BTC$84,639-1.52% LTC$69.33-0.94% XMR$546.63-0.64%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 25, 2026 · 2 min read · Original story

Employee benefits platform Paylogix says hackers stole financial and health data

Employee benefits platform Paylogix says hackers stole financial and health data
Employee benefits platform Paylogix says hackers stole financial and health data

Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms.

The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems.

An investigation revealed that hackers stole files from the company’s network between November 13 and November 18. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January.

The cybercriminals stole Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, taxpayer IDs and other information.

Federal law enforcement was notified of the incident and Paylogix said it is cooperating with an investigation.

Paylogix is a third-party administrator that helps companies manage employee benefits, payroll and insurance administration. It serves as a clearinghouse for many of the tasks handled by company administrators, including the complicated processes around benefit deductions and more.

Paylogix’s tools are deeply embedded in payroll systems and typically handle the most sensitive employee information.

The New York-based company did not respond to requests for comment about how many total victims were impacted by the breach. Paylogix reported that 64,383 people in South Carolina were affected alongside 2,304 in New Hampshire and 1,102 in Vermont.

It also filed breach notices in California, Massachusetts, New Jersey and several other states.

Several law firms are organizing class action lawsuits against Paylogix over the breach.

Incident responders from Google said Akira was the second most frequently observed malware family in 2025 and researchers have tied hundreds of attacks this year to the operation.

As of late 2025, Akira was believed to have claimed more than $244 million in ransomware proceeds, the FBI and several European law enforcement agencies said in an advisory.

Akira has taken credit for dozens of high-profile attacks on entities like Stanford University, the Toronto Zoo, a state-owned bank in South Africa, major foreign exchange broker London Capital Group and other organizations.

References in this story

  1. FalconFeeds.io (@FalconFeedsio) on X x.com 📢Ransomware Alert: 🇺🇸 Akira ransomware group has added 2 US-based new victims to their dark web portal. - Paylogix - McAloon & Friedman, P.C.
  2. Submitted Breach Notification Sample oag.ca.gov
  3. www.cyber.nj.gov
  4. M-Trends 2026 Report cloud.google.com Get Mandiant's 2026 M-Trends report. Based on 500k hours of incident response, it details the new cyber threat landscape and active defense strategy.
  5. Industrial Ransomware Analysis for Q2 2026 www.dragos.com Dive into Industrial Ransomware threats, trends, and effective strategies to protect your industrial operations from cyberattacks.
  6. FBI: Akira gang has received nearly $250 million in ransoms therecord.media The U.S. and European law enforcement released new information to help organizations defend themselves against the Akira ransomware gang, which has attacked small- and medium-sized businesses for years.
  7. Stanford says data from 27,000 people leaked in September ransomware attack therecord.media The university said the hackers gained access to a network belonging to the Department of Public Safety over a four-and-a-half month period last year.
  8. Two decades of visitor data at the Toronto Zoo stolen in cyberattack therecord.media The organization also lost years of wildlife conservation research as a result of the January 2024 cyber incident.
  9. State-owned bank in South Africa confirms ‘Akira’ ransomware attack therecord.media The Development Bank of Southern Africa said Monday that it was hit with a ransomware attack, adding that servers, logfiles and documents were encrypted by the Akira gang last month.
  10. Decryptor publicly released for Akira ransomware used in several high-profile incidents therecord.media A cybersecurity firm released a decryptor for the Akira ransomware, providing a way forward for dozens of victims that have dealt with attacks since the gang emerged in March 2023.
  11. Mississippi electric utility warns 20,000 residents of data breach therecord.media The Yazoo Valley Electric Power Association initially warned customers in August of software problems. Last week, the utility disclosed that "unauthorized access" had led to a breach of sensitive customer information.
  12. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  13. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  14. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  15. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news