logo

HackerOne Data Breach – Employees Data Stolen Following Navia Hack

ID: 72161acc-e856-5e09-b1d6-1b2f44298c37

STIX ID: report--72161acc-e856-5e09-b1d6-1b2f44298c37

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Guru Baran

...
...

HackerOne disclosed that a BOLA vulnerability in its U.S. benefits administrator Navia Benefit Solutions' API was exploited, exposing sensitive personal and health information for about 2.7 million individuals (including 287 HackerOne employees). The unauthorized read-only access occurred in late December 2025–mid January 2026, was detected by Navia on January 23, 2026, and notification to affected parties was delayed, prompting HackerOne to launch its own investigation and warn employees to guard against targeted phishing, identity theft, and fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.