ZeroHour
The Recordpublished ()ingested

Employee benefits platform Paylogix says hackers stole financial and health

highData breach exploited in the wildimportance 65
AI summary · glm-5.3-flash

Akira ransomware gang stole financial, health, and passport data on tens of thousands of people from benefits administrator Paylogix in November.

Hackers stole files from Paylogix's network between November 13 and 18, exposing Social Security numbers, financial accounts, health insurance information, medical data, passport numbers, and taxpayer IDs. State breach notices report at least 67,789 affected people, including 64,383 in South Carolina. Paylogix did not name the attackers but appeared on the Akira ransomware gang's leak site in January. The company notified federal law enforcement, is cooperating with an investigation, and faces organizing class action lawsuits.

  • Akira gang listed Paylogix on its leak site in January
  • Breach notices filed in South Carolina, New Hampshire, Vermont, California, Massachusetts and New Jersey
  • Stolen data includes SSNs, financial accounts, health insurance and medical records, passport numbers
  • Akira believed to have earned over $244 million per FBI and European advisories
VendorsPaylogix
Threat actorsAkira
MalwareAkira
VictimsPaylogix
OrganizationsPaylogixAkiraFBI
CountriesUnited States
Full article408 words · extracted from therecord.media · click to collapse

Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms.

The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems. 

An investigation revealed that hackers stole files from the company’s network between November 13 and November 18. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January. 

The cybercriminals stole Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, taxpayer IDs and other information. 

Federal law enforcement was notified of the incident and Paylogix said it is cooperating with an investigation.

Paylogix is a third-party administrator that helps companies manage employee benefits, payroll and insurance administration. It serves as a clearinghouse for many of the tasks handled by company administrators, including the complicated processes around benefit deductions and more. 

Paylogix’s tools are deeply embedded in payroll systems and typically handle the most sensitive employee information. 

The New York-based company did not respond to requests for comment about how many total victims were impacted by the breach. Paylogix reported that 64,383 people in South Carolina were affected alongside 2,304 in New Hampshire and 1,102 in Vermont. 

It also filed breach notices in California, Massachusetts, New Jersey and several other states.

Several law firms are organizing class action lawsuits against Paylogix over the breach.

Incident responders from Google said Akira was the second most frequently observed malware family in 2025 and researchers have tied hundreds of attacks this year to the operation.  

As of late 2025, Akira was believed to have claimed more than $244 million in ransomware proceeds, the FBI and several European law enforcement agencies said in an advisory

Akira has taken credit for dozens of high-profile attacks on entities like Stanford University, the Toronto Zoo, a state-owned bank in South Africa, major foreign exchange broker London Capital Group and other organizations

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/paylogix-cyberattack-akira-ransomware