Conduent Data Breach: A Settlement Has Been Reached — Nothing Is Approved and There Is No Claim Form Yet (September 2026)
One of the largest healthcare data breaches in U.S. history: Conduent Business Services — a back-office contractor that processes data for major health insurers and state benefit programs — confirmed in a June 2026 federal filing that 62,224,658 people were affected, up from the 10.5 million first reported. Stolen data includes Social Security numbers and medical information. The status changed on September 10, 2026: Conduent told the SEC it reached an agreement in principle in August to settle the consolidated class action, and the court stayed the case the next day. The terms are not public, the paperwork is not signed, and no judge has approved anything — so there is still nothing to file. Here is exactly what exists, what does not, and what to do today.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened — and What the Lawsuits Allege
For nearly three months, from October 21, 2024 to January 13, 2025, intruders had access to the network of Conduent Business Services, a New Jersey-based company that handles mailroom, payment processing, and back-office work for some of the largest U.S. health insurers and for state benefit programs. The SafePay ransomware group claimed responsibility in February 2025 and said it took roughly 8.5 terabytes of data (the attackers' own figure, not independently verified). The consolidated class actions allege negligence, breach of contract, violations of the FTC Act and state consumer-protection laws, failure to comply with HIPAA — and that Conduent took nearly ten months to notify affected people after discovering the breach.
Case Details
More than 35 federal class actions are consolidated as In re: Conduent Business Services Data Breach Litigation, No. 2:25-cv-16953, in the U.S. District Court for the District of New Jersey — assigned to Judge Michael E. Farbiarz, with pretrial matters referred to Magistrate Judge Michael A. Hammer. The court appointed an eight-member Plaintiffs' Steering Committee on December 22, 2025; a consolidated amended complaint uniting 35 suits followed on March 18, 2026, which also names Health Care Service Corporation (Blue Cross Blue Shield), AIG, The Cigna Group, Elevance Health, Humana and Blue Shield of California; a further amended complaint was filed June 12, 2026. On September 10, 2026 the parties filed a joint status report reporting an agreement in principle (docket entries 163–164), and on September 11 the docket shows the case stayed. There is still NO settlement administrator and NO official claims site — the settlement agreement itself has not been finalized or filed.
Current Status
Follow this case
There's no claim deadline yet. We'll email you if a settlement opens a claim period.
Who Is Affected?
Conduent's final regulatory tally, filed with HHS on June 4, 2026, puts the breach at 62,224,658 people — the third-largest healthcare data breach in U.S. history — after earlier counts of roughly 10.5 million (October 2025) and 25 million (February 2026). Conduent processes data for health insurers and state programs; clients confirmed affected include Blue Cross Blue Shield plans operated by Health Care Service Corporation (Texas, Illinois, Montana), Premera Blue Cross, and Humana, plus state agencies such as the Wisconsin Department of Children and Families and Oklahoma Human Services. Texas filings alone report roughly 15.5 million residents affected. If you received a letter from Conduent Business Services about this incident, you are affected.
Is There a Payout?
Timeline
- 1
October 21, 2024 – January 13, 2025 — Network Intrusion
Attackers maintain access to Conduent's systems for nearly three months. Conduent — a business-services contractor spun off from Xerox in 2017 that handles back-office processing for insurers and government benefit programs — detects and stops the intrusion on January 13, 2025.
- 2
January–February 2025 — Disclosure and Ransomware Claim
Conduent discloses an operational disruption in January 2025 and later details the incident in SEC filings. In February 2025 the SafePay ransomware group claims the attack, saying it took roughly 8.5 TB of data — the attackers' own, unverified figure. The group later removes Conduent from its leak site.
- 3
October 24, 2025 — Notification Letters Begin Mailing
Nearly ten months after discovery, letters start going out — some reach consumers as late as January 2026. Initial regulator filings put the count at roughly 10.5 million people. Letters offer two years of free credit monitoring and identity restoration with an enrollment deadline of March 31, 2026.
- 4
November–December 2025 — Lawsuits Consolidate in New Jersey
Class actions stack up in the U.S. District Court for the District of New Jersey and are consolidated as In re: Conduent Business Services Data Breach Litigation, No. 2:25-cv-16953. On December 22, 2025 the court appoints an eight-member Plaintiffs' Steering Committee to coordinate the litigation.
- 5
February–March 2026 — Count Passes 25 Million, States Investigate
State filings push the total past 25 million. The Texas Attorney General opens an investigation, calling it 'likely the largest breach in U.S. history.' On March 18, 2026 a consolidated amended complaint unites 35 suits and also names Health Care Service Corporation (BCBS) and AIG Procurement Services as defendants; motion-to-dismiss briefing follows in spring 2026.
- 6
June 4, 2026 — Final Federal Tally: 62.2 Million
Conduent's updated filing with HHS OCR confirms 62,224,658 affected individuals — the third-largest healthcare data breach ever recorded in the U.S., behind only the 2024 Change Healthcare attack and the 2015 Anthem breach.
- 7
August–September 2026 — Agreement in Principle, Case Stayed
Per Conduent's Form 8-K of September 10, 2026: an agreement in principle to settle the consolidated case was reached in August 2026 and disclosed in a joint status report filed with the court on September 10 (docket entries 163–164). On September 11 the court stayed the case. Paperwork not finalized, no court approval, no terms disclosed. Whether the insurer co-defendants are part of the deal is not stated in the filing.
- 8
Next — Settlement Agreement, Preliminary Approval, Claim Form
What has to happen before anyone can file: a signed settlement agreement filed with the court, a motion for preliminary approval, a preliminary approval order, a court-appointed administrator and official website, then notices and a claims deadline. None of those exist yet. This page will carry the official links and deadlines when they do.
Scam & Misinformation Warnings
A breach touching 62 million people — Social Security numbers and medical data included — is a magnet for fraud. Watch for these:
Fake 'Conduent settlement claim' sites
No claims portal exists — not before the September 2026 agreement in principle, and not after it. A settlement being reached does not create a claim form; only a court-approved settlement with an appointed administrator does. Any page, ad, or social post offering a Conduent payout form today is a scam or clickbait. When the real one comes, the administrator's URL will appear in court filings — and on this page.
Phishing that quotes your real data
The thieves HAVE real Social Security numbers, insurance member IDs, and claims data — a call or email quoting your genuine details is not proof it's legitimate. Conduent's official outreach came by mailed letter with an assistance number printed in it. Never hand personal information to an inbound caller citing this breach.
Fee-charging 'lawsuit sign-up' or 'breach protection' services
Nobody legitimate charges to 'add you' to this class action — if a class is certified, affected people are included automatically. Credit freezes at Equifax, Experian, and TransUnion are free by law; skip any paid 'breach protection' upsell.
Frequently Asked Questions
Is there a Conduent data breach settlement?
An agreement in principle, yes — a finished settlement, no. Conduent's Form 8-K of September 10, 2026 says the company reached an agreement in principle in August 2026 to settle In re: Conduent Business Services Data Breach Litigation, No. 2:25-cv-16953 (D.N.J.), that the parties reported it to the court in a joint status report the same day, and that “the settlement paperwork is not yet finalized, and the settlement agreement has not yet been approved by the court.” The court stayed the case on September 11. The amount and the per-person terms have not been disclosed. There is no claims administrator, no fund and no claim form yet.
I got a Conduent letter — what should I do right now?
Four things: (1) Keep the letter — it documents that you're in the affected group. (2) The free credit-monitoring enrollment deadline in the original letters was March 31, 2026; if your letter is newer, check the deadline printed in it. (3) Freeze your credit for free at Equifax, Experian, and TransUnion — the strongest protection when your SSN is exposed. (4) Watch bank statements and health-insurance Explanation of Benefits documents for services you never received.
How much money will I get?
Honestly: $0 today — no fund exists and no amount has been announced. Conduent's filing discloses that an agreement in principle was reached, not what it pays; the company says only that it has cyber insurance and does not expect a material financial impact. For a reference point once terms appear: comparable healthcare mega-breach settlements have paid documented out-of-pocket losses (often capped around $5,000–$10,000) plus small pro-rata cash payments (typically $50–$100), with the pro-rata amount shrinking as the class grows — and this class is 62 million people. That is a pattern, not a disclosed term.
I've never heard of Conduent — why did they have my data?
Conduent is a business-services contractor (spun off from Xerox in 2017) that handles mailroom, payment processing, and back-office work for health insurers and state benefit programs — it processes data for a large share of Americans who never deal with it directly. Clients confirmed affected in this breach include Blue Cross Blue Shield plans operated by Health Care Service Corporation, Premera Blue Cross, Humana, the Wisconsin Department of Children and Families, and Oklahoma Human Services.
What data was stolen?
Depending on the individual: name, address, date of birth, Social Security number, email, phone, and medical or health-insurance information such as treatment and claims data. Not every element applies to every person — your notification letter states what was involved for you.
Do I need to sign up for the lawsuit?
No. If the settlement is approved, everyone who fits the class definition is included automatically — you would act only later, to file a claim or to opt out once a notice with deadlines exists. Be wary of sites urging you to 'register for the Conduent lawsuit' or 'reserve your payment' today; at this stage nobody can add you to anything, and the September 2026 agreement in principle changed nothing about that.
When will there be a claim form and a payment?
Not on any announced date. The sequence from here: the parties finalize and file the settlement agreement, plaintiffs move for preliminary approval, the judge rules, an administrator sends notices with a claims deadline, then a final approval hearing — and payments only after final approval and any appeals. Conduent's own filing says the paperwork is not finalized, so even the first of those steps has not happened. We update this page at each milestone; the docket (No. 2:25-cv-16953) is where the next step will show up first.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.