← Paylogix

2026 Paylogix — Akira-linked TPA breach Nov 13–18 2025; ≥67,789 in SC/NH/VT notices (nationwide TBD)

2026 67.8K records affected Share on X

Data compromised

DOB, SSN, voluntary benefits, health insurance/medical info, financial accounts, e-signatures, passport/TIN/alien ID numbers; limited access credentials (per notice)

Technical writeup

Verified multi-state regulator notices — Insurance Business August 26, 2026. Paylogix, LLC (NY benefits TPA) said hackers accessed its network between November 13 and 18, 2025 and copied files before containment; law enforcement notified. Monitoring linked Paylogix to the Akira ransomware leak site in January. Disclosed state tallies include South Carolina 64,383, New Hampshire 2,304, and Vermont 1,102 (sum 67,789); California, Massachusetts, New Jersey and other states also received notices without a published nationwide total. Data types in notices include DOB, SSN, benefits/health/medical fields, financial accounts, e-signatures, passport/TIN/alien IDs, and limited credentials. recordsAffected 67789 = sum of cited state counts (floor; nationwide higher); companyConfirmed true.

Root cause

Network intrusion Nov 13–18, 2025 with file copy; Paylogix listed on Akira leak site (Jan); multi-state AG notices

References