Paylogix Data Breach Exposes Sensitive Information of Tens of Thousands, Akira Ransomware Suspected
A recent cyberattack on **Paylogix**, a benefits management technology provider, has resulted in the theft of highly sensitive personal and financial data belonging to tens of thousands of individuals. The breach, which occurred in November, is suspected to be the work of the prolific **Akira** ransomware gang.
Hackers successfully exfiltrated a significant volume of sensitive information from **Paylogix**, a company specializing in benefits management tools for employers and insurance firms. The breach has prompted **Paylogix** to notify several state regulators and issue its own security incident notice, detailing a cyberattack that disrupted its systems last fall.
An internal investigation revealed that unauthorized actors accessed and stole files from the company's network between November 13 and November 18. While **Paylogix** has not officially identified the perpetrators, the company's appearance on the leak site of the **Akira** ransomware gang in January strongly suggests their involvement.
The stolen data is extensive and highly personal, including Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, and taxpayer IDs.
Federal law enforcement agencies have been notified, and **Paylogix** has affirmed its cooperation with the ongoing investigation.
**Paylogix** operates as a critical third-party administrator, deeply embedded in payroll systems and handling the most sensitive employee information for benefit, payroll, and insurance administration tasks.
The New York-based company has not disclosed the total number of individuals impacted. However, breach notices filed with various states indicate a substantial scope: 64,383 individuals in **South Carolina**, 2,304 in **New Hampshire**, and 1,102 in **Vermont** have been affected. Additional breach notifications were also filed in **California**, **Massachusetts**, and **New Jersey**, among other states.
In the wake of the breach, several law firms are reportedly organizing class action lawsuits against **Paylogix**.
**Akira**, the suspected ransomware group, has been identified by incident responders at **Google** as the second most frequently observed malware family in 2025. Researchers have linked hundreds of attacks to the operation this year. According to an advisory from the FBI and several European law enforcement agencies, **Akira** is believed to have amassed over $244 million in ransomware proceeds by late 2025.
The group has claimed responsibility for numerous high-profile attacks on diverse entities, including **Stanford University**, the **Toronto Zoo**, a state-owned bank in South Africa, major foreign exchange broker **London Capital Group**, and various other organizations.