Conduent Data Breach Class Action Lawsuit: Claims and Class

The Conduent data breach class action lawsuit is a consolidated case in the U.S. District Court for the District of New Jersey, In Re: Conduent Business Services Data Breach Litigation, No. 2:25-cv-16953, that combines at least nine separate class actions filed on behalf of tens of millions of people whose personal and health information was stolen during a 2024–2025 intrusion into Conduent’s network. As of June 2026, the case is paused for mediation, with the parties scheduled to appear before Judge Welsh on August 13, 2026.1PACER Monitor. In Re Conduent Business Services Data Breach Litigation

Where the Case Stands Now

At least nine class actions were filed against Conduent by November 2025 and consolidated in New Jersey federal court under case number 2:25-cv-16953.2HIPAA Journal. Conduent Business Solutions Data Breach1PACER Monitor. In Re Conduent Business Services Data Breach Litigation An amended consolidated complaint was filed on June 12, 2026.

Three days later, on June 15, 2026, Magistrate Judge Michael A. Hammer granted a motion to stay all proceedings and deadlines through September 7, 2026, so the parties could try mediation. That mediation is set for August 13, 2026, before Judge Welsh. If it does not resolve the case, the parties must file a joint status report and a proposed briefing schedule for anticipated motions to dismiss by September 10, 2026.1PACER Monitor. In Re Conduent Business Services Data Breach Litigation Whether the litigation settles or moves to contested motions should become clear in the fall of 2026.

Who Is Being Sued

The amended consolidated complaint names three Conduent entities: Conduent Business Services, LLC; Conduent Incorporated; and Conduent State & Local Solutions, Inc. It also names several of Conduent’s major healthcare clients as defendants, including Elevance Health, Health Care Service Corporation, Humana, and The Cigna Group.1PACER Monitor. In Re Conduent Business Services Data Breach Litigation

What the Lawsuits Allege

The consolidated complaint rests on several theories. Plaintiffs allege Conduent was negligent in failing to implement reasonable data security despite handling large volumes of sensitive health and personal information. They also assert breach of implied contract, on the theory that people who provided their data had a reasonable expectation it would be protected, and unjust enrichment, on the theory that Conduent profited from data it did not adequately secure. Plaintiffs seek a declaratory judgment requiring Conduent to adopt stronger security practices and to provide lifelong identity theft protection.3Internet Archive (Court Filing). Marshall v. Conduent Business Services, LLC

The complaints cite alleged violations of the FTC Act’s prohibition on unfair or deceptive practices, the HIPAA Privacy and Security Rules, and the HITECH Act’s requirements for safeguarding electronic medical information.3Internet Archive (Court Filing). Marshall v. Conduent Business Services, LLC As a business associate to healthcare providers and government agencies, Conduent is subject to HIPAA’s Security Rule and contractually obligated to protect electronic protected health information.2HIPAA Journal. Conduent Business Solutions Data Breach

Who Is Leading the Plaintiffs

Judge Hammer appointed an eight-member Plaintiffs’ Steering Committee to lead the consolidated litigation. It is chaired by Shauna Itri of Seeger Weiss and includes attorneys from DiCello Levitt, Hausfeld, Lynch Carpenter, Graybill Law Firm, Cotchett Pitre & McCarthy, Nussbaum Law Group, and Zimmerman Reed.4DiCello Levitt. DiCello Levitt Partner Appointed to Plaintiffs’ Steering Committee in Conduent Data Breach Litigation James E. Cecchi of Carella Byrne Cecchi Brody & Agnello filed the amended consolidated complaint and represents most of the individual and consolidated plaintiffs on the docket.1PACER Monitor. In Re Conduent Business Services Data Breach Litigation

Who the Case Covers

The confirmed number of affected individuals has climbed steadily as the investigation continued. Early reports placed the figure above 10.5 million.5King 5 News. Conduent Data Breach Affects More Than 10 Million By February 2026 that number had risen to at least 25 million.6TechCrunch. Conduent Data Breach Grows, Affecting at Least 25M People Later reporting put the confirmed total above 62.2 million people, with the investigation still ongoing.2HIPAA Journal. Conduent Business Solutions Data Breach

Texas was hit hardest, with roughly 15.5 million residents affected, including Medicaid recipients whose data Conduent processed for Blue Cross Blue Shield of Texas. Notifications also went to regulators in California, Delaware, Indiana, Maine, Massachusetts, Missouri, Montana, New Hampshire, Oregon, Vermont, and Wisconsin.2HIPAA Journal. Conduent Business Solutions Data Breach Texas Attorney General Ken Paxton called the incident “likely the largest breach in U.S. history.”7Texas Attorney General. Attorney General Ken Paxton Demands Information From Blue Cross Blue Shield of Texas and Conduent

The stolen data included names, addresses, dates of birth, Social Security numbers, medical records and treatment information, health insurance details, and claims information.2HIPAA Journal. Conduent Business Solutions Data Breach Some notification letters also referenced phone numbers, email addresses, health insurance member ID numbers, and treatment payment amounts.8Anthem Blue Cross. Conduent Substitute Notice

The Breach Behind the Case

Hackers gained access to Conduent’s network on October 21, 2024, and were not detected until January 13, 2025, giving them nearly three months inside the environment. During that window, files containing electronic protected health information were exfiltrated from what Conduent described as “a limited portion” of its IT environment.2HIPAA Journal. Conduent Business Solutions Data Breach

The SafePay ransomware group claimed responsibility in February 2025, asserting it had stolen 8.5 terabytes of data and threatening to publish the files if a ransom was not paid. Conduent is no longer listed on that leak site as of mid-2026. Conduent has stated there is “no evidence that any underlying data has been misused, posted, or made publicly available.”2HIPAA Journal. Conduent Business Solutions Data Breach

Because Conduent runs payment and benefits platforms for state agencies, the intrusion also caused service outages. In Wisconsin, the Child Support Trust Fund was disrupted, interrupting payments for recipients who received funds by electronic transfer or EBT card. Wisconsin was one of at least four states that experienced outages, though the others have not been publicly identified.9Cybersecurity Dive. Government Payments Contractor Conduent Hit by Cyberattack

Why Notification Took So Long

Conduent identified the intrusion in January 2025, but notification letters did not begin reaching affected people until October 2025, roughly ten months later and a full year after the hackers first entered the network.2HIPAA Journal. Conduent Business Solutions Data Breach Blue Cross Blue Shield of Texas confirmed Conduent began mailing letters to affected BCBSTX members on October 24, 2025.10BCBS Texas. Update on Conduent Cyber Incident

In Montana, Blue Cross Blue Shield of Montana was told by Conduent in January 2025 but did not notify individuals until October. State regulators opened an investigation into whether the nine-month gap violated Montana’s requirement to notify consumers “without unreasonable delay,” and held an administrative hearing in January 2026 after BCBS Montana unsuccessfully sought a temporary restraining order to block it. Montana’s Commissioner of Securities and Insurance communications director called the attempt to block the hearing “troubling.”11Security Magazine. Conduent Data Breach Timeline and What to Know

The letters themselves also drew criticism for not identifying which specific company or agency had originally supplied the recipient’s data to Conduent, leaving many people unclear on how their information ended up in the breach at all.12WRDW. Conduent Data Breach Could Be Largest in US History

State Investigations Running Alongside

Two state investigations are adding pressure on top of the class action.

In Texas, Attorney General Paxton issued Civil Investigative Demands to both Conduent and BCBS Texas on February 12, 2026. The investigation focuses on Conduent’s system security, its communications about the breach, and its compliance with Texas law, and includes a parallel demand to BCBS Texas over its own compliance with state requirements. Roughly four million Texans, including Medicaid recipients, were affected in the state.7Texas Attorney General. Attorney General Ken Paxton Demands Information From Blue Cross Blue Shield of Texas and Conduent

In Missouri, the Department of Commerce and Insurance has been investigating since March 2026. DCI Director Angela Nelson said publicly that Conduent “has not provided sufficient information for regulators to fully assess the potential impact of this breach.”13KCTV5. Missouri Regulators Escalate Pressure on Conduent Over Data Breach Conduent responded that it is not a DCI licensee and lacks visibility into which of its clients are Missouri-regulated, so it cannot speak on their behalf.14Bank Info Security. Missouri Alleges Conduent Stonewalling State on Hack The DCI has since begun soliciting information directly from insurance companies and issued bulletins in March and May 2026 reminding insurers of their duty to report breaches and notify members.15TechTarget Health IT Security. Missouri Regulators Say Conduent Is Not Cooperating in Breach Investigation

What Affected People Have Been Offered

Conduent’s notification letters offered complimentary credit monitoring and identity protection, though the length varied by client. Premera Blue Cross communicated that Conduent was providing two years of monitoring.16Premera. Conduent Data Security Incident BCBS Texas indicated one year of free credit monitoring.17BCBS Texas. Conduent Incident FAQ People who did not receive a monitoring offer were encouraged to obtain free credit reports and place freezes on their credit files.5King 5 News. Conduent Data Breach Affects More Than 10 Million If you received a notification letter, keep it. The class definition, deadlines, and any settlement mechanics will be tied to the details in those notices and to filings on the New Jersey docket.