2024 Paychex — California data-exchange misdirection; worker names/SSNs (disclosed spring)
Data compromised
Employee/worker PII including SSN as alleged in court summaries
Technical writeup
Employment and trade presses summarized a spring 2024 disclosure in which Paychex reportedly misdirected an information exchange tied to the State of California, allowing an unauthorized party to access worker names and Social Security numbers, with consumer notice timing criticized in federal class-action filings covered by HR Dive (corporate population totals not standardized in the first news wave). The episode is indexed as a state-facing payroll/HR workflow error with breach-notification characteristics.
Root cause
Process or channel misconfiguration during government-data exchange permitting unintended recipient access (per complaint narratives)