XML 8 R2.htm IDEA: XBRL DOCUMENT v3.25.1
Material Cybersecurity Incident Disclosure
Apr. 09, 2025
Material Cybersecurity Incident [Line Items]  
Material Cybersecurity Incident Nature [Text Block]
On January 13, 2025, Conduent Incorporated (the "Company") experienced an operational disruption and learned that a ‘threat actor’ gained unauthorized access to a limited portion of the Company’s environment. Upon detection, the Company activated its cybersecurity response plan with the help of external cybersecurity experts to contain, assess, and remediate the incident. The Company restored the affected systems and returned to normal operations within days, and in some cases, hours. The disruption did not have a material impact to the Company’s operations.
Material Cybersecurity Incident Scope [Text Block] The disruption did not have a material impact to the Company’s operations.
As part of its ongoing investigation, the Company determined that the threat actor exfiltrated a set of files associated with a limited number of the Company’s clients. Due to the complexity of the files, the Company engaged cybersecurity data mining experts to evaluate the exfiltrated data and was recently informed of its nature, scope and validity, confirming that the data sets contained a significant number of individuals’ personal information associated with our clients' end-users. The Company is continuing to further analyze and document the precise and detailed impact of the data exfiltrated, and clients are being informed as appropriate in order to determine next steps as required by federal and state law. To the Company’s knowledge, the exfiltrated data has not been released on the dark web or otherwise publicly.
Material Cybersecurity Incident Timing [Text Block] On January 13, 2025, Conduent Incorporated (the "Company") experienced an operational disruption and learned that a ‘threat actor’ gained unauthorized access to a limited portion of the Company’s environment.
Material Cybersecurity Incident Material Impact or Reasonably Likely Material Impact [Text Block] While the Company did not experience material impacts to its operating environment or costs from the event itself, the Company has incurred and accrued material non-recurring expenses in the first quarter related to the event based on potential notification requirements. The Company maintains a cyber insurance policy and has also notified federal law enforcement authorities of the incident.