LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning Repair
data breachhigh

Employee benefits platform Paylogix says hackers stole financial and health data

Employee benefits platform Paylogix has confirmed a cyberattack that occurred in the fall, during which hackers accessed its systems and stole sensitive personal and financial data. The breach, which impacted tens of thousands of individuals across multiple states, involved the theft of Social Security numbers, financial account information, health data, and more. The Akira ransomware gang has claimed responsibility for the attack, and federal law enforcement has been notified.

zeroday.news ·

Paylogix, a technology company specializing in employee benefits management, has confirmed a data breach that resulted in the theft of sensitive personal, financial, and health information belonging to tens of thousands of individuals. The New York-based firm, which provides benefits administration tools to employers and insurance companies, disclosed the incident through state regulatory filings and its own public notice.

The cyberattack, which disrupted Paylogix systems, occurred in the fall, with an internal investigation pinpointing the data exfiltration period between November 13 and November 18. While Paylogix has not publicly identified the perpetrators, the Akira ransomware gang added the company to its leak site in January, claiming responsibility for the breach.

The stolen data includes a wide array of highly sensitive information: Social Security numbers, electronic signatures, financial account details, health insurance information, medical data, passport numbers, and taxpayer identification numbers. Paylogix has reported the incident to federal law enforcement and stated its cooperation with the ongoing investigation.

Paylogix acts as a third-party administrator, facilitating complex processes such as benefit deductions and payroll integration for its clients. This role grants it access to highly sensitive employee data.

While the total number of affected individuals across all states has not been publicly disclosed by Paylogix, specific figures have emerged from state regulatory filings. Reports indicate that 64,383 individuals in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont were impacted. Breach notices have also been filed in California, Massachusetts, New Jersey, and several other states.

The Akira ransomware group, which has claimed responsibility for numerous high-profile attacks, was identified by Google incident responders as the second most frequently observed malware family in 2025. By late 2025, the FBI and European law enforcement agencies estimated that Akira had amassed over $244 million in ransomware proceeds. Previous victims attributed to Akira include Stanford University, the Toronto Zoo, a South African state-owned bank, and London Capital Group.

In the wake of the breach, several law firms are reportedly organizing class-action lawsuits against Paylogix.

data breachcyberattackransomwarepaylogixakira
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

nation-state

58 arrested in international cybercrime crackdown

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.