Skip to content
cisonews.net

Incident · 8-K Item 1.05

Conduent reports exfiltrated client files held personal data of a significant number of people

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Conduent, which runs transaction processing and back-office services for governments and companies, disclosed on April 14, 2025 that a threat actor had taken files tied to some of its clients during an intrusion on January 13, 2025. The Item 1.05 filing came 91 days after the intrusion, once outside experts had worked out what the files contained.

What Conduent said

Systems came back within days, and the company said the disruption itself was not material. The later finding concerned the data.

The company explained the delay by the complexity of the files, which it sent to data mining specialists. It said it had incurred and accrued material non-recurring expenses in the first quarter tied to possible notification requirements. It said it had no knowledge of the data being released publicly.

What the filing does not give

Conduent did not state how many people's data was in the files, which clients were affected, or the dollar amount of the accrued expenses.

Sources

  1. 2025-04-14 · AConduent Incorporated, Form 8-K (SEC EDGAR), published April 14, 2025

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.