- Conduent has submitted a new 8-k form with SEC
- It noted a violation of January 2025 and said that some customer data were taken
- So far no groups assumed responsibility for the attack
Conduent Incorporated, an American corporate service company, has confirmed to suffer a cyberattack and a data violation in a new filing at the US Securities and Exchange Commission (SEC).
In a new 8-k form, Conduent said that in mid-January 2025 it experienced an “operational disturbance” caused by unauthorized access from a threat actor. The attacks reportedly gained access to a “limited part” of the company’s environment and remained there for several days (in some cases said Conduent))
Previous reports said the attack happened after a “third -party system compromise with an operating system”.
Supply chain attack
While the attack did not have a significant impact on the company’s operations, it resulted in the theft of sensitive data.
Conduent offers a number of services, including transaction processing, automation and analysis, across various sectors such as healthcare, transport and government.
Some of its largest clients include the US Secret Service, the District of Columbia Medicaid and others. It serves hundreds of government and transport organizations.
In the attack, the threat actors stole data generated by Conduent’s clients: “As part of its ongoing investigation, the company decided that the threat actor ex -filtered a set of files associated with a limited number of the company’s clients,” the archiving reads.
“Due to the complexity of the files, the company engaged the Cyber Security Data mining for evaluating the ex-filtered data and was recently informed of its nature, scope and validity, confirming that the data sets contained a significant number of individuals ‘personal information associated with our clients’ end users.”
At the time of the press, no groups assumed the responsibility for the attack and the data has not yet been leaked on the dark web.
According to Bleeping computerThis is not Conduent’s first incident as the company also suffered from a data violation in 2020, when the Maze Ransomware group managed to encrypt the company’s devices and steal company data.
Via Bleeping computer