Paylogix Data Breach Class Action Lawsuit Investigation
Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Paylogix data breach, which reportedly affected thousands of individuals and may have exposed names, mailing addresses, email addresses, insurance policy numbers, Social Security numbers, dates of birth, voluntary-benefit information, account or system-access credentials, driver’s license and state identification numbers, passport numbers, taxpayer identification numbers, IRS personal identification numbers, U.S. alien identification numbers, electronic signatures, financial account information and account numbers, health-insurance information, and medical information.
JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Paylogix, please submit your information to be considered:
You may also open the form here: Paylogix Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.
Paylogix Data Breach: Key Facts
| Company: | Paylogix |
|---|---|
| Location: | Westbury, New York |
| Incident Type: | Reportedly Ransomware |
| Number Affected: | TOTAL NOT YET PUBLICLY CONFIRMED |
| Data Involved: | names, mailing addresses, email addresses, insurance policy numbers, Social Security numbers, dates of birth, voluntary-benefit information, account or system-access credentials, driver’s license and state identification numbers, passport numbers, taxpayer identification numbers, IRS personal identification numbers, U.S. alien identification numbers, electronic signatures, financial account information and account numbers, health-insurance information, and medical information |
| Date Began: | November 13, 2025 |
| Date Discovered: | November of 2025 |
| Date Ended: | November 18, 2025 |
| Notice Date: | August 14, 2026 |
| Credit Monitoring: | 12 Months of Cyberscout |
| Status: | Class Action Lawsuit Investigation |
What happened in the Paylogix data breach?
Paylogix, LLC recently notified individuals of a data breach involving unauthorized access to its computer network. Paylogix provides software-as-a-service solutions to insurance providers and supports the enrollment and administration of employee benefits. According to the company, affected individuals’ information was likely maintained by Paylogix because a current or former employer used its services during the employee-benefits enrollment process.
The Paylogix cybersecurity incident began in November 2025, when the company experienced a disruption affecting certain computer systems and services. Paylogix took steps to secure its environment and opened an investigation into the nature and scope of the disruption. That investigation determined that an unauthorized party accessed certain systems and may have viewed or removed files from the Paylogix network between November 13 and November 18, 2025. The California Attorney General identifies those same dates as the period of the Paylogix data breach. California Paylogix Submitted Breach Notification Sample
Paylogix has not publicly explained how the unauthorized party initially entered its network. Its notices do not identify a compromised account, phishing attack, software vulnerability or other specific point of entry. The company also has not officially characterized the event as a ransomware attack. However, cybersecurity reporting indicates that a ransomware group claimed responsibility on January 15, 2026, and alleged that it obtained approximately 185 gigabytes of Paylogix data. That claim has not been independently confirmed by Paylogix, and the company’s official notices do not name a ransomware group or verify the amount of data the group reportedly obtained. TEISS: Paylogix data breach exposes sensitive employee and client information in ransomware attack
After investigating the intrusion, Paylogix began reviewing the potentially affected files to determine what personal information they contained and which individuals and customers were connected to those records. In a preliminary public notice available by January 26, 2026, Paylogix stated that the information varied by person but could include names, addresses, email addresses and insurance policy numbers. In some cases, the affected files also contained Social Security numbers. Paylogix NOTICE OF DATA EVENT
Paylogix subsequently reconciled the affected records with its customer accounts and notified the relevant customers on or around July 20, 2026. The company then mailed individual data breach notification letters dated August 14, 2026, to people whose information was identified in the reviewed files. The public California sample redacts the individualized description of the information involved, so each recipient’s letter should be consulted to determine the precise types of data affected. Paylogix reported the breach to the California Attorney General on August 14, 2026. California Paylogix Submitted Breach Notification Sample
Paylogix has not publicly disclosed the total number of individuals affected nationwide. The notification materials state that approximately 634 Rhode Island residents may have been affected, but that figure should not be treated as a national total. Because Paylogix provides services to multiple insurance providers and benefits programs, the incident may involve individuals associated with more than one employer or insurance organization.
In response to the Paylogix data breach, the company reported the incident to law enforcement, investigated the affected systems and files, and implemented additional technical security measures. Paylogix stated that, as of the August 2026 notification, it was not aware of identity theft or fraud connected to the incident. As a precaution, the company offered affected individuals 12 months of complimentary credit monitoring and identity-theft protection through Cyberscout, a TransUnion company. Recipients must enroll within 90 days of the date shown on their notification letter.
How did the Paylogix breach occur?
The Paylogix data breach occurred when an unauthorized party gained access to certain company computer systems and copied files from the Paylogix network between November 13 and November 18, 2025. Paylogix has not disclosed how the attacker initially entered its network. Its notices do not identify phishing, stolen credentials, malware, an unpatched vulnerability or a compromised third-party system as the point of entry. Paylogix NOTICE OF DATA EVENT
When did the Paylogix breach occur?
The Paylogix data breach occurred between November 13 and November 18, 2025. During that period, an unauthorized party accessed certain Paylogix systems and copied files from its network.
How many people were affected by the Paylogix breach?
Paylogix has not publicly disclosed the total number of people affected by the data breach. The company’s notification materials state that approximately 634 Rhode Island residents may have been affected, indicating that the incident extended across multiple states.
What information was exposed in the Paylogix breach?
- The information potentially exposed in the Paylogix data breach varied by individual. Not every person had every category exposed.
- Names
- Mailing addresses
- Email addresses
- Insurance policy numbers
- Social Security numbers
- Dates of birth
- Voluntary-benefit information
- Account or system-access credentials
- Driver’s license and state identification numbers
- Passport numbers
- Taxpayer identification numbers
- IRS personal identification numbers
- U.S. alien identification numbers
- Electronic signatures
- Financial account information and account numbers
- Health-insurance information
- Medical information
Has Paylogix offered free credit monitoring and/or identity theft protection services?
Yes. Paylogix is offering affected individuals 12 months of complimentary credit monitoring and identity-theft protection services through Cyberscout, a TransUnion company. Eligible recipients must enroll within 90 days of the date of their notification letter using the unique activation code provided in the letter.
Paylogix data breach timeline:
| Date | Event |
|---|---|
| November 13–18, 2025 | An unauthorized party gained access to certain Paylogix computer systems and copied files from the company’s network during this period. These are the official breach dates reported to the California Attorney General. |
| November 2025 | Paylogix experienced a disruption affecting certain systems and services. The company took steps to contain the incident, secure its systems and begin an investigation. Paylogix has not disclosed the precise date it discovered the disruption or how the attacker initially entered its network. |
| January 15, 2026 | A ransomware group reportedly claimed responsibility for the attack and alleged that it obtained approximately 185 gigabytes of Paylogix data. Paylogix has not publicly confirmed a ransomware group's involvement or the amount of data reportedly stolen. |
| January 26, 2026 | Paylogix’s preliminary public notice directed potentially affected individuals to a dedicated assistance line beginning January 26. At that stage, the company’s review of the affected files remained underway. |
| June 12, 2026 | Paylogix issued a public announcement confirming that certain systems had been accessed without authorization and that files had been copied between November 13 and November 18, 2025. The company stated that it was reviewing the files to determine what information they contained and which individuals were affected. |
| Around July 20, 2026 | After reviewing and reconciling the affected records, Paylogix notified the insurance providers and other customers associated with the affected information on or around July 20. |
| August 14, 2026 | Paylogix sent data breach letters to individuals whose information was identified in the affected files. The letters offered eligible recipients 12 months of complimentary credit monitoring and identity-theft protection services through Cyberscout, a TransUnion company. |
| August 14, 2026 | The Paylogix breach was reported to the California Attorney General, identifying November 13 through November 18, 2025, as the breach period. |
| Within 90 days of each notification letter | Monitoring enrollment deadline. Eligible recipients must activate the complimentary Cyberscout services within 90 days of the date on their letter using the unique enrollment code provided. |
Who is Paylogix?
Paylogix is a Westbury, New York-based insurance technology company and third-party administrator that provides voluntary employee benefits administration services. Founded in 1995, the company develops technology used by insurance carriers, benefits providers, brokers and employers to manage benefit enrollment, premium billing, payment processing, payroll deductions and related administrative functions. Paylogix offers enrollment and billing platforms, software-as-a-service tools, alternative payment options, merchant gateway services and other solutions supporting the administration of workplace benefits. About Paylogix
What should you do if you received a Paylogix data breach letter?
- If you received a Paylogix data breach notification letter, it means Paylogix identified your information in files that may have been viewed or taken during the cybersecurity incident. Receiving a letter does not necessarily mean that your information has been misused, but the sensitive nature of the affected data makes several precautions appropriate.
- Read the letter carefully. Determine which types of information were affected in your case. The exposed information varied by individual and may include Social Security numbers, financial information, identification numbers, medical information, benefit records or account credentials.
- Enroll in the complimentary protection services. Paylogix is offering eligible recipients 12 months of credit monitoring and identity-theft protection through Cyberscout, a TransUnion company. Enrollment must be completed within 90 days of the letter’s date using the unique activation code provided.
- Consider freezing your credit. A credit freeze can help prevent someone from opening a new credit account in your name. Freezes are free, do not affect your credit score and must be placed separately with Equifax, Experian and TransUnion. FTC: Credit Freezes and Fraud Alerts
- Review all three credit reports. Obtain reports from Equifax, Experian and TransUnion through AnnualCreditReport.com. Look for unfamiliar accounts, credit inquiries, addresses or other activity. Free reports are currently available weekly. FTC: Checking Your Credit Report
- Secure affected accounts. If login credentials were involved, change the affected passwords immediately, replace any reused passwords and enable multifactor authentication. If financial account information was exposed, contact the financial institution and ask whether the account or payment card should be monitored or replaced.
- Monitor benefit and medical records. Review insurance statements and explanations of benefits for services, claims or providers you do not recognize. Report suspicious medical or benefits activity to the insurer or benefits administrator.
- Be alert for targeted scams. Criminals may use stolen personal information to make phishing emails, calls or text messages appear legitimate. Do not disclose passwords, Social Security numbers or the Cyberscout activation code in response to unsolicited communications.
- Preserve relevant records. Keep the Paylogix letter, envelopes, enrollment confirmation, suspicious communications and documentation of any fraudulent transactions, lost time or other expenses.
- Report suspected identity theft promptly. If you discover misuse of your information, visit IdentityTheft.gov to report it and obtain an individualized recovery plan. You should also notify the affected financial institution or insurer and dispute unauthorized credit activity.
Paylogix Sample Data Breach Notice
The sample notice describes the Paylogix data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Paylogix Sample Data Breach Notice in a New Tab
Paylogix Notice of Data Event
The notice describes the Paylogix data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Paylogix Notice of Data Event in a New Tab
Sources and additional information about the data breach:
-
- Paylogix Website
- Paylogix NOTICE OF DATA EVENT
- California Paylogix Submitted Breach Notification Sample
- TEISS: Paylogix data breach exposes sensitive employee and client information in ransomware attack
- FTC: Credit Freezes and Fraud Alerts
- AnnualCreditReport.com
- FTC Consumer Advice: Identity Theft
- IdentityTheft.gov
- FTC: Checking Your Credit Report
- IRS Identity Theft Guide for Individuals
- U.S. Department of Health and Human Services Office of Inspector General: Medical Identity Theft
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
Class Action FAQ
About This Data Breach Resource
This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Paylogix data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.
This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.
This page is especially relevant for readers searching for information about the Paylogix data breach, Paylogix data breach notice, Paylogix class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.
Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.
The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.
For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?
This website is not associated with nor authorized by Paylogix or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.