of Texas. The Texas AG called it “potentially one of the largest healthcare data breaches in US history.”
State-level notifications stacked up:
- Texas: 15.4 million residents
- Oregon: 10.5 million
- Delaware, Massachusetts, and others each in the hundreds of thousands
Immediate response costs are pegged at roughly $2 million — a figure that covers emergency containment only. It excludes fines, class-action settlements, long-term remediation, and lost contracts. For comparison, the Change Healthcare breach (2024), which affected 193 million people, ultimately cost UnitedHealth Group over $1 billion.
The supply chain lesson: your security is your vendor’s security
The Conduent breach is not another entry in a long list. It exposes a systemic weakness in the outsourcing model: hundreds of organizations — governments, insurers, Fortune 500s — entrust their most sensitive data to a single provider, with no real visibility into that provider’s security controls.
Conduent’s clients were not hacked. They saw nothing. They simply inherited the breach through their contract.
Five concrete steps for CISOs and legal teams:
- Audit third-party access with strict Least Privilege. Every vendor service account must be scoped to the minimum necessary, with mandatory MFA — ideally FIDO2 to resist phishing.
- Monitor outbound data volume from vendor tunnels. A BPO provider has no legitimate reason to move terabytes to unknown destinations. A baseline of outbound traffic, with alerts on deviation, is non-negotiable.
- Require incident notification within 24 to 48 hours in contractual clauses — not “as soon as reasonably practicable.”
- Simulate a total critical-vendor failure. A yearly tabletop exercise with the scenario “your BPO is compromised, systems offline for 7 days” will tell you whether your business continuity plan actually works.
- Ensure the contract includes robust indemnification for vendor-side data breaches.
The verdict
The Conduent breach confirms what CISOs have known for years but boards still struggle to fund: you are only as strong as your weakest link. When your service provider handles payroll, healthcare reimbursements, and welfare benefits for your citizens or employees, its attack surface is your attack surface.
If you depend on a third party to process personal or health data, start auditing its access controls today — not at the next contract renewal. And if that vendor won’t agree to an independent security audit, find one that will.
SafePay is not done. BPOs remain the perfect target: concentrated data, wide attack surface, multiplied impact. The question is not whether the next Conduent will happen — it is whether your organization will be on the exposed client list when it does.
References
- Conduent Data Breach — Largest Data Breach in U.S. History As Ransomware Group Stolen 8 TB of Data, Cyber Security News, February 23, 2026.
- Supply Chain Fragility: Lessons from the Conduent/SafePay Ransomware Crisis, Threat Landscape, February 24, 2026.
- The 8 Terabyte Heist: Inside the Conduent Breach and the Rise of SafePay, Lostbrain, February 28, 2026.
- Conduent SEC Filing (8-K), April 9, 2025.
- SafePay Ransomware — Technical Analysis, Cyber Security News.