Paylogix Breach Spreads Past One Vendor

Paylogix said hackers stole files from its network between Nov. 13 and Nov. 18, exposing sensitive records for tens of thousands of people. The benefits-management company later appeared on Akira’s leak site, and state breach notices put the affected total at 64,383 in South Carolina alone, with additional victims in other states. Paylogix sits between employers, payroll systems, and insurers, so the stolen files included Social Security numbers, financial account details, health insurance information, medical data, passport numbers, and taxpayer IDs. That makes the compromise more than a single-company incident: the vendor held the record set that links employee identity, pay, and benefits. For organizations that used Paylogix, the exposure now follows the data rather than the perimeter. Even if the employer’s own network was untouched, employees whose benefits or payroll data flowed through the administrator can still face identity theft and benefits fraud.

Part of the PlainSec briefing for 2026-08-25

Every edition of this story: Paylogix Breach Spreads Past One Vendor

Sources