TL;DR: Conduent’s breach went undetected for 83 days while attackers exfiltrated more than 8 terabytes of sensitive records, showing how perimeter-first controls can miss authorised-looking data movement, according to Nightfall. The case reinforces that content-layer visibility, lineage tracking, and automated response are now core requirements for organisations handling regulated data and third-party processing.
NHIMG editorial — based on content published by Nightfall: How Conduent Lost 25 Million Records in 83 Days: The DLP Failure Everyone Missed
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: What breaks when content-aware DLP is not in place for regulated data flows?
A: Security teams lose visibility into whether authorised traffic is carrying sensitive records out of the environment.
Q: Why do third-party processors create a larger governance problem than direct storage?
A: Because the organisation still owns the data risk even when a vendor runs the environment.
Q: How do security teams know if exfiltration controls are actually working?
A: Look for evidence that bulk file access, compression, and outbound staging are detected early and correlated with privileged sessions.
Practitioner guidance
- Deploy content-aware exfiltration controls Inspect data at the point of transfer, not just at the perimeter, so bulk movement of PHI, PII, and credentials is blocked or quarantined in real time.
- Map third-party data flows to accountable identities Inventory which service accounts, vendor users, and integration paths can move regulated data, then tie each path to an owner and an approval boundary.
- Measure detection latency for high-value records Track how long it takes to notice staged exports, compressed archives, and large outbound transfers involving regulated datasets.
What's in the full article
Nightfall's full research covers the operational detail this post intentionally leaves for the source:
- How Nightfall traces sensitive data across downloads, cloud sync, clipboard use, USB transfers, and AI prompts
- Why legacy DLP leaves 60 to 80% of sensitive data undiscovered across SaaS environments
- Examples of automated remediation options such as blocking transfers, redacting content, and revoking external sharing
- The report's data discovery and classification workflow for PHI, PII, financial records, and credentials
Conduent’s 83-day exfiltration: what DLP teams missed at the content layer?
Explore further
Content-layer detection has become the missing control plane for regulated data. Conduent’s breach shows that perimeter trust is insufficient when attackers can move sensitive records through legitimate channels for weeks. Content-aware monitoring changes the question from "is the traffic allowed" to "is the data permitted to leave." For organisations handling PHI, PII, or delegated customer data, that distinction is the difference between auditability and blind spots.
A question worth separating out:
Q: Who is accountable when a vendor breach exposes downstream client data?
A: Accountability is shared, but control ownership sits with the institution that granted access and the vendor that held it. Frameworks such as NIST Cybersecurity Framework 2.0 and identity governance programmes expect organisations to know their access boundaries and response responsibilities. If the access path was not governed, the incident becomes an accountability gap as well as a security one.
👉 Read our full editorial: Conduent’s 83-day breach shows why DLP failed at the content layer