Conduent Breach Affected at Least 25 Million Americans, and Counting

Plus, new research from Palo Alto Networks found that a massive cyber-espionage campaign has compromised at least 70 organizations across 37 countries in the last year.

Good morning! Here’s what’s up.

People

Helen Christakos has joined the global privacy and cybersecurity group of law firm Norton Rose Fulbright as a partner in the San Francisco office.

Clips ✂️

Conduent Breach Explodes: 25M+ Americans Hit in Govtech Hack

A ransomware attack on government technology giant Conduent has ballooned into one of the largest data breaches in recent history, affecting at least 25.9 million Americans - and the final count could soar much higher. The January 2025 breach, which initially appeared to impact 4 million Texans, now reveals a far more catastrophic scope as state attorneys general across the country report staggering victim numbers. With Conduent handling personal and health data for over 100 million Americans through government contracts, the company's silence on total victim counts is raising alarm bells across Washington.

The scale of the Conduent breach is unprecedented in govtech. What started as a January 2025 ransomware attack that knocked out operations for several days has metastasized into a data exposure event affecting tens of millions of Americans - with the final victim count still unknown.

Texas alone saw 15.4 million residents impacted, accounting for roughly half the state's population. That's a dramatic escalation from the 4 million initially reported in October. Oregon's attorney general confirmed another 10.5 million affected residents. Add in the hundreds of thousands notified across Delaware, Massachusetts, New Hampshire, and other states, and you're looking at a breach that could dwarf most corporate data disasters in recent memory.

by The Tech Buzz

Hackers hit sensitive targets in 37 nations in vast spying plot

An Asian cyberespionage group has spent the past year breaking into computer systems belonging to governments and critical infrastructure organizations in more than 37 countries, according to the cybersecurity firm Palo Alto Networks.

The state-aligned attackers have infiltrated networks of 70 organizations, including five national law enforcement and border control agencies, according to a new research report from the company. They have also breached three ministries of finance, one country’s parliament and a senior elected official in another, the report states. The Santa Clara, California-based firm declined to identify the hackers’ country of origin.

The spying operation was unusually vast and allowed the hackers to hoover up sensitive information in apparent coordination with geopolitical events, such as diplomatic missions, trade negotiations, political unrest and military actions, according to the report.

by Bloomberg

Hackers claim 1.4 TB theft from Iron Mountain, major data management company

Everest ransomware gang posted Iron Mountain on its dark web leak site, which it uses to showcase and threaten its latest victims. The post says attackers accessed internal documents with a “variety of personal documents and information of clients,” totalling 1.4 TB of data.

Iron Mountain is a major information management company, providing records management, data backup, and information destruction services. The company handles digital as well as physical data.

After the article went live, the company issued a public statement, saying that "Iron Mountain confirms that it was alerted about a cybersecurity," and that the company is "assessing the situation."

“No customer confidential or sensitive information has been involved. A single compromised login credential was used to gain access to one folder, consisting primarily of marketing materials shared with third-party vendors on a public-facing file-sharing site,” Iron Mountain said.

by Cybernews

AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+

Fraudsters significantly ramped up their use of AI to enhance campaigns across voice and virtual meeting channels last year, boosting speed and volume, according to Pindrop.

The voice authentication and deepfake detection specialist said its new report, Inside the 2025 AI Fraud Spike, is based on its own data collected between January and December 2025.

The firm pointed to a 1210% increase in AI-enabled fraud during this time, versus a 195% surge in traditional fraud.

The reasons for the growing popularity of deepfakes, voice bots, and “AI-generated interactions” is simple – it’s cheaper, faster, harder to detect, and incredibly scalable, said Pindrop.

“We saw it first in contact centers, where synthetic voices and automated social engineering bypassed controls in seconds,” the report noted.

“Now, the same tactics are rippling across real-time interactions that rely on trust: from remote job interviews to financial transactions and beyond. For CISOs and CTOs, this isn’t just another trend – it’s a fundamental shift in how fraud operates and how trust breaks at enterprise scale.”

by Infosecurity Magazine

The Godfather of Ransomware? Inside DragonForce’s Cartel Ambitions

The Cybereason, A LevelBlue Company, Threat Intelligence Team conducted an analysis of DragonForce, a ransomware group that emerged in late 2023 as a significant cyber threat actor.

DragonForce employs advanced methodologies, using a dual-extortion strategy in which they not only encrypt critical business data but also exfiltrate sensitive information, threatening to release it on dark web leak sites unless the ransom is paid.

DragonForce has targeted a variety of sectors, with a notable focus on manufacturing and construction, and has impacted several high-profile organizations. The group has shown adaptability by continuously refining its tools and tactics, moving from dedicated victim sites to a centralized domain for hosting leaked data. This rapid evolution keeps them a persistent and growing threat to businesses worldwide.

by LevelBlue

OpenAI’s new model leaps ahead in coding capabilities—but raises unprecedented cybersecurity risks

OpenAI believes it has finally pulled ahead in one of the most closely watched races in artificial intelligence: AI-powered coding. Its newest model, GPT-5.3-Codex, represents a solid advance over rival systems, showing markedly higher performance on coding benchmarks and reported results than earlier generations of both OpenAI’s and Anthropic’s models—suggesting a long-sought edge in a category that could reshape how software is built.

But the company is rolling out the model with unusually tight controls and delaying full developer access as it confronts a harder reality: The same capabilities that make GPT-5.3-Codex so effective at writing, testing, and reasoning about code also raise serious cybersecurity concerns. In the race to build the most powerful coding model, OpenAI has run headlong into the risks of releasing it.

by Fortune

X