Severity Daily

IT and AI security incidents, checked against the primary source

Tag: third-party risk

  • Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig told two state regulators about a breach involving Social Security numbers on September 8 and September 9, 2026, days before it publicly characterized the incident as limited — and the filings, not the firm, are where the concrete facts are.

    What happened

    Greenberg Traurig, LLP, an international law firm with more than 3,200 attorneys, has reported a data breach to at least two state attorneys general. The filings are dated September 8, 2026 in Vermont and September 9, 2026 in California. The California entry gives a breach date of August 26, 2026.

    Those are the dates that matter for anyone tracking this, and they run in that order: the incident on August 26, the Vermont notification on September 8, the California notification on September 9, and the firm’s public statement on September 10. Nothing here is fresh as of this afternoon; what is new is that the regulatory record became legible this week.

    The Vermont Attorney General’s security breach notice database lists Greenberg Traurig, LLP with a report date of September 8, 2026, 10 Vermont residents affected, and the data element involved recorded as “Social Security Numbers.” Vermont does not publish the underlying consumer notice on the portal; it makes them available on request.

    The California Attorney General’s breach list carries the entry as “Greenberg Traurig, LLP (“GT”)” with a breach date of 08/26/2026 and a reported date of 09/09/2026. California’s threshold for appearing on that list is a notice sent to more than 500 California residents, so the California filing establishes a floor of 500 people in that state alone. A sample consumer notice is posted alongside the entry as a PDF; it could not be parsed by automated fetching, and its contents are therefore not reported here.

    Separately, on September 10, 2026, the firm made a public statement. It was given to Reuters and reached us through a secondary brief rather than from the firm directly, so it is reported here as relayed, not as read at first hand: the firm is described as saying that “an unauthorized actor” accessed documents and posted them on the dark web, that its “firm systems were not compromised or breached,” and that a “limited number of documents” and a “small number of affected clients” were involved. We could not read Reuters’ report or a statement on the firm’s own site.

    What the filings settle and what they do not

    Two things are established by primary record. First, Social Security numbers are in scope — that is Vermont’s own categorization on its portal, not a characterization by anyone reporting on the incident. Second, the population is not trivially small: California’s 500-resident threshold is a floor for one state, and ten Vermonters were notified in a state of roughly 650,000 people.

    Almost everything else is open. No total count of affected individuals appears in either filing. No discovery date is published. Neither portal states how the data was taken. And the firm’s own characterization — systems not compromised, documents nonetheless accessed and posted — points at some path that the firm has not described in anything we could read. A vendor, a third-party platform, a service the firm uses, an individual account: those are the ordinary candidates, and we are not going to pick one. It is worth being explicit that “our systems were not breached” and “client documents were taken and published” are not contradictory statements. They are, together, an incomplete one.

    We are also not going to attach an attacker to this. Ransomware leak-site trackers list the firm, and a claimed group name is circulating. No named victim, regulator, or filing we read attributes the incident to anyone, and this publication does not state attribution as fact.

    Why it matters

    The most useful thing about this incident is the order in which it became public. The firm’s public statement landed on September 10. The Vermont filing predates it by two days and the California filing by one, and the filings carry harder information than the statement does — a data element, a resident count, a breach date. A reader who followed only the coverage learned that the exposure was “limited.” A reader who checked two state portals learned that Social Security numbers were involved and that more than 500 Californians were notified.

    That gap is structural, not a criticism of any particular firm. A public statement is written to characterize; a state breach filing is written to satisfy a statutory disclosure form with fields for dates, counts, and data categories. The form is the part that does not compress. State attorney general portals are among the few primary sources in this field that are searchable, dated, and free, and they are checked far less often than vendor advisories are.

    The second thing worth drawing out is what a law firm’s breach means downstream, because it is not the firm’s own risk that is interesting. A firm of this size holds other organizations’ material — deal documents, litigation files, privileged communications, regulatory correspondence, and the personal data of its clients’ employees and customers. “A small number of affected clients” can be an accurate description of a compromise that is large for each of the clients involved. The unit of harm is not the law firm; it is the client whose file was in the set. Companies that received no notification because they are not the firm’s clients may still have people in those documents — opposing parties, witnesses, employees named in a matter.

    The third is the Social Security number detail, which changes what a reasonable response looks like. Document exposure without identifiers is a confidentiality problem. Document exposure with Social Security numbers is an identity-theft problem with a much longer tail, because the identifier does not rotate. Vermont’s portal records that element for this incident, which means the notification letters in at least one state told people their Social Security number was involved.

    What to do

    There is nothing to patch. The actions here are about finding out whether you are in scope.

    If your organization uses Greenberg Traurig, ask the firm directly whether your matters are in the affected set rather than waiting to be told. The firm has described the number of affected clients as small; that is a reason to ask, not a reason to assume you are outside it. Ask specifically what categories of your data were in the exposed documents, and whether any of your employees’ or customers’ personal data was in them.

    If you receive a notification letter, it will say which of your data elements were involved. Where a Social Security number is named, a credit freeze at all three bureaus is the response that actually matters, and it is free.

    If you maintain a third-party risk register, outside counsel belongs in it. Law firms are frequently omitted from vendor inventories because they are engaged by the legal department rather than procurement, and they routinely hold more sensitive material than the SaaS vendors that do get tracked. This incident is a reasonable prompt to check whether your register has one.

    If you monitor breaches as a practice, add the California and Vermont portals to what you check. Both carried this incident before it was widely reported, and both carry incidents that are never reported at all.

    Sourcing note

    The Vermont Attorney General’s security breach notice listing and the California Attorney General’s data breach list were both read directly. Vermont is the source for the September 8, 2026 report date, the count of 10 Vermont residents, and the “Social Security Numbers” data element. California is the source for the entry name “Greenberg Traurig, LLP (“GT”),” the August 26, 2026 breach date, and the September 9, 2026 reported date, and for the fact that a sample consumer notice is posted. That notice is a PDF and could not be parsed by automated fetching, so nothing from its text is reported here — it is the document most likely to answer the open questions below, and it is publicly available to anyone who can open it.

    The firm’s public statement of September 10, 2026 was not read at first hand. It was given to Reuters, and reached this story through a secondary brief summarizing that report. The quoted fragments — “an unauthorized actor,” “firm systems were not compromised or breached,” “limited number of documents,” “small number of affected clients” — are therefore reported as relayed and should be treated as weaker than the filing data above. Neither Reuters’ report nor a statement on the firm’s own website was reachable. The figure of more than 3,200 attorneys is the firm’s generally published size and is not drawn from any filing.

    Unresolved: the total number of individuals affected across all states, the discovery date, the mechanism by which documents were obtained given the firm’s statement that its systems were not compromised, whether any client organizations have been named, and whether additional state filings exist beyond Vermont and California. No attribution is asserted. Leak-site listings and claimed actor names were not treated as evidence and are not repeated here.

  • Conduent settled the class action over its January 2025 breach with no amount disclosed, and filed it under Item 8.01 rather than 1.05

    Conduent settled the class action over its January 2025 breach with no amount disclosed, and filed it under Item 8.01 rather than 1.05

    Conduent reached the agreement in principle in August 2026, but it became public on September 10, 2026, when the parties told the court — and the filing that followed carries no dollar figure.

    What happened

    Conduent Incorporated filed an 8-K with the Securities and Exchange Commission on September 10, 2026, disclosing that it has agreed in principle to settle the consolidated class action arising from the cybersecurity incident it suffered in January 2025. The filing is accession number 0001677703-26-000113, CIK 0001677703, document cndt-20260910.htm, and its cover page gives the date of earliest event reported as September 10, 2026.

    It is filed under “Item 8.01. Other Events.” That matters.

    The narrative runs to seven sentences. Conduent and Conduent Business Services, LLC “are parties to several lawsuits in the U.S. asserted by or on behalf of individuals who allegedly received a notification letter that their personal information may have been affected by our previously disclosed cybersecurity incident that took place in January 2025.” Those suits, the company says, “have been consolidated into one single action in the U.S. District Court, District of New Jersey (In re: Conduent Business Services Data Breach Litigation).”

    Conduent does not concede the claims. “The Company denies plaintiffs’ allegations and believes that it has strong defenses to plaintiffs’ claims.” The settlement is framed as a cost decision: “Nevertheless, to avoid the costs and burdens of litigation, in August 2026, the Company reached an agreement in principle to settle the consolidated case, which the parties disclosed in a joint status report filed with the Court on September 10, 2026.”

    Two sentences hedge the timeline: “The settlement paperwork is not yet finalized, and the settlement agreement has not yet been approved by the court,” and the timing of final court approval “cannot be predicted with certainty.”

    The last sentence is the financial one: “The Company maintains cyber insurance and does not expect the settlement to have a material impact on its financial position, results of operations or cash flows.”

    No settlement amount appears anywhere in the filing. Neither does a class size nor a range.

    The same company filed the incident itself under Item 1.05

    On April 14, 2025, Conduent filed a different 8-K about the same incident, and that one is captioned “Item 1.05. Material Cybersecurity Incidents” — the item the SEC created specifically for material cybersecurity incidents.

    That filing says “On January 13, 2025, Conduent Incorporated (the ‘Company’) experienced an operational disruption,” that the company activated its response plan, and that it “restored the affected systems and returned to normal operations within days.” On the data, it says a threat actor “exfiltrated a set of files associated with a limited number of the Company’s clients,” and that those files contained “a significant number of individuals’ personal information associated with our clients’ end-users.”

    It also splits materiality in two, which is easy to miss. On operations: “The disruption did not have a material impact to the Company’s operations.” On money: “the Company has incurred and accrued material non-recurring expenses in the first quarter related to the event based on potential notification requirements.” And on exposure at the time: “To the Company’s knowledge, the exfiltrated data has not been released on the dark web or otherwise publicly.”

    So the same incident produced a 1.05 in April 2025 and an 8.01 in September 2026, seventeen months apart, from the same registrant.

    The number that is not in either filing

    Neither 8-K states how many people were affected. The count has instead accumulated across regulators, and it has moved a great deal.

    Figures reported in circulation, with the venues they were reportedly filed in: roughly 25 million, attributed to a Wisconsin state filing in February 2025; 14,791,500 and later 15,494,592 in Texas attorney general filings during October 2025; 10,515,849 in a notification to state regulators dated October 28, 2025; and 62,224,658 reported to the Department of Health and Human Services Office for Civil Rights in June 2026. A separate, far smaller OCR entry of 42,616 was last updated on September 24, 2025.

    These are not all measuring the same thing — state filings count residents of that state, and the OCR figure counts individuals whose protected health information was involved across covered entities Conduent serves as a business associate. But they are the numbers the public record offers, they disagree by a factor of six at the top end, and the largest arrived roughly fourteen months after the incident. We could not confirm the 62,224,658 figure against the OCR portal directly; see the sourcing note.

    Why it matters

    The first thing worth taking from this is that the Item number on a cybersecurity 8-K is information, and it is routinely flattened in coverage. Item 1.05 is for a cybersecurity incident the registrant has determined to be material. Item 8.01 is the general “other events” item, used for disclosures a company chooses or is otherwise obliged to make. A settlement of litigation that arose from an incident is not itself a material cybersecurity incident, so 8.01 is the correct home for it. Conduent using 1.05 for the event and 8.01 for the settlement is the architecture working as designed, and it is a cleaner example than most. This publication has previously followed the reverse sequence at Boston Scientific, where an 8.01 preceded a 1.05.

    The second thing is the disclosure trigger, which is not the deal. Conduent reached the agreement in principle in August 2026. The market learned about it on September 10, 2026, and the filing is explicit about why: the parties “disclosed in a joint status report filed with the Court” that day. The 8-K follows the docket. That is lawful and ordinary, but it has a consequence for anyone who watches 8-K traffic as a signal — the timing of a settlement disclosure tracks the litigation calendar rather than the company’s own view of when the news matured. Reading 8-K dates as event dates will mislead you.

    The third is the absent amount, and it is worth being precise about what its absence does and does not tell you. Read together, “maintains cyber insurance” and “does not expect the settlement to have a material impact” describe the company’s expectation of the net figure after insurance — not the gross settlement, and not what class members will receive. Those are different numbers, and only the net one is characterized here. For an incident whose count in the public record sits above 60 million individuals, the per-person economics cannot be derived from this filing at all.

    The absence is also temporary. Class settlements do not stay private: the amount, the class definition, and the claims process all become public when plaintiffs move for preliminary approval in the District of New Jersey. That motion is where the number will be, and it is the document to watch rather than the next 8-K.

    The fourth is the drift in the count itself, which is the most portable lesson here. Anyone who sized their own third-party exposure from April 2025’s “a limited number of the Company’s clients,” and never revisited it, was working from a number that later grew by orders of magnitude. Breach counts are not stable for a year or more after an incident, and the first number a company publishes is the floor of an estimate, not a measurement.

    What to do

    There is nothing to patch here; the actions are recordkeeping and monitoring.

    If your organization is a Conduent client, or contracts with a government program Conduent administers, re-pull the current affected count for your own population rather than relying on the figure you recorded in 2025. The counts above moved repeatedly, and upward.

    If you maintain a third-party incident register, this is the case for a field that records when a count was last confirmed, not just the count. A register holding “Conduent, ~10 million, October 2025” is not wrong so much as stale, and staleness in that field is invisible.

    Watch the docket in the District of New Jersey for the preliminary approval motion. That filing, not the next 8-K, will carry the settlement amount and the class definition.

    And for anyone who prepares these filings: the pair here is a reasonable model. The incident determination goes in 1.05; the downstream litigation event goes in 8.01, with the materiality statement scoped to the settlement rather than to the incident.

    Sourcing note

    The September 10, 2026 filing was read directly from the SEC’s EDGAR archive — accession 0001677703-26-000113, document cndt-20260910.htm — and every sentence quoted above is quoted from it verbatim. The April 14, 2025 filing was read from Conduent’s own investor relations site. A full-text search of 8-K filings mentioning a cybersecurity incident over September 10 and 11, 2026 returned this filing and no other.

    The affected-individual figures are the weakest material on this page and are labeled as reported rather than confirmed: they come from secondary compilation, not from the underlying regulator records. The HHS Office for Civil Rights breach portal is a dynamic application whose report list is not retrievable by automated fetching, so only its explanatory page could be read. The state attorney general figures were likewise not read from the state portals. Conduent has stated no count in either 8-K, so no primary-source number exists to reconcile these against.

    Unresolved: the settlement amount, the class definition, the claims administration terms, and whether the gross settlement differs materially from the net figure the company characterizes. Also unresolved is whether the smaller OCR entry of 42,616 and the 62,224,658 figure are separate submissions or successive updates to one record. None of these will be answerable until the preliminary approval motion is filed.