A breach at contractor Conduent exposed the Social Security numbers of about 62 million people, and lawsuits are piling up

Image Credit: Unknown author

A data breach at a company most Americans have never dealt with directly has grown into one of the largest on record, and the final tally is far bigger than early estimates suggested. Conduent, a business-services contractor that handles payments, benefits administration and customer records for government agencies and large companies, has confirmed that the incident exposed the personal information of more than 62 million people. Among the data taken were Social Security numbers, and the legal fallout is still expanding.

How a 25 million estimate became 62 million

The scale of the breach climbed in stages, which is part of why it drew so much attention. Attackers first reached Conduent’s systems in October 2024, and the company did not detect the intrusion until January 2025. Early public estimates put the number of affected individuals in the low tens of millions.

By early 2026, after regulators pressed for detail, the figure was revised upward to roughly 25.5 million. Then, on June 4, 2026, Conduent set the final total at 62,224,658 individuals, more than double the earlier count, according to industry outlet HIPAA Journal. That total makes it one of the largest breaches of personal and health-related data ever reported in the United States, trailing only the 2024 Change Healthcare incident and the 2015 Anthem breach. The exposed records reportedly included names, addresses, dates of birth, Social Security numbers, and in many cases medical and health-insurance information.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

The lawsuits and investigations stacking up

The size of the exposure has produced a wave of litigation rather than a single case. At least ten federal class-action lawsuits have been filed against Conduent in the U.S. District Court for the District of New Jersey, and plaintiffs’ firms have continued to add filings as the affected-person count rose. The complaints broadly allege that the company was negligent in failing to put adequate safeguards in place to protect the sensitive data it held on behalf of its clients.

Separately, state attorneys general in Missouri, Montana and Texas have opened investigations, and the incident has drawn federal regulatory scrutiny tied to the health-related information involved. None of this has produced a settlement or a claims fund yet, which is an important distinction for consumers. Unlike the many data-breach cases already paying cash, the Conduent matter offers no money to claim today. It is at the litigation stage, and any consumer payout, if one ever comes, would be months or years away.

That gap between exposure and any potential compensation is exactly the window criminals exploit. Stolen data does not expire, and a Social Security number taken in a 2024 intrusion can surface in fraud attempts long after the headlines fade and long before any class-action money is distributed. Consumers who treat the litigation as the moment to relax have the timing backward; the practical protection has to happen now, independent of whether the courts ever award a dollar. The lawsuits may eventually hold Conduent accountable, but they will not undo an account opened in a victim’s name in the meantime.

What exposure of a Social Security number actually risks

For older Americans, the combination of a Social Security number, a birth date and an address is the most damaging cluster of data a criminal can obtain, because it is enough to open new accounts, file fraudulent tax returns or apply for credit in someone else’s name. Many of the people swept into the Conduent breach never had a direct relationship with the company at all; their information was there because a government agency or employer that used Conduent as a contractor passed it along.

That indirect exposure is precisely why waiting for a breach-notification letter is a weak defense. Notices are mailed to last-known addresses, and people who have moved, or whose data was held by a client of Conduent rather than by the company itself, may never receive one. The safer assumption for anyone who has interacted with a large employer, insurer or public benefits program is that some of their data is already circulating, and to act accordingly.

The protective steps that cost nothing

The strongest single move available to consumers is a credit freeze, which is free by law at each of the three national credit bureaus and blocks most new accounts from being opened in a person’s name. The Federal Trade Commission walks through how to place one, how to lift it temporarily, and what to do if fraud has already occurred at its consumer resource, IdentityTheft.gov. A freeze can be lifted in minutes whenever a person genuinely applies for credit, so it does not lock a household out of borrowing.

A related move is to request the free annual credit reports available to every consumer and to review them for accounts that were never opened by the account holder, a step the same federal resource explains. For anyone who files taxes, requesting an Identity Protection PIN from the Internal Revenue Service adds a second lock, because it blocks a fraudulent return filed with a stolen Social Security number from being processed. Neither step costs anything, and both directly counter the specific risks a breach of this size creates.

Beyond freezing credit, the practical defenses are unglamorous but effective: monitoring bank and card statements, treating unsolicited calls or emails that reference the breach as potential scams, and never confirming personal details to an inbound caller. Fraudsters routinely follow a large breach with a wave of impersonation calls that use the leaked data to sound legitimate. A breach this size guarantees that such calls will circulate, and the exposed information is what makes them convincing. Recognizing that pattern, and refusing to act on any unexpected contact, remains the cheapest protection a retiree has.

This article was created with AI assistance and was reviewed, edited, and fact-checked by The Financial Wire editorial team.

More Financial Reading

Leave a Reply

Your email address will not be published. Required fields are marked *