Paylogix Ransomware Attack Exposes Health, Financial, and Identity Data
Paylogix — a New York-based company that manages employee benefits, payroll, and insurance administration on behalf of employers — disclosed this month that hackers stole sensitive files from its network over five days in November, according to The Record.
The stolen data includes Social Security numbers, passport numbers, taxpayer IDs, electronic signatures, financial account details, health insurance records, and medical data. The type of information Paylogix handles is about as sensitive as it gets — the company sits at the centre of payroll systems for many of its clients, which means a single breach touches a wide range of employees across multiple organisations.
Paylogix appeared on the leak site of the Akira ransomware gang in January. Akira is a prolific operation: Google's incident response team ranked it the second most observed ransomware family in 2025, and the FBI estimates the group has collected over $244 million in ransom payments.
At least 67,789 people across South Carolina, New Hampshire, and Vermont have been confirmed affected. Breach notices have also been filed in California, Massachusetts, New Jersey, and several other states — the true total is likely higher. Several law firms are already organising class action lawsuits.
What to do: If you receive a data breach notification from Paylogix, or from your employer, take it seriously. Place a credit freeze with all three major bureaus (Equifax, Experian, TransUnion) — it is free and prevents anyone opening new credit in your name. Monitor your health insurance statements for unfamiliar claims, which is a common but overlooked form of identity fraud.

