Benefits Data Exposed Through API Flaws
Coverage from Stock Titan, DZone, and others

Navia Benefit Solutions disclosed unauthorized access through a Broken Object Level Authorization flaw that exposed sensitive employee and dependent information, including Social Security numbers, for nearly 2.
7 million people. The incident shows how benefits administrators and integrated service providers can become high-impact data targets when API authorization and monitoring controls fail. A separate Navient incident involving a ransomware attack on an outside law firm reinforces the broader exposure created by third-party environments, although it is not part of the Navia breach.
The Navia breach is now quantified at nearly 2.7 million affected people, substantially clarifying its scale and the sensitivity of exposed records. A separate Navient law-firm ransomware incident broadens the story into a wider third-party data-exposure pattern, though it is not linked to Navia.
