Conduent reached the agreement in principle in August 2026, but it became public on September 10, 2026, when the parties told the court — and the filing that followed carries no dollar figure.
What happened
Conduent Incorporated filed an 8-K with the Securities and Exchange Commission on September 10, 2026, disclosing that it has agreed in principle to settle the consolidated class action arising from the cybersecurity incident it suffered in January 2025. The filing is accession number 0001677703-26-000113, CIK 0001677703, document cndt-20260910.htm, and its cover page gives the date of earliest event reported as September 10, 2026.
It is filed under “Item 8.01. Other Events.” That matters.
The narrative runs to seven sentences. Conduent and Conduent Business Services, LLC “are parties to several lawsuits in the U.S. asserted by or on behalf of individuals who allegedly received a notification letter that their personal information may have been affected by our previously disclosed cybersecurity incident that took place in January 2025.” Those suits, the company says, “have been consolidated into one single action in the U.S. District Court, District of New Jersey (In re: Conduent Business Services Data Breach Litigation).”
Conduent does not concede the claims. “The Company denies plaintiffs’ allegations and believes that it has strong defenses to plaintiffs’ claims.” The settlement is framed as a cost decision: “Nevertheless, to avoid the costs and burdens of litigation, in August 2026, the Company reached an agreement in principle to settle the consolidated case, which the parties disclosed in a joint status report filed with the Court on September 10, 2026.”
Two sentences hedge the timeline: “The settlement paperwork is not yet finalized, and the settlement agreement has not yet been approved by the court,” and the timing of final court approval “cannot be predicted with certainty.”
The last sentence is the financial one: “The Company maintains cyber insurance and does not expect the settlement to have a material impact on its financial position, results of operations or cash flows.”
No settlement amount appears anywhere in the filing. Neither does a class size nor a range.
The same company filed the incident itself under Item 1.05
On April 14, 2025, Conduent filed a different 8-K about the same incident, and that one is captioned “Item 1.05. Material Cybersecurity Incidents” — the item the SEC created specifically for material cybersecurity incidents.
That filing says “On January 13, 2025, Conduent Incorporated (the ‘Company’) experienced an operational disruption,” that the company activated its response plan, and that it “restored the affected systems and returned to normal operations within days.” On the data, it says a threat actor “exfiltrated a set of files associated with a limited number of the Company’s clients,” and that those files contained “a significant number of individuals’ personal information associated with our clients’ end-users.”
It also splits materiality in two, which is easy to miss. On operations: “The disruption did not have a material impact to the Company’s operations.” On money: “the Company has incurred and accrued material non-recurring expenses in the first quarter related to the event based on potential notification requirements.” And on exposure at the time: “To the Company’s knowledge, the exfiltrated data has not been released on the dark web or otherwise publicly.”
So the same incident produced a 1.05 in April 2025 and an 8.01 in September 2026, seventeen months apart, from the same registrant.
The number that is not in either filing
Neither 8-K states how many people were affected. The count has instead accumulated across regulators, and it has moved a great deal.
Figures reported in circulation, with the venues they were reportedly filed in: roughly 25 million, attributed to a Wisconsin state filing in February 2025; 14,791,500 and later 15,494,592 in Texas attorney general filings during October 2025; 10,515,849 in a notification to state regulators dated October 28, 2025; and 62,224,658 reported to the Department of Health and Human Services Office for Civil Rights in June 2026. A separate, far smaller OCR entry of 42,616 was last updated on September 24, 2025.
These are not all measuring the same thing — state filings count residents of that state, and the OCR figure counts individuals whose protected health information was involved across covered entities Conduent serves as a business associate. But they are the numbers the public record offers, they disagree by a factor of six at the top end, and the largest arrived roughly fourteen months after the incident. We could not confirm the 62,224,658 figure against the OCR portal directly; see the sourcing note.
Why it matters
The first thing worth taking from this is that the Item number on a cybersecurity 8-K is information, and it is routinely flattened in coverage. Item 1.05 is for a cybersecurity incident the registrant has determined to be material. Item 8.01 is the general “other events” item, used for disclosures a company chooses or is otherwise obliged to make. A settlement of litigation that arose from an incident is not itself a material cybersecurity incident, so 8.01 is the correct home for it. Conduent using 1.05 for the event and 8.01 for the settlement is the architecture working as designed, and it is a cleaner example than most. This publication has previously followed the reverse sequence at Boston Scientific, where an 8.01 preceded a 1.05.
The second thing is the disclosure trigger, which is not the deal. Conduent reached the agreement in principle in August 2026. The market learned about it on September 10, 2026, and the filing is explicit about why: the parties “disclosed in a joint status report filed with the Court” that day. The 8-K follows the docket. That is lawful and ordinary, but it has a consequence for anyone who watches 8-K traffic as a signal — the timing of a settlement disclosure tracks the litigation calendar rather than the company’s own view of when the news matured. Reading 8-K dates as event dates will mislead you.
The third is the absent amount, and it is worth being precise about what its absence does and does not tell you. Read together, “maintains cyber insurance” and “does not expect the settlement to have a material impact” describe the company’s expectation of the net figure after insurance — not the gross settlement, and not what class members will receive. Those are different numbers, and only the net one is characterized here. For an incident whose count in the public record sits above 60 million individuals, the per-person economics cannot be derived from this filing at all.
The absence is also temporary. Class settlements do not stay private: the amount, the class definition, and the claims process all become public when plaintiffs move for preliminary approval in the District of New Jersey. That motion is where the number will be, and it is the document to watch rather than the next 8-K.
The fourth is the drift in the count itself, which is the most portable lesson here. Anyone who sized their own third-party exposure from April 2025’s “a limited number of the Company’s clients,” and never revisited it, was working from a number that later grew by orders of magnitude. Breach counts are not stable for a year or more after an incident, and the first number a company publishes is the floor of an estimate, not a measurement.
What to do
There is nothing to patch here; the actions are recordkeeping and monitoring.
If your organization is a Conduent client, or contracts with a government program Conduent administers, re-pull the current affected count for your own population rather than relying on the figure you recorded in 2025. The counts above moved repeatedly, and upward.
If you maintain a third-party incident register, this is the case for a field that records when a count was last confirmed, not just the count. A register holding “Conduent, ~10 million, October 2025” is not wrong so much as stale, and staleness in that field is invisible.
Watch the docket in the District of New Jersey for the preliminary approval motion. That filing, not the next 8-K, will carry the settlement amount and the class definition.
And for anyone who prepares these filings: the pair here is a reasonable model. The incident determination goes in 1.05; the downstream litigation event goes in 8.01, with the materiality statement scoped to the settlement rather than to the incident.
Sourcing note
The September 10, 2026 filing was read directly from the SEC’s EDGAR archive — accession 0001677703-26-000113, document cndt-20260910.htm — and every sentence quoted above is quoted from it verbatim. The April 14, 2025 filing was read from Conduent’s own investor relations site. A full-text search of 8-K filings mentioning a cybersecurity incident over September 10 and 11, 2026 returned this filing and no other.
The affected-individual figures are the weakest material on this page and are labeled as reported rather than confirmed: they come from secondary compilation, not from the underlying regulator records. The HHS Office for Civil Rights breach portal is a dynamic application whose report list is not retrievable by automated fetching, so only its explanatory page could be read. The state attorney general figures were likewise not read from the state portals. Conduent has stated no count in either 8-K, so no primary-source number exists to reconcile these against.
Unresolved: the settlement amount, the class definition, the claims administration terms, and whether the gross settlement differs materially from the net figure the company characterizes. Also unresolved is whether the smaller OCR entry of 42,616 and the 62,224,658 figure are separate submissions or successive updates to one record. None of these will be answerable until the preliminary approval motion is filed.
