Paylogix Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Paylogix data breach, which reportedly affected thousands of individuals and may have exposed names, mailing addresses, email addresses, insurance policy numbers, Social Security numbers, dates of birth, voluntary-benefit information, account or system-access credentials, driver’s license and state identification numbers, passport numbers, taxpayer identification numbers, IRS personal identification numbers, U.S. alien identification numbers, electronic signatures, financial account information and account numbers, health-insurance information, and medical information.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Paylogix, please submit your information to be considered:

You may also open the form here: Paylogix Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

Paylogix Data Breach: Key Facts

Company: Paylogix
Location: Westbury, New York
Incident Type: Reportedly Ransomware
Number Affected: TOTAL NOT YET PUBLICLY CONFIRMED
Data Involved: names, mailing addresses, email addresses, insurance policy numbers, Social Security numbers, dates of birth, voluntary-benefit information, account or system-access credentials, driver’s license and state identification numbers, passport numbers, taxpayer identification numbers, IRS personal identification numbers, U.S. alien identification numbers, electronic signatures, financial account information and account numbers, health-insurance information, and medical information
Date Began: November 13, 2025
Date Discovered: November of 2025
Date Ended: November 18, 2025
Notice Date: August 14, 2026
Credit Monitoring: 12 Months of Cyberscout
Status: Class Action Lawsuit Investigation


What happened in the Paylogix data breach?

Paylogix, LLC recently notified individuals of a data breach involving unauthorized access to its computer network. Paylogix provides software-as-a-service solutions to insurance providers and supports the enrollment and administration of employee benefits. According to the company, affected individuals’ information was likely maintained by Paylogix because a current or former employer used its services during the employee-benefits enrollment process.

The Paylogix cybersecurity incident began in November 2025, when the company experienced a disruption affecting certain computer systems and services. Paylogix took steps to secure its environment and opened an investigation into the nature and scope of the disruption. That investigation determined that an unauthorized party accessed certain systems and may have viewed or removed files from the Paylogix network between November 13 and November 18, 2025. The California Attorney General identifies those same dates as the period of the Paylogix data breach. California Paylogix Submitted Breach Notification Sample

Paylogix has not publicly explained how the unauthorized party initially entered its network. Its notices do not identify a compromised account, phishing attack, software vulnerability or other specific point of entry. The company also has not officially characterized the event as a ransomware attack. However, cybersecurity reporting indicates that a ransomware group claimed responsibility on January 15, 2026, and alleged that it obtained approximately 185 gigabytes of Paylogix data. That claim has not been independently confirmed by Paylogix, and the company’s official notices do not name a ransomware group or verify the amount of data the group reportedly obtained. TEISS: Paylogix data breach exposes sensitive employee and client information in ransomware attack

After investigating the intrusion, Paylogix began reviewing the potentially affected files to determine what personal information they contained and which individuals and customers were connected to those records. In a preliminary public notice available by January 26, 2026, Paylogix stated that the information varied by person but could include names, addresses, email addresses and insurance policy numbers. In some cases, the affected files also contained Social Security numbers. Paylogix NOTICE OF DATA EVENT

Paylogix subsequently reconciled the affected records with its customer accounts and notified the relevant customers on or around July 20, 2026. The company then mailed individual data breach notification letters dated August 14, 2026, to people whose information was identified in the reviewed files. The public California sample redacts the individualized description of the information involved, so each recipient’s letter should be consulted to determine the precise types of data affected. Paylogix reported the breach to the California Attorney General on August 14, 2026. California Paylogix Submitted Breach Notification Sample

Paylogix has not publicly disclosed the total number of individuals affected nationwide. The notification materials state that approximately 634 Rhode Island residents may have been affected, but that figure should not be treated as a national total. Because Paylogix provides services to multiple insurance providers and benefits programs, the incident may involve individuals associated with more than one employer or insurance organization.

In response to the Paylogix data breach, the company reported the incident to law enforcement, investigated the affected systems and files, and implemented additional technical security measures. Paylogix stated that, as of the August 2026 notification, it was not aware of identity theft or fraud connected to the incident. As a precaution, the company offered affected individuals 12 months of complimentary credit monitoring and identity-theft protection through Cyberscout, a TransUnion company. Recipients must enroll within 90 days of the date shown on their notification letter.


How did the Paylogix breach occur?

The Paylogix data breach occurred when an unauthorized party gained access to certain company computer systems and copied files from the Paylogix network between November 13 and November 18, 2025. Paylogix has not disclosed how the attacker initially entered its network. Its notices do not identify phishing, stolen credentials, malware, an unpatched vulnerability or a compromised third-party system as the point of entry. Paylogix NOTICE OF DATA EVENT


When did the Paylogix breach occur?

The Paylogix data breach occurred between November 13 and November 18, 2025. During that period, an unauthorized party accessed certain Paylogix systems and copied files from its network.


How many people were affected by the Paylogix breach?

Paylogix has not publicly disclosed the total number of people affected by the data breach. The company’s notification materials state that approximately 634 Rhode Island residents may have been affected, indicating that the incident extended across multiple states.


What information was exposed in the Paylogix breach?

  • The information potentially exposed in the Paylogix data breach varied by individual. Not every person had every category exposed.
    • Names
    • Mailing addresses
    • Email addresses
    • Insurance policy numbers
    • Social Security numbers
    • Dates of birth
    • Voluntary-benefit information
    • Account or system-access credentials
    • Driver’s license and state identification numbers
    • Passport numbers
    • Taxpayer identification numbers
    • IRS personal identification numbers
    • U.S. alien identification numbers
    • Electronic signatures
    • Financial account information and account numbers
    • Health-insurance information
    • Medical information

Has Paylogix offered free credit monitoring and/or identity theft protection services?

Yes. Paylogix is offering affected individuals 12 months of complimentary credit monitoring and identity-theft protection services through Cyberscout, a TransUnion company. Eligible recipients must enroll within 90 days of the date of their notification letter using the unique activation code provided in the letter.


Paylogix data breach timeline:

Date Event
November 13–18, 2025 An unauthorized party gained access to certain Paylogix computer systems and copied files from the company’s network during this period. These are the official breach dates reported to the California Attorney General.
November 2025 Paylogix experienced a disruption affecting certain systems and services. The company took steps to contain the incident, secure its systems and begin an investigation. Paylogix has not disclosed the precise date it discovered the disruption or how the attacker initially entered its network.
January 15, 2026 A ransomware group reportedly claimed responsibility for the attack and alleged that it obtained approximately 185 gigabytes of Paylogix data. Paylogix has not publicly confirmed a ransomware group's involvement or the amount of data reportedly stolen.
January 26, 2026 Paylogix’s preliminary public notice directed potentially affected individuals to a dedicated assistance line beginning January 26. At that stage, the company’s review of the affected files remained underway.
June 12, 2026 Paylogix issued a public announcement confirming that certain systems had been accessed without authorization and that files had been copied between November 13 and November 18, 2025. The company stated that it was reviewing the files to determine what information they contained and which individuals were affected.
Around July 20, 2026 After reviewing and reconciling the affected records, Paylogix notified the insurance providers and other customers associated with the affected information on or around July 20.
August 14, 2026 Paylogix sent data breach letters to individuals whose information was identified in the affected files. The letters offered eligible recipients 12 months of complimentary credit monitoring and identity-theft protection services through Cyberscout, a TransUnion company.
August 14, 2026 The Paylogix breach was reported to the California Attorney General, identifying November 13 through November 18, 2025, as the breach period.
Within 90 days of each notification letter Monitoring enrollment deadline. Eligible recipients must activate the complimentary Cyberscout services within 90 days of the date on their letter using the unique enrollment code provided.

Who is Paylogix?

Paylogix is a Westbury, New York-based insurance technology company and third-party administrator that provides voluntary employee benefits administration services. Founded in 1995, the company develops technology used by insurance carriers, benefits providers, brokers and employers to manage benefit enrollment, premium billing, payment processing, payroll deductions and related administrative functions. Paylogix offers enrollment and billing platforms, software-as-a-service tools, alternative payment options, merchant gateway services and other solutions supporting the administration of workplace benefits. About Paylogix


What should you do if you received a Paylogix data breach letter?

  • If you received a Paylogix data breach notification letter, it means Paylogix identified your information in files that may have been viewed or taken during the cybersecurity incident. Receiving a letter does not necessarily mean that your information has been misused, but the sensitive nature of the affected data makes several precautions appropriate.
    • Read the letter carefully. Determine which types of information were affected in your case. The exposed information varied by individual and may include Social Security numbers, financial information, identification numbers, medical information, benefit records or account credentials.
    • Enroll in the complimentary protection services. Paylogix is offering eligible recipients 12 months of credit monitoring and identity-theft protection through Cyberscout, a TransUnion company. Enrollment must be completed within 90 days of the letter’s date using the unique activation code provided.
    • Consider freezing your credit. A credit freeze can help prevent someone from opening a new credit account in your name. Freezes are free, do not affect your credit score and must be placed separately with Equifax, Experian and TransUnion. FTC: Credit Freezes and Fraud Alerts
    • Review all three credit reports. Obtain reports from Equifax, Experian and TransUnion through AnnualCreditReport.com. Look for unfamiliar accounts, credit inquiries, addresses or other activity. Free reports are currently available weekly. FTC: Checking Your Credit Report
    • Secure affected accounts. If login credentials were involved, change the affected passwords immediately, replace any reused passwords and enable multifactor authentication. If financial account information was exposed, contact the financial institution and ask whether the account or payment card should be monitored or replaced.
    • Monitor benefit and medical records. Review insurance statements and explanations of benefits for services, claims or providers you do not recognize. Report suspicious medical or benefits activity to the insurer or benefits administrator.
    • Be alert for targeted scams. Criminals may use stolen personal information to make phishing emails, calls or text messages appear legitimate. Do not disclose passwords, Social Security numbers or the Cyberscout activation code in response to unsolicited communications.
    • Preserve relevant records. Keep the Paylogix letter, envelopes, enrollment confirmation, suspicious communications and documentation of any fraudulent transactions, lost time or other expenses.
    • Report suspected identity theft promptly. If you discover misuse of your information, visit IdentityTheft.gov to report it and obtain an individualized recovery plan. You should also notify the affected financial institution or insurer and dispute unauthorized credit activity.

Paylogix Sample Data Breach Notice

The sample notice describes the Paylogix data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Paylogix Sample Data Breach Notice in a New Tab


Paylogix Notice of Data Event

The notice describes the Paylogix data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Paylogix Notice of Data Event in a New Tab


Sources and additional information about the data breach:


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the Paylogix data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
Paylogix data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of August 15, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Paylogix data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the Paylogix data breach, Paylogix data breach notice, Paylogix class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by Paylogix or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.