Hackers Steal Financial and Health Data in Paylogix Breach

Hackers Steal Financial and Health Data in Paylogix Breach

The Paylogix data breach involved stolen financial, health, and identity information. Here’s what happened, who may be affected, and how you can better protect your personal information online today.

What Happened in the Paylogix Data Breach?

According to The Record, Paylogix — an employee benefits and payroll administration company — reported a data breach involving stolen files.

Hackers accessed the company’s network between November 13 and November 18, 2025. The attack disrupted some systems, and Paylogix notified federal law enforcement.

The company later filed breach notices in several states.

Personal information stolen in a breach can stay useful to criminals long after the incident. Scammers may use it for identity theft or convincing phishing messages.

You may also have information from another breach without realizing it. If you are unsure whether your information was leaked, automatic monitoring can help.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Stolen?

Paylogix has not publicly shared the total number of people affected.

However, the company reported 64,383 affected people in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont. It also filed notices in California, Massachusetts, New Jersey, and other states.

The stolen files included:

  • Social Security numbers
  • financial account information
  • health insurance information
  • medical data
  • passport numbers
  • taxpayer identification numbers
  • electronic signatures
  • other personal information

Because the total number has not been released, the full size of the breach remains unclear.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How Hackers Got Into Paylogix Is Still Unknown

Paylogix has not publicly explained exactly how hackers entered its network. It also has not identified the attackers.

Paylogix appeared on the Akira ransomware gang’s leak site in January 2026. However, that does not confirm Akira carried out the breach.

Ransomware is harmful software that can lock files and demand payment. Paylogix has not said ransomware was used in this incident.