Conduent confirms cyberattack behind US government service outages
- Organization
- Conduent
- Exploit
- Hacking
- Industry
- Business Services
Conduent, a New Jersey based business process services company that works for more than 600 government entities across 46 US states, confirmed on January 22, 2025 that an outage affecting its systems had been caused by a cybersecurity incident.
The disruption surfaced first through the company's public sector clients. The Wisconsin Department of Children and Families said Conduent notified it of the incident on January 13, and that payees who receive child support through electronic transfer or an EBT card did not get their scheduled payments. Oklahoma Human Services had earlier reported an outage on a customer service line. SecurityWeek reported that four states were affected.
A company spokesperson said Conduent "experienced an operational disruption due to a cybersecurity incident" and that the incident "was contained and all systems have been restored." Conduent declined to say how the intrusion occurred or whether data had been taken, and no group had claimed responsibility at the time.
The scope became clear much later. SecurityWeek reported that Conduent ultimately notified more than 10.5 million people that names, addresses, dates of birth, Social Security numbers and health and insurance information had been stolen, and that intruders had been inside the network from October 21, 2024 until they were removed on January 13, 2025.
Sources
- SecurityWeek, Conduent Confirms Cyberattack After Government Agencies Report Outages
- Cybersecurity Dive, Government payments contractor Conduent confirms cyberattack impacts multiple states
- TechCrunch, Conduent confirms outage was due to a cybersecurity incident
- SecurityWeek, 10 Million Impacted by Conduent Data Breach