Volvo Group North America disclosed an indirect data breach after attackers compromised systems at its vendor Conduent, a business process outsourcing provider that handles workforce benefits and other back-office services. Notifications and regulatory filings indicate 16,991 affected individuals tied to Volvo in the US, with intruders having access to Conduent environments from October 21, 2024 to January 13, 2025; Volvo learned in late January and later confirmed its exposure as Conduent and customers worked to determine downstream impact.
Exposed data included names, with reporting also describing theft of highly sensitive identifiers such as SSNs, dates of birth, and health/insurance-related information (e.g., policy details and medical data), though the exact data elements may vary by individual. Conduent reported discovering the intrusion in January 2025, taking containment actions and engaging forensic investigators; impacted parties are being offered identity monitoring/credit monitoring services and advised to consider fraud alerts or credit freezes, underscoring the extended notification timelines and broad blast radius typical of large third-party service provider breaches.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
By February 2026, reporting on the Conduent case publicly linked the intrusion to the SafePay ransomware group, though Conduent had not confirmed the attribution in the cited coverage. The reporting also highlighted the long delay between Conduent's 2025 detection and downstream customer notification.
Volvo notified regulators that the third-party Conduent breach exposed sensitive personal and health-related information for nearly 17,000 affected individuals. Conduent began sending notifications on behalf of customers and offered identity monitoring and related protection services.
Volvo Group North America said it learned in late January 2026 that data tied to current or former health plans had been accessed through Conduent's systems. The company later reported that nearly 17,000 of its employees and/or customers were affected in the United States.
Subsequent regulatory disclosures indicated the scope of the Conduent breach expanded significantly, with reported totals rising from about 10 million people to roughly 25 million. State filings cited impacts including 10.5 million people in Oregon and 15.5 million in Texas, alongside additional affected organizations such as insurers and Wisconsin state agencies.
Conduent said it learned of the incident on January 13, 2025, and that the unauthorized access window ran from October 21, 2024, to January 13, 2025. The company locked down affected systems and engaged forensic investigators after discovery.
Attackers gained access to Conduent systems on October 21, 2024, starting an intrusion that would later be tied to theft of sensitive personal and health-related data from Conduent customers' records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.