Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, ransomware, ransomware-group, sector-finance, sector-healthcare] ยท confidence: high ยท severity: high ยท affected_sectors: [finance, healthcare] ยท au_impact: false

Akira Ransomware Breach at Benefits Platform Paylogix Exposed SSNs, Health and Financial Data on Tens of Thousands

Employee benefits administrator Paylogix disclosed a major data breach following an Akira ransomware intrusion that exposed sensitive personal, medical, and financial records of tens of thousands of individuals across multiple US states.

Overview

Attribute Detail
Target Organisation Paylogix (Employee Benefits Administrator)
Threat Group Akira Ransomware Group (Disclosed on Tor leak site in January)
Intrusion Window 13 November 2025 โ€“ 18 November 2025
Impacted Population Over 67,000 confirmed individuals (64,383 in SC, 2,304 in NH, 1,102 in VT, plus CA, MA, NJ filings)
Compromised Data Social Security numbers, electronic signatures, financial account details, health insurance details, medical records, passport numbers
Date 2026-08-25

Incident Timeline & Breach Scope

Forensic investigations determined that unauthorized actors maintained network access over a five-day window in mid-November 2025, during which substantial archives of structured employee benefit records were exfiltrated.

In January 2026, the Akira ransomware group listed Paylogix on its dark web leak site. Although Paylogix did not officially attribute the intrusion in its state regulatory filings, the data types and exfiltration timing correspond directly with Akira's extortion timeline. Multiple consumer class-action lawsuits have been initiated alleging negligence in protecting confidential benefits data.

Threat Landscape Context

Akira continues to rank among the most prolific ransomware-as-a-service (RaaS) operations globally. Incident response research from Google Cloud / Mandiant identified Akira as the second most observed malware family across enterprise engagements in 2025, driven by rapid exploitation of exposed edge networking devices and virtual private network gateways.

Remediation & Defensive Considerations

Organisations operating benefits administration and third-party HR platforms should: - Enforce strict segmentation between customer data repositories and internal corporate networks. - Enforce hardware-backed MFA and continuous device posture checks for all administrative access. - Deploy real-time behavioral data loss prevention (DLP) to alert on bulk data staging and off-hours exfiltration.

Sources