HackMyIP
← Back to News
2026-08-25 The Record

Paylogix Breach: Akira Ransomware Exposes 64K+ Employee Records

RansomwareData BreachPrivacy

Paylogix, a New York-based benefits management platform serving employers and insurance firms, has disclosed that the Akira ransomware gang stole sensitive personal, financial, and medical data from over 68,000 individuals during a cyberattack in November 2025. The breach, which occurred between November 13 and November 18, was confirmed after the company was added to Akira's leak site in January. Paylogix provides third-party administration tools that handle payroll deductions, benefits management, and insurance administration, making it a high-value target for attackers seeking to exploit supply chain trust relationships.

The compromised data includes Social Security numbers, electronic signatures, financial account details, health insurance information, medical records, passport numbers, and taxpayer IDs. Paylogix has filed breach notifications in multiple states, reporting 64,383 affected individuals in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont, with additional filings in California, Massachusetts, and New Jersey. Several law firms have already begun organizing class action lawsuits against the company over the incident, while federal law enforcement has been notified and is actively investigating.

Akira has rapidly become one of the most prolific ransomware operations of 2025, ranking as the second most frequently observed malware family according to Google incident response teams. The group has claimed responsibility for attacks on Stanford University, the Toronto Zoo, London Capital Group, and a South African state-owned bank, amassing over $244 million in ransom payments as of late 2025 according to an FBI and European law enforcement advisory. Akira affiliates are known for exploiting VPN vulnerabilities and stolen credentials to gain initial network access before deploying encryption payloads.

For individuals potentially affected by this or similar breaches, it is critical to monitor exposed credentials and take immediate protective steps. Users can verify whether their information has been compromised using an email breach checker, strengthen account security by testing password strength with a password checker, and run a comprehensive privacy checkup to identify other vulnerabilities that could be exploited in follow-on identity theft or phishing campaigns.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →