· In the news · Three documents ·

Why did you get a Conduent letter? And who is writing to you now that the official wave has ended.

The short answer

Conduent told the SEC in August 2026 that its breach notifications “began in October 2025 and have been substantially concluded”. Searches for “Conduent letter” are still climbing. Both of those are true at once, and the gap between them is where the risk sits. This page sets out what Conduent has actually filed, what it has never said, and how to check any letter without using the letter.

You opened an envelope from a company you have never heard of. It knew your name and address, it mentioned your Social Security number, and it offered you credit monitoring. The obvious question is whether it is real.

Almost every article you will find answers that question the same way: the letter is real, do not ignore it. That answer is correct and it is incomplete, because it was written for a moment that has largely passed. There are three separate records of this incident, they were written for three different audiences, and they do not say the same thing. Reading them side by side is more useful than any checklist.

Document one: what Conduent told its investors

Public companies must disclose material cybersecurity incidents to the Securities and Exchange Commission. Conduent Incorporated, listed on NASDAQ as CNDT, filed a Form 8-K under Item 1.05 on 14 April 2025. It is short, and it is the closest thing to a primary account that exists.

From the 8-K, filed 14 April 2025. “On January 13, 2025, Conduent Incorporated (the ‘Company’) experienced an operational disruption and learned that a ‘threat actor’ gained unauthorized access to a limited portion of the Company’s environment.”

The filing says systems were restored “within days, and in some cases, hours” and that the disruption “did not have a material impact to the Company’s operations”. It then says the threat actor took files belonging to “a limited number of the Company’s clients”, and that those files contained “a significant number of individuals’ personal information associated with our clients’ end-users”.

That last phrase is the whole reason you received an envelope. You were never Conduent’s customer. Conduent runs back office work for organisations that do deal with you: government agencies, health insurers, benefits and transit programmes. Your record travelled with somebody else’s contract, which is exactly why the name on the envelope means nothing to you.

Document two: what Conduent told health regulators, and why the number keeps moving

Here is the part that almost no coverage handles carefully. Conduent’s SEC filings have never stated how many people were affected. Not the 8-K in April 2025, and not the quarterly report filed sixteen months later. Both say “a significant number of individuals” and stop there.

The counts you have seen quoted come from breach notifications made to state and federal regulators, and they have been revised upward more than once as the analysis continued.

One incident, three different totals.
October 2025. Reporting of the initial regulator notifications put the figure at roughly 10.5 million people.
February 2026. Revised state filings were reported as raising it to about 25 million. This is the number most articles still quote.
4 June 2026. HIPAA Journal reported that Conduent had given the Department of Health and Human Services Office for Civil Rights an updated total of 62,224,658 individuals.
Timeline of the Conduent January 2025 cyber event: incident detected 13 January 2025, Form 8-K filed 14 April 2025, notifications begin October 2025 at a reported 10.5 million people, state filings revised February 2026 to about 25 million, and an OCR total of 62,224,658 reported on 4 June 2026. Conduent's own SEC filings state no number.
One incident, three records. The company filings and the regulator filings do not say the same thing.

We have not independently inspected the OCR entry, and we are attributing that figure to the outlet that reported it rather than claiming it as our own reading. The practical point stands either way: if the article in front of you says 25 million, look at its date. A figure that has already been revised upward twice, and now stands at nearly six times the first one published, can move again, and “my letter never came, so I was not affected” is a conclusion the record does not support.

Document three: the letter in your hand, and the timing problem nobody mentions

Conduent’s quarterly report for the period ending 30 June 2026, filed on 10 August 2026, contains one sentence that changes how you should read anything arriving now.

From the 10-Q, filed 10 August 2026. “The Company worked with affected clients to determine next steps as required by federal and state law, including individual and regulatory notifications that began in October 2025 and have been substantially concluded.”

By the company’s own account, the official notification programme is largely finished. Yet public interest in the phrase “Conduent letter” is still rising, and local news is still running explainers telling people not to ignore the envelope.

This does not mean a letter arriving today is fake. Notifications can be sent late, they can come from the organisation you actually deal with rather than from Conduent, and settlements and claims programmes generate their own legitimate mail. It does mean that “it is about Conduent, so it must be the official notice” has stopped being a safe assumption.

There is a second sentence in the same filing worth holding onto, because a whole category of frightening messages contradicts it. Conduent states that “to the Company’s knowledge, the exfiltrated data has not been released on the dark web or otherwise publicly”. That is a statement of what the company knew at the time of filing rather than a guarantee. But it means that any message telling you your records “have been found on the dark web”, and asking you to pay or click to see the proof, is asserting something the breached company itself has not asserted.

Why a real breach is such useful cover

Impersonation works by borrowing an expectation that already exists. Tens of millions of people have now been told, correctly, that a company they had never heard of holds their Social Security number and that mail about it is legitimate. That is an unusually good starting position for a fraudulent letter, because the two things that normally make someone suspicious, an unfamiliar sender and an alarming subject, have been pre-approved by the real event.

It is the same structure as the recovery scams that follow every large fraud, and the same structure we have written about in the Impersonation Index: the fastest way to tell a real message from a copy is almost never the message itself.

How to check any letter about this, without using the letter

The method below works whether the envelope is genuine or not, which is the point. You never have to make a judgement call about wording, logos or tone.

Four checks, in order.
Go around the letter, never through it. Find the organisation you actually have a relationship with, the insurer, agency or employer named in it, and contact them on a number or web address you look up yourself. Ask whether they sent it.
Nothing legitimate here costs money. Breach notification and any monitoring offered with it are free to you. A fee, of any size, for any reason, ends the conversation.
Do not give an inbound contact what the breach already exposed. A genuine notice tells you what happened. It does not need you to confirm your Social Security number, bank details or date of birth back to it.
Enrol through the provider, not the link. If monitoring is offered, open the provider's own site directly and use the code from your letter there.

Then do the thing that helps regardless of which letters were real: freeze your credit at each of the three bureaus. It is free, it is reversible, and unlike monitoring it prevents new accounts rather than telling you afterwards. Our identity theft guide covers the steps.

What we could not establish

Stating the limits, because a page about verification should be checkable itself. We read Conduent’s 8-K and 10-Q directly from SEC EDGAR and quote them above. We did not independently inspect the HHS Office for Civil Rights entry, so the 62,224,658 figure is attributed to HIPAA Journal’s 4 June 2026 report rather than claimed as our own reading. We are not naming the monitoring provider beyond what appears in your own letter, and we make no claim about who was responsible, because those attributions vary between outlets and Conduent has not confirmed them. We also do not publish claim deadlines or payment dates for any related programme, as those are exactly the details that fabricated pages get wrong.

Sources

Company filings read directly from SEC EDGAR. Reported figures attributed to the outlet that published them.

Conduent Form 8-K, Item 1.05, 14 Apr 2025Conduent Form 10-Q, 10 Aug 2026HIPAA Journal — updated OCR totalHHS OCR Breach PortalFTC — IdentityTheft.gov
ORIGINAL DATA
Does that company actually text you? What real senders say they will never do
GUIDE
Identity theft: freezing your credit, and what to do after a breach
THE SECOND WOUND
Why one breach turns into a stream of approaches, and what a sucker list is