HackerOne discloses employee data breach after Navia hack
ID: 6245259a-aef0-5117-89ae-b983cb7a4954
STIX ID: report--6245259a-aef0-5117-89ae-b983cb7a4954
Feed Name: Bleeping Computer
HackerOne disclosed that a breach of benefits administrator Navia—attributed to a Broken Object Level Authorization (BOLA) vulnerability—resulted in unauthorized access to and theft of sensitive personal data for 287 employees (including SSNs, names, addresses, DOBs, and contact information) between December 22, 2025 and January 15, 2026; Navia notified affected parties and offered identity protection, and the exposed data primarily raises phishing and identity-theft risks rather than direct financial loss.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
