HackerOne slams supplier for delayed breach notice after staff data exposed
ID: 131e3587-7b01-545b-8931-6a2fbff6afc9
STIX ID: report--131e3587-7b01-545b-8931-6a2fbff6afc9
Feed Name: The Register (Security)
A breach of third-party benefits provider Navia, attributed to exploitation of a Broken Object Level Authorization (BOLA) vulnerability, exposed personally identifiable information (including Social Security numbers, names, addresses, dates of birth, contact details, and health plan data) for over 2.6 million people and affected about 300 HackerOne employees. Navia detected suspicious activity in late January 2026 but notification delays occurred; there is no confirmed misuse yet, though affected parties are advised to monitor for fraud and consider credit protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
