Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachmass-credential-exposurebreach-disclosure-notificationhealthcare-sector-threat

Third-Party Healthcare and Benefits Service Provider Breaches Expand to Millions of Victims

Updated 3mo agoFirst seen Feb 27, 20262 sources

Health insurance technology provider TriZetto Provider Solutions (a Cognizant subsidiary) updated breach notifications indicating the impact of its November 2024 intrusion has grown to more than 3.4 million affected individuals. Disclosures to state regulators and downstream notifications from county governments and healthcare providers indicate theft of sensitive personal data including addresses, Social Security numbers, and health insurance identifiers, with some jurisdictions reporting hundreds of thousands of impacted residents.

Separately, the Conduent incident has expanded dramatically in public filings, with reported totals rising from roughly 10.5 million to more than 25 million affected individuals across the US, including a major increase in Texas (reported at 15.4 million) while Oregon remains around 10.5 million. Reporting indicates attackers maintained access for roughly three months and exfiltrated about 8 TB of data, underscoring the systemic risk posed by large, behind-the-scenes vendors that support Medicaid/SNAP and other state benefit programs, healthcare-related processing, and major employer services—creating a wide “blast radius” even for individuals unfamiliar with the vendor name.

Share:
Third-Party Healthcare and Benefits Service Provider Breaches Expand to Millions of Victims
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 27, 20264mo ago

TriZetto files updated Oregon disclosure exceeding 3.4 million victims

TriZetto Provider Solutions submitted an updated breach disclosure to Oregon's Justice Department reporting that the 2024 incident affected more than 3.4 million individuals. The filing followed earlier notifications to other U.S. regulators, including disclosures reflected in Texas and South Carolina figures.

Feb 26, 20264mo ago

Conduent breach total rises above 25 million people

Updated state notifications reportedly expanded the known impact of the Conduent breach from about 10.5 million to more than 25 million people nationwide. Texas' estimated affected population reportedly increased from roughly 4 million to 15.4 million residents.

Conduent breach disclosures put impact at about 10.5 million

Initial state breach notifications for the Conduent incident reportedly indicated that about 10.5 million people were affected. Oregon's reported total was around 10.5 million individuals.

SafePay ransomware gang claims the Conduent attack

The Conduent incident was later claimed by the SafePay ransomware gang. Reportedly exposed data included Social Security numbers, government identifiers, and medical and insurance information.

Nov 1, 20258mo ago

Conduent attackers maintain access and exfiltrate 8 TB of data

Attackers reportedly remained inside Conduent's environment for about three months and stole approximately 8 TB of data. The compromise affected a vendor that supports state benefit programs, healthcare-related payment and mailroom services, and corporate back-office and HR functions.

Nov 1, 20242y ago

TriZetto suffers breach affecting healthcare data

In November 2024, TriZetto Provider Solutions was hacked, leading to the theft of sensitive personal and health insurance data. Oregon county governments later said the incident exposed details including addresses, Social Security numbers, and health insurance numbers for more than 700,000 people.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Organizations
8 linked
Recorded FutureCognizantThe RecordThe Clorox CompanyTriZetto Provider SolutionsVolvoConduentBlue Cross Blue Shield
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Third-Party Healthcare and Benefits Service Provider Breaches Expand to Millions of Victims | Mallory