Ransomware victim disclosure
← All victimsPaylogix
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Jan 15, 2026
- Data size
- 185 GB
- Records
- 130 employees
About the victim
AI dossier — public-source company profilePaylogix is a US-based insurtech company specializing in the administration of voluntary employee benefits. Their services encompass enrollment, premium billing, alternative funding, and a SaaS platform designed for employer groups of all sizes. They serve clients across the insurance and benefits administration space.
- Industry
- Insurance Technology (Voluntary Benefits Administration)
- Employees
- 130
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (SSNs, government-issued IDs for employees), combined with client data, financial records, and confidential business documents totalling 185 GB — spanning both personal regulated data and sensitive business information in a financial services/insurtech context.Akira claims to have exfiltrated 185 GB of corporate data from Paylogix, including employee PII (SSNs, passports, driver's licenses for approximately 130 employees), client information, detailed financials, internal confidential files, and NDAs, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee SSNs
- Employee passports
- Employee driver's licenses
- Employee personal information (~130 individuals)
- Client information
- Detailed financial records
- Internal confidential files
- Non-disclosure agreements (NDAs)
What the group claims
Paylogix is an insuretech pioneer offering premium technology sol utions that streamline the administration of voluntary benefits. Their robust suite of services includes enrollment, premium billi ng, alternative funding, and a software-as-a-service platform tai lored for groups of all sizes. We will upload 185gb of corporate data soon. Employee personal in formation (complete information about 130 employees including SSN s, passports, DLs and so on), client information, detailed financ ials, internal confidential files, NDAs and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

