logo

HackerOne discloses employee data breach after Navia hack

ID: 6245259a-aef0-5117-89ae-b983cb7a4954

STIX ID: report--6245259a-aef0-5117-89ae-b983cb7a4954

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2026-03-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

HackerOne disclosed that a breach of benefits administrator Navia—attributed to a Broken Object Level Authorization (BOLA) vulnerability—resulted in unauthorized access to and theft of sensitive personal data for 287 employees (including SSNs, names, addresses, DOBs, and contact information) between December 22, 2025 and January 15, 2026; Navia notified affected parties and offered identity protection, and the exposed data primarily raises phishing and identity-theft risks rather than direct financial loss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.