Volvo Group North America has exposed the personal information of nearly 17,000 employees due to a significant Conduent data breach. According to a filing with the Maine Attorney General, Volvo listed late January 2026 as the date when it discovered that its employee data was compromised.
Conduent is a major business services provider that handles HR and benefits administration for the automaker.Â
The breach notification reveals that the attackers accessed and exfiltrated 16,991 employee health plan files from Volvo. While the full scope of exposed data varies by individual, compromised information includes employee names and potentially other elements, such as:
Cybercriminals maintained access to Conduent's systems for a prolonged period, from October 21, 2024, to January 13, 2025. The timeline highlights a significant delay in discovery and notification.
Although Conduent has stated there is no evidence of data misuse, the SafePay ransomware group has claimed responsibility for the attack, alleging it stole 8.5TB of data.
The data breach affecting Volvo employees is part of a much larger incident, with updated victim totals potentially reaching tens of millions, given Conduent's role in government and corporate services, as reports indicate that 25 million Americans were affected.
The SafePay claim shows how ransomware actors are targeting the supply chain to maximize impact. Reports this month revealed that 1.4 million Betterment email addresses were exposed following a third-party social engineering.
In 2025, Safepay targeted the U.S. defense contractor Hardwick Tactical and IT leader Ingram Micro, emerging as the most prolific threat actor of May 2025.