Paylogix, a SaaS platform that administers employee benefits enrollment for corporate clients, has begun notifying individuals that hackers accessed and copied files from its network between November 13 and 18, 2025, nine months before the notifications went out and the breach reached state regulators.
According to Paylogix’s notice, filed with multiple state attorneys general including California, Vermont, New Hampshire, and Massachusetts, the exposed data includes dates of birth, Social Security numbers, and voluntary benefit information for all affected individuals, with access credentials, electronic signatures, financial account information, health insurance and medical information, passport numbers, and taxpayer identification numbers exposed for a subset. State-level counts vary widely: Vermont’s filing lists 1,102 residents affected, New Hampshire 2,304, and Rhode Island approximately 634, suggesting a total population in the tens of thousands once every state filing is aggregated. Paylogix is offering 12 months of credit monitoring through Cyberscout and says it has notified law enforcement and added technical security measures, though its notice does not name an individual company official or state whether the intrusion has been attributed to a specific threat actor.
The detail that should concern security leaders more than the data types is the timeline: an intrusion detected as a “network disruption” in November took roughly nine months to become individual notification letters and state filings in mid-August. Benefits platforms hold the same sensitive data categories as a healthcare provider or a bank (Social Security numbers, health records, financial accounts), but as third-party administrators they often sit outside the vendor-risk review a company applies to its core HR or payroll systems. That gap is the same one this publication flagged after CareCloud’s healthcare breach disclosure grew over time and after Apollo’s breach landed as part of a broader wave of financial-sector notifications: benefits and financial-services TPAs are accumulating the same sensitive data as their regulated clients without always facing the same disclosure urgency, and a nine-month gap between detection and notification is long enough that any credential or SSN exposed has likely already been used elsewhere.
Source: California Attorney General, Data Breach Notification