Paylogix, a technology provider for voluntary benefits administration, disclosed a cyber incident that disrupted its network and led to unauthorized access to certain systems between November 13 and November 18, 2025. After containment and restoration efforts, the company said its investigation found that files on the network may have been viewed or taken, exposing sensitive information tied to customer records.
The compromised data may include names, addresses, email addresses, policy numbers, and Social Security numbers. Paylogix said it completed a review of affected files, notified relevant customers around July 20, 2026, and issued individual notices dated August 14, 2026; one state filing said about 634 Rhode Island residents may have been affected. The company reported the incident to law enforcement, implemented additional technical security measures, and is offering 12 months of credit monitoring and identity theft protection through Cyberscout, a TransUnion company.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Paylogix's breach notification letter was dated August 14, 2026, informing recipients their information was found in affected files. The notice offered 12 months of complimentary credit monitoring and identity theft protection through Cyberscout and stated that about 634 Rhode Island residents may have been impacted.
After reviewing affected files and reconciling impacted records, Paylogix notified relevant customers about the incident on or around July 20, 2026. The company had also reported the event to law enforcement and said notification was not delayed by law enforcement.
Paylogix stated that the period during which certain files may have been viewed or taken from its network lasted through November 18, 2025. The incident response included containment and restoration of impacted systems and services.
Paylogix experienced a cyber incident that caused network disruption and unauthorized access to certain computer systems and services. The company later determined that files may have been viewed or taken during this period.
The Akira ransomware operation added Paylogix to its leak site, claiming the company as a victim. Paylogix did not publicly identify the responsible attackers, so the listing is an unconfirmed ransomware-group claim rather than an official attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecyber.nj.gov
Open sourceconsumer.sc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.