Last Update: 09/22/2026 at 11:34 PM EST

Benefits Data Exposed Through API Flaws

Coverage from Stock Titan, DZone, and others

Benefits Data Exposed Through API Flaws topic image

Navia Benefit Solutions disclosed unauthorized access through a Broken Object Level Authorization flaw that exposed sensitive employee and dependent information, including Social Security numbers, for nearly 2.

7 million people. The incident shows how benefits administrators and integrated service providers can become high-impact data targets when API authorization and monitoring controls fail. A separate Navient incident involving a ransomware attack on an outside law firm reinforces the broader exposure created by third-party environments, although it is not part of the Navia breach.

Looking Back
106 Day Timeline
Mar 19Apr 9Apr 30May 21Jun 11Jul 2
History
09/06/2026

The Navia breach is now quantified at nearly 2.7 million affected people, substantially clarifying its scale and the sensitivity of exposed records. A separate Navient law-firm ransomware incident broadens the story into a wider third-party data-exposure pattern, though it is not linked to Navia.

All Articles6 articles
Important3 articles · CI Score 60 and above
Stock Titan
Navient disclosed a June 2026 ransomware incident at a third-party law firm that led to unauthorized access of borrower data, including Social Security numbers.
7/2/2026 • Data Breaches & Exposure Events • General
DZone / Igboanugo David Ugochukwu
Navia Benefit Solutions disclosed an API authorization flaw in a breach discovered weeks later after 24 days of unauthorized access exposed Social Security and COBRA records for 2,697,540 Americans.
6/15/2026 • Cybersecurity Tech (Privacy-Relevant) • General
ScyScan
HackerOne disclosed on February 20, 2026, that a vulnerability in Navia's systems exposed personal data for 287 employees in a Maine regulatory filing.
3/24/2026 • Data Breaches & Exposure Events • General
Interesting2 articles · CI Score 45–59
Custommapposter
Navia reported a BOLA authorization vulnerability enabling weeks of unauthorized access from December 22, 2025 to January 15, 2026 and notifying affected parties on February 20.
3/26/2026 • Data Breaches • General
BleepingComputer / Sergiu Gatlan
HackerOne notified employees after a BOLA vulnerability enabled unauthorized access to Navia benefits administrator data, affecting 287 employees and dependents between December 22, 2025 and January 15, 2026.
3/24/2026 • Data Breaches & Exposure Events • General
Additional1 article · CI Score below 45
BleepingComputer / Bill Toulas
Navia Benefit Solutions notified nearly 2.7 million U.S. individuals in 2026 after unauthorized access to benefits administration systems occurred from December 22, 2025, to January 15, 2026.
3/19/2026 • Data Breaches & Exposure Events • General