Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider, Double-Extortion Data Theft via VPN Credential Abuse
Conduent Safepay Ransomware Breach (TL-2026-0161), also tracked as Conduent Breach 2025, is a high-severity ransomware operation, first published 2026-03-01. It is attributed to Safepay (Russia) with medium confidence, affects Conduent Business Process Outsourcing Platform, maps to 25 MITRE ATT&CK techniques (T1018, T1021.001, T1021.002), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0161
- Threat ID
- TL-2026-0161
- Also known as
- Conduent Breach 2025, Safepay Ransomware
- Severity
- HIGH
- Status
- MONITORING
- Category
- RANSOMWARE
- First published
- 2026-03-01
- Last reviewed
- 2026-03-01
- Attribution
- Safepay
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government, healthcare, technology, transportation, financial, insurance, critical-infrastructure
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Conduent Safepay Ransomware Breach
Malware and tooling: SafePay, FilZilla, Veil-PowerView
The Safepay ransomware group compromised Conduent, a major BPO provider servicing government agencies (toll systems, benefits), healthcare organizations, and enterprises including Volvo Group. The breach — originating from October 2024 with discovery in January 2025 — exposed personal data of 25+ million people including SSNs, dates of birth, medical information, and health insurance details. Safepay operates a double-extortion model using a LockBit-derived ransomware binary (locker.dll via regsvr32), with initial access via VPN credential compromise and RDP lateral movement.
How Conduent Safepay Ransomware Breach works
Conduent is an American business process outsourcing (BPO) company spun off from Xerox in 2017, employing 56,000 people across 22 countries with $3.4 billion annual revenue. The company provides digital platforms and services for government agencies (toll systems, benefits administration, child support, Medicaid), healthcare organizations, insurers, and enterprises. **Breach Timeline and Scope**: The threat actor gained initial access to Conduent's environment on October 21, 2024. The breach was discovered in January 2025 when a service outage revealed the compromise. Conduent disclosed the cybersecurity incident in April 2025 via SEC Form 8-K filing. Data breach notifications filed with US Attorney General offices confirm massive impact: 10.5 million affected in Oregon, 15.5 million in Texas (as reported by Volvo Group notification), 76K in Washington, with additional states yet to report. The total exceeds 25 million individuals. **Data Exposed**: Names, Social Security Numbers, full dates of birth, health insurance policy/ID numbers, and medical information. This combination of PII and PHI creates extreme downstream risk for identity theft, medical fraud, synthetic identity creation, and targeted phishing campaigns. **Safepay Ransomware Technical Analysis**: Safepay is a relatively new ransomware operation first observed in October 2024 by Huntress analysts, accumulating over 220 victims as of mid-2025. Analysis by Huntress reveals the ransomware binary (locker.dll) is derived from leaked LockBit source code, sharing extensive code similarities with LockBit samples from late 2022. Key technical characteristics: - **Execution**: Deployed via regsvr32.exe with command-line flags: -pass (password), -enc (encryption level), -uac (UAC bypass), -path (target path), -network (propagation), -selfdelete, -logging - **Initial Access**: VPN gateway credential compromise (GlobalProtect VPN in Ingram Micro case) using compromised credentials and password spray attacks - **Lateral Movement**: RDP with valid credentials. No new account creation or persistence mechanisms observed — relies on valid credentials throughout - **Discovery**: ShareFinder.ps1 (Veil-PowerView) to enumerate accessible network shares - **Defense Evasion**: Disabling Windows Defender Real-Time Protection and Automatic File Submission via GUI (SystemSettingsAdminFlows.exe), CMSTPLUA COM Object UAC bypass (DllHost.exe parent), SeDebugPrivilege token escalation, ThreadHideFromDebugger on worker threads - **Data Collection**: WinRAR archiving with -v5g volume splitting, -r recursive, extensive file type exclusions, archiving from remote UNC paths - **Exfiltration**: FileZilla FTP client for data transfer (installed, used, then uninstalled) - **Encryption**: Multi-threaded encryption via worker thread pool (LockBit-derived), AES encryption with RSA key wrapping, .safepay extension appended - **Anti-Analysis**: Cyrillic language killswitch (GetSystemDefaultUILanguage check), XOR-based string obfuscation (random single-byte key + index + first byte of kernel32.dll 'M'), token impersonation via DuplicateToken - **Process/Service Termination**: Terminates SQL, Oracle, Exchange, Sophos, Veeam, backup services and Office/browser processes before encryption - **Shadow Copy Deletion**: bcdedit /set recoveryenabled no + wmic shadowcopy delete **Double-Extortion Model**: Safepay operates a Tor-based leak site listing victims with downloadable stolen data. They also maintain a TON (The Open Network/Telegram-based) site. The group's ransom note (readme_safepay.txt) claims data theft and threatens publication. **Downstream Impact**: Conduent's client Volvo Group North America confirmed 17,000 customers/staff had personal details exposed. Multiple state government agencies processing benefits, child support, and Medicaid through Conduent were affected. The breach creates cascading risk across government services and healthcare systems that relied on Conduent for data processing. **Prior Conduent Breach**: Conduent was previously hit by Maze ransomware in June 2020, making this their second major ransomware incident. The Safepay attack is significantly larger in scope. **Safepay's Other Major Victim**: IT giant Ingram Micro suffered a SafePay attack in July 2025, with 3.5TB threatened for leak and 42,000 people confirmed affected. The attack pattern was identical — VPN credential compromise, RDP lateral movement, WinRAR archiving, FileZilla exfiltration.
MITRE ATT&CK techniques used in TL-2026-0161
discovery
T1018 Remote System Discovery; T1082 System Information Discovery; T1135 Network Share Discovery
lateral-movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares
defense-evasion
T1027 Obfuscated Files or Information; T1070.004 File Deletion; T1078 Valid Accounts; T1078.002 Domain Accounts; T1134.001 Token Impersonation/Theft; T1218.010 Regsvr32; T1480.001 Environmental Keying
collection
T1039 Data from Network Shared Drive; T1560.001 Archive via Utility
exfiltration
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1569.002 Service Execution
credential-access
persistence
T1133 External Remote Services
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
privilege-escalation
T1548.002 Bypass User Account Control
defense-impairment
Affected products and versions in Conduent Safepay Ransomware Breach
- Conduent — Business Process Outsourcing Platform
Vulnerable versions: All — October 2024 compromise
Fixed in: Post-January 2025 remediation - Multiple — State Government Agencies (Oregon, Texas, Washington)
Vulnerable versions: Benefits, Medicaid, child support systems processed by Conduent - Volvo Group — North America Operations
Vulnerable versions: Customer and employee records via Conduent BPO - Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022
Remediation for Conduent Safepay Ransomware Breach
Immediate actions
- Block known Safepay IOCs at perimeter (SHA256 hashes, workstation names)
- Audit all VPN gateway access logs for compromised credentials and password spray attempts
- Force MFA on all VPN and RDP access immediately
- Hunt for regsvr32.exe executing locker.dll or any DLL with -pass/-enc flags
- Monitor for ShareFinder.ps1 or Veil-PowerView activity
- Check for WinRAR/FileZilla recent installations and executions
- Verify Windows Defender Real-Time Protection is enabled and hasn't been disabled via GUI
Workarounds
- Disable RDP where not required
- Block regsvr32.exe for non-administrative users via AppLocker
- Monitor and alert on bcdedit and wmic shadowcopy delete commands
- Restrict WinRAR and FileZilla installation to approved users only
Longer-term hardening
- Implement network segmentation to limit RDP lateral movement
- Deploy EDR with ransomware canary file detection
- Enforce application whitelisting to prevent unauthorized regsvr32.exe DLL loading
- Monitor for CMSTPLUA COM Object UAC bypass (DllHost.exe with CLSID in command line)
- Implement VPN gateway hardening with certificate-based authentication
- Deploy PAM solution to rotate and monitor privileged credentials
- Enable VSS protection and immutable backup solutions
Weaknesses (CWE) in Conduent Safepay Ransomware Breach
CWE-522, CWE-306, CWE-284
Timeline of Conduent Safepay Ransomware Breach
- Conduent previously hit by Maze ransomware — first major ransomware incident. Source: https://www.bleepingcomputer.com/news/security/business-services-giant-conduent-hit-by-maze-ransomware/
- Safepay ransomware first observed by Huntress analysts in October 2024. LockBit-derived binary. Two initial incidents across disparate customer infrastructures. Source: https://www.huntress.com/blog/its-not-safe-to-pay-safepay
- Safepay threat actor gains initial access to Conduent environment via VPN credential compromise. Environment compromised for ~3 months before discovery.
- Conduent discovers the breach after service outage. Cybersecurity incident confirmed publicly January 22, 2025. Source: https://www.bleepingcomputer.com/news/security/conduent-confirms-cybersecurity-incident-behind-recent-outage/
- Safepay ransomware group claims responsibility for the Conduent breach on their Tor leak site.
- Conduent discloses in SEC Form 8-K that threat actors stole files containing customer information and customer client data. Source: https://www.bleepingcomputer.com/news/security/govtech-giant-conduent-confirms-client-data-stolen-in-january-cyberattack/
- IT giant Ingram Micro suffers SafePay ransomware attack via GlobalProtect VPN credential compromise. 3.5TB data threatened. 42,000 people affected. Source: https://www.bleepingcomputer.com/news/security/ingram-micro-outage-caused-by-safepay-ransomware-attack/
- Conduent data breach notifications confirm 10.5 million affected in Oregon, 4 million in Texas, 76K in Washington. Source: https://www.bleepingcomputer.com/news/security/bpo-giant-conduent-confirms-data-breach-impacts-105-million-people/
- Volvo Group North America discloses 17,000 customers/staff affected via Conduent breach. Texas total reaches 15.5 million. Source: https://www.bleepingcomputer.com/news/security/volvo-group-north-america-customer-data-exposed-in-conduent-hack/
- Threadlinqs Intelligence publishes comprehensive analysis combining Conduent breach scope (25M+ records) with Safepay ransomware technical analysis.
- As of 2026-05-29, the specific Conduent breach is contained (systems restored, SEC-disclosed, no CVE to patch), but the SafePay ransomware actor remains fully active — Ransom-DB/ransomware.live track 400-483 victims with the latest discovery on 2026-05-25 and an early-2026 resurgence. The actor-level threat (VPN-credential/RDP TTPs) is ongoing and undisrupted, warranting continued monitoring.
Sources cited for Conduent Safepay Ransomware Breach
- BleepingComputer — BPO giant Conduent confirms data breach impacts 10.5 million people
- BleepingComputer — Volvo Group North America customer data exposed in Conduent hack
- Huntress — It's Not Safe to Pay SafePay (Ransomware Technical Analysis)
- BleepingComputer — Ingram Micro outage caused by SafePay ransomware attack
- BleepingComputer — SafePay ransomware threatens to leak 3.5TB of Ingram Micro data
- BleepingComputer — Govtech giant Conduent confirms client data stolen in January cyberattack
- BleepingComputer — Conduent confirms cybersecurity incident behind recent outage
- Maine Attorney General — Conduent Data Breach Notification
- NCC Group — Weak Passwords Led to SafePay Ransomware Yet Again
- DCSO CyTec — SafePay: The New Kid on the Block
- BleepingComputer — Business services giant Conduent hit by Maze Ransomware (2020)
Threats related to Conduent Safepay Ransomware Breach
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration
- VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data Destruction (Wiper-by-Accident) Across Windows, Linux, and ESXi
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of Clinical/Pharmacovigilance Records
Detection coverage for TL-2026-0161
As of 2026-03-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0161 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.