Remember when the government assured you they'd keep your Social Security number safe?
Conduent – the contractor handling medical billing, toll transactions, and prepaid cards for government programs – just watched its data breach numbers explode from 10 million victims to over 25 million.
The company still won't say if all 100 million Americans they serve got hit.
Ransomware Attack Gave Hackers Three Months To Steal Social Security Numbers And Medical Records
Conduent discovered the breach on January 13, 2025.
The SafePay ransomware gang had been inside their systems since October 21, 2024 – almost three full months.
During that time, these criminals stole 8.5 terabytes of data containing names, Social Security numbers, medical records, and health insurance details tied to Medicaid programs, child support systems, food assistance, and toll records across multiple states.
Texas alone jumped from 4 million victims in October to 15.4 million now.
Oregon reported 10.5 million hit.
Hundreds of thousands more got notification letters in Delaware, Massachusetts, New Hampshire, and California.
SafePay Ransomware Group Behind Eighth-Largest Healthcare Data Breach In U.S. History
SafePay ransomware emerged in September 2024 and became one of the most aggressive groups on the planet by early 2025.
They target 90% small and mid-sized businesses – organizations that can pay ransoms but can't absorb the operational shutdown.
SafePay uses stolen credentials, exploits VPN vulnerabilities, and gets inside through exposed Remote Desktop Protocol endpoints.
Once they're in, they disable security tools, delete backup systems, and encrypt everything within 24 hours – faster than most ransomware groups operate.
Security researchers believe SafePay is staffed by veterans from disbanded operations like LockBit and Conti, explaining their sophisticated tactics and rapid-fire attack pace.
The group claims 265 victims across multiple countries since late 2024, with the United States their primary target.
Their double-extortion model means they steal data first, then encrypt systems – forcing victims to pay twice: once for the decryption key, once to prevent data publication.
Government Contractor Security Failures Put 100 Million Americans At Identity Theft Risk
Conduent handles technology for approximately 100 million Americans across government healthcare programs.
They process $85 billion in annual disbursements and manage over 2 billion customer service interactions yearly.
One contractor.
One breach.
Twenty-five million victims confirmed – potentially 100 million at risk.
This mirrors the 2024 National Public Data breach that exposed sensitive information on nearly all Americans, and the Opexus contractor breach where two employees with prior hacking convictions destroyed more than 30 government databases and stole 1,800 files from IRS and GSA systems.
The pattern is clear: outsource your data to private contractors, watch them get hacked, then spend months figuring out how many millions of citizens got exposed.
Conduent expects to finish notifying victims by April 15, 2026 – fifteen months after the breach began.
They've burned through $25 million in response costs so far, with cyber insurance covering some expenses.
They're facing at least ten class-action lawsuits in federal court for failing to protect personal information and notify victims promptly.
The Department of Health and Human Services Office for Civil Rights is investigating whether Conduent violated HIPAA Security Rules.
State attorneys general across the country are scrambling to figure out how many of their residents got hit because Conduent won't provide complete numbers.
The company claims they've found no evidence the stolen data appeared on the dark web.
That's supposed to be reassuring.
It's not.
Medical records and Social Security numbers don't expire – they're ammunition for sophisticated fraud schemes that play out over years, not months.
Identity thieves don't need to dump everything on public forums to profit from it.
Sources:
- Eric Revell, "Data breach exposes personal data of 25M Americans," Fox Business, February 10, 2026.
- Zack Whittaker, "Data breach at govtech giant Conduent balloons, affecting millions more Americans," TechCrunch, February 5, 2026.
- Multiple Authors, "Conduent Business Services Data Breach Victim Count Swells to Over 25M," HIPAA Journal, February 9, 2026.
- Multiple Authors, "SafePay ransomware explained: IOCs, TTPs, and defense strategies," ThreatLocker Blog, November 7, 2025.
- Yelisey Boguslavskiy, "Unmasking the SafePay Ransomware Group," Infosecurity Magazine, November 6, 2025.
- Multiple Authors, "SafePay Ransomware: How a Non-RaaS Group Executes Rapid Fire Attacks," Bitdefender, July 2025.
- Multiple Authors, "Data Breach at Government Contractor Conduent Sparks Nearly a Dozen Class Action Lawsuits," CPO Magazine, November 25, 2025.
