Paylogix, a technology company specializing in employee benefits management, has confirmed a data breach that resulted in the theft of sensitive personal, financial, and health information belonging to tens of thousands of individuals. The New York-based firm, which provides benefits administration tools to employers and insurance companies, disclosed the incident through state regulatory filings and its own public notice.
The cyberattack, which disrupted Paylogix systems, occurred in the fall, with an internal investigation pinpointing the data exfiltration period between November 13 and November 18. While Paylogix has not publicly identified the perpetrators, the Akira ransomware gang added the company to its leak site in January, claiming responsibility for the breach.
The stolen data includes a wide array of highly sensitive information: Social Security numbers, electronic signatures, financial account details, health insurance information, medical data, passport numbers, and taxpayer identification numbers. Paylogix has reported the incident to federal law enforcement and stated its cooperation with the ongoing investigation.
Paylogix acts as a third-party administrator, facilitating complex processes such as benefit deductions and payroll integration for its clients. This role grants it access to highly sensitive employee data.
While the total number of affected individuals across all states has not been publicly disclosed by Paylogix, specific figures have emerged from state regulatory filings. Reports indicate that 64,383 individuals in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont were impacted. Breach notices have also been filed in California, Massachusetts, New Jersey, and several other states.
The Akira ransomware group, which has claimed responsibility for numerous high-profile attacks, was identified by Google incident responders as the second most frequently observed malware family in 2025. By late 2025, the FBI and European law enforcement agencies estimated that Akira had amassed over $244 million in ransomware proceeds. Previous victims attributed to Akira include Stanford University, the Toronto Zoo, a South African state-owned bank, and London Capital Group.
In the wake of the breach, several law firms are reportedly organizing class-action lawsuits against Paylogix.






