The benefits administration vendor Paylogix has told state regulators that attackers stole files containing medical data, health insurance details, Social Security numbers, financial account information, electronic signatures, and passport numbers from its network last fall.
The New York-based company, which helps employers and insurance firms manage payroll, benefits, and insurance administration, said the theft occurred between November 13 and November 18, 2025. The company has not publicly identified the attackers, though the Akira extortion gang added Paylogix to its dark web site in January. Federal law enforcement was notified and the company says it is cooperating with an investigation.
State filings show the impact so far: 64,383 people in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont, with additional notices filed in California, Massachusetts, and New Jersey. The company has not disclosed a total victim count.
Because Paylogix tools sit inside employer payroll and benefits systems, a compromise reaches some of the most sensitive records a worker has, including health insurance coverage and medical information. Several law firms are organizing class actions over the breach, which law enforcement has tied to Akira, a ransomware operation that researchers say claimed more than $244M in proceeds as of late 2025.