Paylogix, LLC, a New York-based third-party administrator that runs premium billing, payroll and voluntary-benefits administration for employers and insurance carriers, has told multiple state regulators that intruders copied files from its network over a six-day window in November 2025. The stolen data includes Social Security numbers, medical information, health insurance details, financial account information, electronic signatures, taxpayer IDs and passport numbers. Paylogix has not published a total victim count. The largest single-state figure disclosed so far is 64,383 individuals in South Carolina, with 2,304 in New Hampshire and 1,102 in Vermont, plus filings in California, Massachusetts, New Jersey and other states. The Akira ransomware group added Paylogix to its leak site in January 2026, though Paylogix itself has not named an attacker.
What Happened
The intrusion window is the one fact every source agrees on: attackers had access to the Paylogix network between November 13 and November 18, 2025, and files were viewed or taken during that period. Paylogix describes the event publicly as a network disruption in the fall of 2025 that was later determined to be a cyberattack.
The disclosure timeline is the story's most damning detail. Per Federman & Sherwood's account of the California Attorney General filing, Paylogix completed its file review, mapped records back to the client companies they belonged to, and notified affected customers on or around July 20, 2026. Individual notice letters went out around August 14, 2026, the date recorded in California AG filings by both Dapeer Law and DataBreachClassActions. Dapeer Law puts the gap at roughly nine months from discovery to individual notification. The Record and Insurance Business both published on the state filings on August 25 and 26, 2026.
Paylogix says it notified federal law enforcement (Insurance Business adds local law enforcement) and is cooperating with an investigation. The company says it implemented additional technical security measures after the incident and states it is unaware of any identity theft or fraud tied to the breach. Affected individuals are being offered 12 months of credit monitoring and identity theft protection through Cyberscout, a TransUnion company.
Note on sourcing: the New Jersey Cybersecurity and Communications Integration Cell weekly bulletin included in our source set does not cover this incident, and nothing in this brief rests on it.
What Was Taken
Accounts of the exposed data categories genuinely differ, and the difference matters.
The Record (OUTLET tier), reporting from the state notices, lists: Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, taxpayer IDs "and other information." Insurance Business and MedRisk report substantially the same set.
Abington Cole + Ellery publishes a far longer list drawn from the notice letters: names, mailing addresses, email addresses, insurance policy numbers, SSNs, dates of birth, voluntary-benefit information, account or system-access credentials, driver's license and state ID numbers, passport numbers, taxpayer identification numbers, IRS personal identification numbers, U.S. alien identification numbers, electronic signatures, financial account information and account numbers, health insurance information and medical information. The credentials element and the IRS PIN element appear in this source alone and should be treated as unconfirmed until it shows up in a primary filing.
DataBreachClassActions describes the California AG filing as covering full name, SSN, date of birth, wage and compensation information, tax return information, direct deposit account details, home address and email address. Federman & Sherwood, working from the same California notice, states flatly that the specific data elements are redacted from the public California filing and cannot be reliably determined from it. Two OTHER-tier sources therefore make incompatible claims about the same document. Federman's position is the more conservative and internally consistent one; the wage, tax-return and direct-deposit categories should be read as plausible for a payroll-adjacent TPA but not as confirmed from the California record.
On volume, no source offers a national total. Abington Cole + Ellery's key-facts table states plainly: "TOTAL NOT YET PUBLICLY CONFIRMED." The Record reports Paylogix did not respond to questions about total victim count. The confirmed state-level floor is 67,789 individuals across South Carolina, New Hampshire and Vermont, and given filings in California, Massachusetts and New Jersey, the real number is certainly higher.
Why It Matters
A third-party administrator is a concentration risk wearing an administrative job title. Paylogix sits between employers, carriers and employees, handling consolidated list billing, benefit deductions and enrollment files. That position means a single intrusion reaches employees of thousands of downstream client companies, none of whom chose Paylogix as a vendor or can audit its controls.
It also means the data set is unusually complete per person. Most breaches leak one dimension: identity, or health, or finance. A benefits TPA holds all three simultaneously, bound to the same individual, along with dependents enrolled through the same plan. SSN plus date of birth plus direct deposit details plus medical information plus a passport number plus a stored electronic signature is a near-complete synthetic identity kit, and the e-signature element in particular enables document forgery that credit monitoring does nothing to detect.
The nine-month notification gap compounds the harm. Data taken in November 2025 was in adversary hands for the entire period during which victims could have frozen credit or watched accounts, and the disclosure arrived only after the Akira leak-site listing had already been public for roughly seven months. The affected-file review process TPAs must run, mapping records back to which client each individual belongs to, is genuinely slow, but the practical result is that victims learned last.
Expect regulatory follow-through. Medical and health insurance information in a vendor's possession raises HIPAA business-associate questions, and multiple firms including Dapeer Law, Federman & Sherwood and Abington Cole + Ellery have opened class action investigations.
The Attack Technique
Paylogix has not identified the attackers and has published no technical detail on initial access, dwell time before November 13, or how the intrusion was contained.
The Akira attribution rests on leak-site evidence, not on a company statement. The Record, Insurance Business and MedRisk all report that Paylogix appeared on Akira's dark web leak site in January 2026, which is circumstantial but is the standard basis for attribution in ransomware extortion cases. MedRisk goes further and states that law enforcement has tied the breach to Akira; no other source supports that, The Record explicitly says Paylogix did not identify the hackers, and that claim should not be treated as established.
Akira operates a double-extortion model, stealing data and threatening publication to force payment. Insurance Business cites the November 2025 joint advisory from the FBI, CISA and international partners, which put Akira's claimed proceeds at approximately $244.17 million as of late September 2025 and characterized the group as an imminent threat. MedRisk reports the same figure more loosely as "more than $244M as of late 2025," attributed to researchers rather than to the advisory. The advisory is the stronger citation.
Worth noting what the observed behavior implies: a six-day access window ending in a "network disruption" is consistent with Akira's documented pattern of rapid reconnaissance, credential harvesting, bulk exfiltration and then encryption. Public reporting on Akira campaigns through 2025 has repeatedly centered on VPN and edge appliance access without MFA. Nothing in the Paylogix filings confirms that vector here, and it should be treated as pattern, not fact.
What Organizations Should Do
1. Inventory your benefits and payroll intermediaries, not just your carriers. Most organizations can name their health insurer instantly and cannot name the TPA that processes their premium billing. Build the list, then ask each one for their breach notification SLA in writing and what they consider the notification trigger.
2. Contractually compress the notification clock for TPAs. Nine months from discovery to individual notice is legal in most states and useless to victims. Negotiate for notification to the client within days of confirmed exfiltration, separate from the completion of a full file review.
3. Harden and monitor external access surfaces. Enforce phishing-resistant MFA on every VPN, remote access gateway and edge appliance, patch internet-facing infrastructure on an aggressive cycle, and alert on the first successful authentication from a new geography or ASN. This is where Akira intrusions have most consistently started.
4. Alert on bulk data movement, not just encryption. Every category taken from Paylogix was stolen before anything broke. Baseline normal egress volume per user and per service account, and generate a high-priority alert on large archive creation, unusual outbound transfers to cloud storage, and abnormal read volume against benefits, HR and enrollment databases.
5. Segment the benefits data store and cut standing access. Enrollment and billing systems holding SSNs, medical information and direct deposit details should be isolated from general corporate network reachability, with just-in-time access for administrators and full audit logging of bulk reads.
6. Treat e-signature and passport exposure as a distinct problem. Credit monitoring addresses financial fraud. It does not address a forged signature on a benefits change form or a passport number used for account takeover. Where your workforce is affected, brief employees on document-based fraud and, for direct deposit specifically, require out-of-band verification on any account change request.
7. If your employees may be in scope, act now rather than waiting for a letter. State filings are already public in South Carolina, New Hampshire, Vermont, California, Massachusetts and New Jersey. Credit freezes, IRS Identity Protection PINs and direct deposit change verification cost nothing and do not require a confirmed notice.
Sources: Paylogix hack spilled health and financial records of tens of thous... | Insurance benefits platform Paylogix says hackers stole financial a... | Paylogix TPA data breach puts benefits brokers on notice Insurance... | Paylogix Data Breach Lawsuit (August 2026) | Weekly Bulletin NJCCIC - NJ.gov | Paylogix, LLC Data Breach Class Action (2026) | Paylogix, LLC Data Breach – Investigated by Federman & ... | Paylogix Data Breach Class Action Lawsuit Investigation