Navia Benefit Solutions
Incident posture
Linked entities
- Victim
- Navia Benefit Solutions
- Threat actors
- 0 actors
- Sources
- 4 sources
Timeline
Summary
Navia Benefit Solutions discovered unauthorized access to its systems and found that an intruder had obtained personal data including names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. The breach affected nearly 2.7 million individuals, including 287 employees of HackerOne who were notified that their data may have been compromised. The company reported no evidence of misuse of the exposed data, while a law firm is investigating potential class action claims on behalf of affected persons.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Navia discovered unauthorized access on January 23, 2026. An investigation determined that the attacker had access between December 22, 2025 and January 15, 2026. The compromised data included names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. Navia reported to the Maine Attorney General’s Office on March 18, 2026 that nearly 2.7 million individuals were affected. Navia sent a breach notification dated February 20, 2026 to impacted individuals and to HackerOne, which was delivered in March. HackerOne indicated that the notification concerned 287 of its employees whose personal information may have been exposed.
The breach impacted more than 2.6 million individuals according to multiple filings. The exposed information consisted of names, birth dates, Social Security numbers, phone numbers, email addresses, and health plan details. Navia stated it had no evidence of attempted or actual misuse of the data. HackerOne said it would conduct its own investigation, maintain communication with Navia to understand the incident, and evaluate Navia’s privacy and security practices, indicating it could seek other benefits providers if unsatisfied. Edelson Lechtzin LLP announced it is investigating a class action lawsuit on behalf of persons whose sensitive personal data may have been compromised in the Navia breach. The law firm provided contact information for individuals wishing to discuss the case.
Sources
Sources available to members: 4 sources.