CSIDB logo
Incident

Navia Benefit Solutions

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 12:54

Linked entities

Victim
Navia Benefit Solutions
Threat actors
0 actors
Sources
4 sources

Timeline

Occurred
Dec 2025
Discovered
Jan 2026
Disclosed
Mar 2026
Resolved
Pending

Summary

Navia Benefit Solutions discovered unauthorized access to its systems and found that an intruder had obtained personal data including names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. The breach affected nearly 2.7 million individuals, including 287 employees of HackerOne who were notified that their data may have been compromised. The company reported no evidence of misuse of the exposed data, while a law firm is investigating potential class action claims on behalf of affected persons.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Navia discovered unauthorized access on January 23, 2026. An investigation determined that the attacker had access between December 22, 2025 and January 15, 2026. The compromised data included names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. Navia reported to the Maine Attorney General’s Office on March 18, 2026 that nearly 2.7 million individuals were affected. Navia sent a breach notification dated February 20, 2026 to impacted individuals and to HackerOne, which was delivered in March. HackerOne indicated that the notification concerned 287 of its employees whose personal information may have been exposed.

The breach impacted more than 2.6 million individuals according to multiple filings. The exposed information consisted of names, birth dates, Social Security numbers, phone numbers, email addresses, and health plan details. Navia stated it had no evidence of attempted or actual misuse of the data. HackerOne said it would conduct its own investigation, maintain communication with Navia to understand the incident, and evaluate Navia’s privacy and security practices, indicating it could seek other benefits providers if unsatisfied. Edelson Lechtzin LLP announced it is investigating a class action lawsuit on behalf of persons whose sensitive personal data may have been compromised in the Navia breach. The law firm provided contact information for individuals wishing to discuss the case.

Sources

Sources available to members: 4 sources.

CSIDB