Why did you get a Conduent letter? And who is writing to you now that the official wave has ended.
Conduent told the SEC in August 2026 that its breach notifications “began in October 2025 and have been substantially concluded”. Searches for “Conduent letter” are still climbing. Both of those are true at once, and the gap between them is where the risk sits. This page sets out what Conduent has actually filed, what it has never said, and how to check any letter without using the letter.
You opened an envelope from a company you have never heard of. It knew your name and address, it mentioned your Social Security number, and it offered you credit monitoring. The obvious question is whether it is real.
Almost every article you will find answers that question the same way: the letter is real, do not ignore it. That answer is correct and it is incomplete, because it was written for a moment that has largely passed. There are three separate records of this incident, they were written for three different audiences, and they do not say the same thing. Reading them side by side is more useful than any checklist.
Document one: what Conduent told its investors
Public companies must disclose material cybersecurity incidents to the Securities and Exchange Commission. Conduent Incorporated, listed on NASDAQ as CNDT, filed a Form 8-K under Item 1.05 on 14 April 2025. It is short, and it is the closest thing to a primary account that exists.
The filing says systems were restored “within days, and in some cases, hours” and that the disruption “did not have a material impact to the Company’s operations”. It then says the threat actor took files belonging to “a limited number of the Company’s clients”, and that those files contained “a significant number of individuals’ personal information associated with our clients’ end-users”.
That last phrase is the whole reason you received an envelope. You were never Conduent’s customer. Conduent runs back office work for organisations that do deal with you: government agencies, health insurers, benefits and transit programmes. Your record travelled with somebody else’s contract, which is exactly why the name on the envelope means nothing to you.
Document two: what Conduent told health regulators, and why the number keeps moving
Here is the part that almost no coverage handles carefully. Conduent’s SEC filings have never stated how many people were affected. Not the 8-K in April 2025, and not the quarterly report filed sixteen months later. Both say “a significant number of individuals” and stop there.
The counts you have seen quoted come from breach notifications made to state and federal regulators, and they have been revised upward more than once as the analysis continued.

We have not independently inspected the OCR entry, and we are attributing that figure to the outlet that reported it rather than claiming it as our own reading. The practical point stands either way: if the article in front of you says 25 million, look at its date. A figure that has already been revised upward twice, and now stands at nearly six times the first one published, can move again, and “my letter never came, so I was not affected” is a conclusion the record does not support.
Document three: the letter in your hand, and the timing problem nobody mentions
Conduent’s quarterly report for the period ending 30 June 2026, filed on 10 August 2026, contains one sentence that changes how you should read anything arriving now.
By the company’s own account, the official notification programme is largely finished. Yet public interest in the phrase “Conduent letter” is still rising, and local news is still running explainers telling people not to ignore the envelope.
There is a second sentence in the same filing worth holding onto, because a whole category of frightening messages contradicts it. Conduent states that “to the Company’s knowledge, the exfiltrated data has not been released on the dark web or otherwise publicly”. That is a statement of what the company knew at the time of filing rather than a guarantee. But it means that any message telling you your records “have been found on the dark web”, and asking you to pay or click to see the proof, is asserting something the breached company itself has not asserted.
Why a real breach is such useful cover
Impersonation works by borrowing an expectation that already exists. Tens of millions of people have now been told, correctly, that a company they had never heard of holds their Social Security number and that mail about it is legitimate. That is an unusually good starting position for a fraudulent letter, because the two things that normally make someone suspicious, an unfamiliar sender and an alarming subject, have been pre-approved by the real event.
It is the same structure as the recovery scams that follow every large fraud, and the same structure we have written about in the Impersonation Index: the fastest way to tell a real message from a copy is almost never the message itself.
How to check any letter about this, without using the letter
The method below works whether the envelope is genuine or not, which is the point. You never have to make a judgement call about wording, logos or tone.
Then do the thing that helps regardless of which letters were real: freeze your credit at each of the three bureaus. It is free, it is reversible, and unlike monitoring it prevents new accounts rather than telling you afterwards. Our identity theft guide covers the steps.
What we could not establish
Stating the limits, because a page about verification should be checkable itself. We read Conduent’s 8-K and 10-Q directly from SEC EDGAR and quote them above. We did not independently inspect the HHS Office for Civil Rights entry, so the 62,224,658 figure is attributed to HIPAA Journal’s 4 June 2026 report rather than claimed as our own reading. We are not naming the monitoring provider beyond what appears in your own letter, and we make no claim about who was responsible, because those attributions vary between outlets and Conduent has not confirmed them. We also do not publish claim deadlines or payment dates for any related programme, as those are exactly the details that fabricated pages get wrong.
Sources
Company filings read directly from SEC EDGAR. Reported figures attributed to the outlet that published them.