Office workers
Image: Israel Andrade / Unsplash

Employee benefits platform Paylogix says hackers stole financial and health data

Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms.

The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems. 

An investigation revealed that hackers stole files from the company’s network between November 13 and November 18. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January. 

The cybercriminals stole Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, taxpayer IDs and other information. 

Federal law enforcement was notified of the incident and Paylogix said it is cooperating with an investigation.

Paylogix is a third-party administrator that helps companies manage employee benefits, payroll and insurance administration. It serves as a clearinghouse for many of the tasks handled by company administrators, including the complicated processes around benefit deductions and more. 

Paylogix’s tools are deeply embedded in payroll systems and typically handle the most sensitive employee information. 

The New York-based company did not respond to requests for comment about how many total victims were impacted by the breach. Paylogix reported that 64,383 people in South Carolina were affected alongside 2,304 in New Hampshire and 1,102 in Vermont. 

It also filed breach notices in California, Massachusetts, New Jersey and several other states.

Several law firms are organizing class action lawsuits against Paylogix over the breach.

Incident responders from Google said Akira was the second most frequently observed malware family in 2025 and researchers have tied hundreds of attacks this year to the operation.  

As of late 2025, Akira was believed to have claimed more than $244 million in ransomware proceeds, the FBI and several European law enforcement agencies said in an advisory

Akira has taken credit for dozens of high-profile attacks on entities like Stanford University, the Toronto Zoo, a state-owned bank in South Africa, major foreign exchange broker London Capital Group and other organizations

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.