Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider, Double-Extortion Data Theft via VPN Credential Abuse — Threadlinqs Intelligence
As of 2026-05-30, Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider, Double-Extortion Data Theft via VPN Credential Abuse is a high-severity ransomware threat attributed to Safepay (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0161 · Severity: HIGH · Status: MONITORING · Category: RANSOMWARE
Attribution: Safepay · Russia · FINANCIAL
The Safepay ransomware group compromised Conduent, a major BPO provider servicing government agencies (toll systems, benefits), healthcare organizations, and enterprises including Volvo Group. The
Conduent is an American business process outsourcing (BPO) company spun off from Xerox in 2017, employing 56,000 people across 22 countries with $3.4 billion annual revenue. The company provides digital platforms and services for government agencies (toll systems, benefits administration, child support, Medicaid), healthcare organizations, insurers, and enterprises.
**Breach Timeline and Scope**: The threat actor gained initial access to Conduent's environment on October 21, 2024. The breach was discovered in January 2025 when a service outage revealed the compromise. Conduent disclosed the cybersecurity incident in April 2025 via SEC Form 8-K filing. Data breach notifications filed with US Attorney General offices confirm massive impact: 10.5 million affected in Oregon, 15.5 million in Texas (as reported by Volvo Group notification), 76K in Washington, with additional states yet to report. The total exceeds 25 million individuals.
**Data Exposed**: Names, Social Security Numbers, full dates of birth, health insurance policy/ID numbers, and medical information. This combination of PII and PHI creates extreme downstream risk for identity theft, medical fraud, synthetic identity creation, and targeted phishing campaigns.
**Safepay Ransomware Technical Analysis**: Safepay is a relatively new ransomware operation first observed in October 2024 by Huntress analysts, accumulating over 220 victims as of mid-2025. Analysis by Huntress reveals the ransomware binary (locker.dll) is derived from leaked LockBit source code, sharing extensive code similarities with LockBit samples from late 2022.
Key technical characteristics:
- **Execution**: Deployed via regsvr32.exe with command-line flags: -pass (password), -enc (encryption level), -uac (UAC bypass), -path (target path), -network (propagation), -selfdelete, -logging
- **Initial Access**: VPN gateway credential compromise (GlobalProtect VPN in Ingram Micro case) using compromised credentials and password spray attacks
- **Lateral Movement**: RDP with valid credentials. No new account creation or persistence mechanisms observed — relies on valid credentials throughout
- **Discovery**: ShareFinder.ps1 (Veil-PowerView) to enumerate accessible network shares
- **Defense Evasion**: Disabling Windows Defender Real-Time Protection and Automatic File Submission via GUI (SystemSettingsAdminFlows.exe), CMSTPLUA COM Object UAC bypass (DllHost.exe parent), SeDebugPrivilege token escalation, ThreadHideFromDebugger on worker threads
- **Data Collection**: WinRAR archiving with -v5g volume splitting, -r recursive, extensive file type exclusions, archiving from remote UNC paths
- **Exfiltration**: FileZilla FTP client for data transfer (installed, used, then uninstalled)
- **Encryption**: Multi-threaded encryption via worker thread pool (LockBit-derived), AES encryption with RSA key wrapping, .safepay extension appended
- **Anti-Analysis**: Cyrillic language killswitch (GetSystemDefaultUILanguage check), XOR-based string obfuscation (random single-byte key + index + first byte of kernel32.dll 'M'), token impersonation via DuplicateToken
- **Process/Service Termination**: Terminates SQL, Oracle, Exchange, Sophos, Veeam, backup services and Office/browser processes before encryption
- **Shadow Copy Deletion**: bcdedit /set recoveryenabled no + wmic shadowcopy delete
**Double-Extortion Model**: Safepay operates a Tor-based leak site listing victims with downloadable stolen data. They also maintain a TON (The Open Network/Telegram-based) site. The group's ransom note (readme_safepay.txt) claims data theft and threatens publication.
**Downstream Impact**: Conduent's client Volvo Group North America confirmed 17,000 customers/staff had personal details exposed. Multiple state government agencies processing benefits, child support, and Medicaid through Conduent were affected. The breach creates cascading risk across government services and healthcare systems that relied on Conduent for data processing.
**Prio
Weaknesses (CWE)
CWE-522, CWE-306, CWE-284
Target sectors: government, healthcare, technology, transportation, financial, insurance, critical-infrastructure
Target regions: North America, Europe
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078, T1078.002, T1133, T1059.001, T1059.003, T1569.002, T1078, T1548.002, T1134.001, T1562.001