CITGO Petroleum Corporation is notifying current and former employees that their personal information was exposed — not because CITGO’s own systems were hacked, but because a vendor two layers down its benefits-administration chain, Paylogix, LLC, was breached nearly a year ago.
CITGO Petroleum Corporation, the Houston-based refiner, has begun notifying individuals associated with the company that their personal information may have been exposed in a data breach. According to CITGO’s notice letter, the company contracted with Mercer Health & Benefits Administration LLC to help administer voluntary benefit programs for CITGO employees — including prepaid legal, accident, and critical illness coverage — and Mercer, in turn, engaged Paylogix, LLC to manage the associated program data. Paylogix identified an incident on its own systems in November 2025 and determined that the intrusion occurred between approximately November 13 and November 18, 2025. CITGO states it did not learn that the incident affected CITGO-associated individuals until July 27, 2026 — more than eight months after the intrusion. CITGO’s notice letter is dated August 12, 2026.
Source: CITGO Petroleum Corporation notice letter; Texas Attorney General data security breach report, published 09/25/2026 (1,907 Texas residents); Massachusetts OCABR annual data breach report, row 2026-1449, filed 08/27/2026 (5 Massachusetts residents).
A Breach Two Vendors Removed From CITGO Itself
CITGO’s letter is direct about where the breach actually happened: “This incident occurred within Paylogix’s systems. CITGO’s own network and systems were not affected.” CITGO is one of potentially many companies whose employee benefits data passed through Paylogix — the letter states that “data from other companies besides CITGO was impacted in connection with this incident.” If your benefits plan, at CITGO or any other employer, used Mercer Health & Benefits Administration and Paylogix to manage voluntary benefit programs, you may have received a notice about this same underlying breach under a different company’s name.
What Information Was Exposed
CITGO’s letter to individual recipients uses a merge-field template that does not specify the exact data elements for each person. However, CITGO’s regulatory filings are more specific: a Texas filing covering 1,907 Texas residents confirms Social Security numbers, health insurance information, and dates of birth were involved, and an earlier Massachusetts filing covering 5 residents also confirms Social Security numbers.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
Two Notices, One Breach
CITGO’s letter notes that affected individuals may separately receive a notice directly from Paylogix about this same incident, and that you are not required to respond to both — you can use the protective services offered by CITGO, by Paylogix, or both. If you received a letter from either CITGO or Paylogix referencing a data incident in this timeframe, they likely concern the same underlying breach.
What You Can Do Now
- Enroll in the 24 months of complimentary Epiq 3-Bureau Credit Monitoring – Plus offered in CITGO’s notice letter before the enrollment deadline
- If Paylogix separately offers credit monitoring, you may enroll in either service, both, or neither
- Place a fraud alert or credit freeze with the three major credit bureaus, given that Social Security numbers were confirmed exposed
- Review your health insurance explanation-of-benefits statements for services you didn’t receive
- Contact us for a free case review if you received a notice letter from CITGO or from Paylogix regarding this incident
Do You Have Legal Options?
Employers and the vendors they hire to administer employee benefits have a legal duty to secure the Social Security numbers, health insurance information, and other personal data involved in those programs. If you received a notice letter from CITGO or Paylogix about this breach, you may have legal options.
If you received a data breach notice from CITGO or Paylogix, contact Emery | Reddy today for a free case review.
FAQ
What information was exposed in the CITGO/Paylogix breach?
CITGO’s regulatory filings confirm Social Security numbers, health insurance information, and dates of birth were involved for at least some affected individuals.
Was CITGO itself hacked?
No. CITGO’s own notice letter states plainly that the incident occurred within the systems of Paylogix, LLC, a vendor engaged by CITGO’s benefits administrator, Mercer Health & Benefits Administration LLC, and that CITGO’s own network and systems were not affected.
How many people are affected?
CITGO has not released a single national total. Regulatory filings confirm 1,907 Texas residents and 5 Massachusetts residents, and CITGO’s letter states that individuals associated with other companies besides CITGO were also affected by the same Paylogix incident.
How long did it take to notify affected individuals?
Paylogix identified the incident in November 2025, with the intrusion itself dated to mid-November 2025. CITGO says it did not learn the breach affected CITGO-associated individuals until July 27, 2026, and its notice letter is dated August 12, 2026 — roughly nine months after the breach occurred.
I work for a different company but used the same benefits vendor — could I be affected too?
Possibly. CITGO’s letter states that data from companies other than CITGO was affected by this same Paylogix incident. If your employer’s voluntary benefits program (prepaid legal, accident, or critical illness coverage) was administered through Mercer Health & Benefits Administration and Paylogix, you may be affected even if you’ve never worked for CITGO.
Do I have a legal claim?
Employers and the vendors they hire to administer employee benefits have a legal duty to secure the personal and health information involved. If you received a notice letter from CITGO or Paylogix, contact the Data Breach Attorneys at Emery | Reddy Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.