RegCorpus.comSubscribe
Missouri library
BulletinMO DCI Bulletin 26-08

26-08 - Conduent Cybersecurity Breach, May 5, 2026

Missouri · Department of Commerce and Insurance · effective May 5, 2026
First seen July 19, 2026 · last checked July 19, 2026
Version history
v1fetched Jul 19, 2026·effective May 5, 2026bdf73fe5a119
Full text
Official document · full text
1
DEPARTMENT OF COMMERCE & INSURANCE P.O. Box 690 , Jefferson C ity. Mo, 65102-0690
2
INSURANCE BULLETIN 26-08
3
Conduent Cybersecurity Breach
4
Issued: May 5, 2026
5
The following Bulletin is issued by the Missouri Department of Commerce and Insurance ("Department'? to inform and educate the reader on the specified issue. It does not have the force and effect of law, is not an evaluation of any specific facts or circumstances, and is not binding on the Department. See section 374.015, RSMo.
6
To: All entities regulated by the Department I V1 ' Ii _ /'I
7
From: Angela L. Nelson, Director ~ 17( / I ~ Re: Addendum - Conduent Cybersecurity Breach
8
This bulletin is issued as a follow-up to Insurance Bulletin 26-05 to provide additional information to insurers and other entities regulated by the Missouri Department of Commerce and Insurance ("Department") regarding the Conduent cybersecurity breach. This bulletin also requests information from insurers and other entities regulated by the Department. Background
9
Conduent Business Services, LLC (“Conduent”) provides document processing services, including receiving insurance claim forms, payment integrity services, and other back-office support services to a variety of entities, including but not limited to insurers.
10
According to media reports, on January 13, 2025, Conduent discovered that an unauthorized third party had access to a portion of its network from October 21, 2024, to January 13, 2025. The affected files contained names, addresses, social security numbers, and medical records. Reports vary on the impact of the breach, with some estimating that potentially 25 million Americans or more were affected.
11
Since the issuance of Insurance Bulletin 26-05 on March 17, 2026, the Department has been in direct contact with Conduent to better understand the Conduent cybersecurity breach and its impact on Missouri insurance consumers, and to ensure that Missourians receive the identity protection assistance they deserve.
12
To date, Conduent has been unwilling to provide the Department with the information the Department needs to assess the impact of what is reportedly one of the largest cybersecurity breaches in United States history.
13
As a result of Conduent’s lack of cooperation, the Department is reminding insurers and other entities regulated by the Department to review Insurance Bulletin 26-05 and ensure they have taken the steps outlined therein.
14
Actions Needed:
15
Because of Conduent’s failure to provide information, the Department asks that any insurer or other entity regulated by the Department that utilized the services of Conduent or any of its affiliates prior to or during the time period of the cybersecurity breach, either directly or indirectly, contact the Department’s Market Conduct Section at marketconduct@insurance.mo.gov.
16
The Department would greatly appreciate insurers or other entities also providing information on the nature of services provided by Conduent or its affiliates. This information will guide the Department’s response to the cybersecurity breach.
17
2 The Department also reminds insurers and other regulated entities of their duties to report cybersecurity breaches to the Director using the form available on the Department’s website at https://apps.dci.mo.gov/forms/CybersecurityEventNotification, and as further outlined in the resources below:
18
Insurance Bulletin 26-01 Insurance Bulletin 23-04 Section 407.1500 RSMo The Insurance Data Security Act
19
Questions for the Department regarding an entity’s duties can be sent to cyberbreach@insurance.mo.gov.
20
Questions relating to the Conduent cybersecurity breach may be directed to Conduent. Conduent has a dedicated assistance line at 877-332-1658 (toll free), Monday-Friday, from 9:00 a.m. to 9:00 p.m. Eastern Time, and may also be contacted at Attn: Data Incident, 100 Campus Drive, Suite 200, Florham Park, New Jersey 07932.
21
Questions relating to the content of this bulletin may be directed to the Department’s Market Conduct Section at marketconduct@insurance.mo.gov
22
###