logo

HackerOne slams supplier for delayed breach notice after staff data exposed

ID: 131e3587-7b01-545b-8931-6a2fbff6afc9

STIX ID: report--131e3587-7b01-545b-8931-6a2fbff6afc9

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-26

Author: Carly Page

...
...

A breach of third-party benefits provider Navia, attributed to exploitation of a Broken Object Level Authorization (BOLA) vulnerability, exposed personally identifiable information (including Social Security numbers, names, addresses, dates of birth, contact details, and health plan data) for over 2.6 million people and affected about 300 HackerOne employees. Navia detected suspicious activity in late January 2026 but notification delays occurred; there is no confirmed misuse yet, though affected parties are advised to monitor for fraud and consider credit protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.