Payactiv, Inc., a company offering earned wage access and financial wellness services, experienced a data breach stemming from unauthorized network access between April 3 and August 20, 2025. The company discovered the incident on September 12, 2025, and subsequently determined that personal information had been viewed. Payactiv began mailing notices to affected individuals around September 29, 2025, and also notified law enforcement.
The breach affected at least 176,282 people nationwide. Confirmed data types include names and Social Security numbers. The official notification stated that the specific breached elements varied by recipient. Other potential data types, such as dates of birth, addresses, government IDs, medical information, and financial information, were reported by a secondary source as possibly exposed, but these are not clearly confirmed in the official notice excerpts available. Affected individuals reside in states including Montana, Maine, New Hampshire, Massachusetts, Texas, Washington, California, Oregon, and Vermont. After the incident, Payactiv used third-party cybersecurity experts to investigate and enhanced security measures.
It is possible that additional details regarding the breach and its full impact may emerge as investigations continue. Notices to consumers may also be ongoing.