Paylogix TPA data breach puts benefits brokers on notice

Paylogix holds data for every employee enrolled in the benefit programs it administers. When it was breached, that exposure flowed to plan participants who have never heard of Paylogix

Paylogix TPA data breach puts benefits brokers on notice

Benefits

By Mark Rosanes

A ransomware gang stole health records, Social Security numbers, financial account data, and passport numbers from Paylogix, LLC. The New York-based company is a third-party administrator that processes employee benefits, payroll, and insurance administration on behalf of employers and insurers. Its position inside employer benefit programs means it holds exactly the kind of concentrated and high-value data that ransomware groups target.

Hackers accessed Paylogix's network between November 13 and November 18, 2025. They copied files before the intrusion was contained, according to the company's notice of data event filed with multiple state regulators. Paylogix notified federal and local law enforcement and is cooperating with their investigation. The company confirmed 64,383 affected individuals in South Carolina, alongside 2,304 in New Hampshire and 1,102 in Vermont. Breach notices were also filed in California, Massachusetts, New Jersey, and several other states.

The total victim count across all states was not disclosed.

Akira ransomware linked to the attack

Paylogix was added to the leak site of the Akira ransomware gang in January based on cybersecurity monitoring reports. Akira uses a double-extortion model, stealing data and threatening to publish it unless a ransom is paid. By late September 2025, the group had claimed approximately $244.17 million in ransomware proceeds, according to a joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and international law enforcement partners issued in November 2025. The advisory identified Akira as an imminent threat to critical infrastructure, with primary targets in healthcare, financial services, and information technology.

Akira uses credential theft and VPN vulnerabilities as its primary entry methods. The FBI-CISA advisory noted the group exploited a SonicWall vulnerability to expand its reach as recently as mid-2025. Several law firms have since announced they are organizing class action lawsuits against Paylogix.

A TPA breach hits plan participants

Paylogix handles benefit deductions, payroll integration, and insurance administration for employers and their carriers. That role places it at the center of benefit plan data flows. The files potentially involved in the breach span dates of birth, Social Security numbers, voluntary benefit information, health insurance information, medical information, financial account information, electronic signatures, passport numbers, taxpayer identification numbers, and US alien identification numbers. In limited circumstances, access credentials were also involved, according to Paylogix's notice.

For benefits brokers whose employer clients use Paylogix or comparable platforms, the breach is a supply-chain risk event. A TPA embedded in payroll and benefits administration holds data on every employee enrolled in the programs it administers. When that platform is breached, the exposure flows through to plan participants who may not know the TPA's name.

Brokers should audit TPA vendor security

Dual-extortion ransomware, where attackers steal data before deploying encryption, accounted for 70 percent of Coalition's ransomware claims in 2025, based on data from the MGA's 2026 Cyber Claims Report. Data-theft incidents of this type cost more than twice as much as encryption-only events, driven by notification costs, regulatory investigations, and class action exposure. The Paylogix breach follows that pattern: files were copied first, and the leak site posting in January came after the November intrusion.

Ransomware claims have risen 80 percent since 2022, according to Travelers' Q1 2026 Cyber Threat Report. For brokers advising employer clients on TPA selection, the Paylogix breach is a concrete argument for cybersecurity due diligence as a standard evaluation step. Questions about multi-factor authentication, breach notification timelines, encryption standards, and whether the TPA carries its own cyber insurance are now part of the broker advisory role.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!