Skip to content

Navia Benefit Solutions

Disclosed Mar 18, 20266 months ago2,697,540 affectedConfirmed

Official notice

Navia benefits breach exposes SSNs of 2.7 million people

Benefits administrator Navia said attackers accessed its systems between December 22, 2025 and January 15, 2026 and notified nearly 2.7 million people whose names, SSNs and FSA, HRA or COBRA details were exposed. Client HackerOne said the flaw was a broken object level authorization bug.

What is known

People affected2,697,540 (as reported by the organization)
DisclosedMar 18, 2026
DiscoveredJan 23, 2026
HappenedDec 22, 2025
AttackHacking
Data exposedNames, Health, Dates of birth, Social Security numbers, Phone numbers, Emails, Insurance, Addresses
SectorFinance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Navia Benefit Solutionsoag.ca.gov · Official notice
Washington Attorney General breach notice: Navia Benefit Solutionsatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Navia Benefit Solutionsattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Navia Benefit Solutionsjustice.oregon.gov · Official notice
HHS OCR breach report: Navia Benefit Solutions (Business Associate, WA)ocrportal.hhs.gov · Official notice
Navia discloses data breach impacting 2.7 million peoplebleepingcomputer.com · News
Texas Attorney General data security breach report BR-0004920: Navia Benefit Solutionsoag.my.site.com · Official notice
Vermont Attorney General: 2026-03-18 Navia Benefit Solutions Data Breach Notice to Consumersago.vermont.gov · Official notice
Indiana Attorney General 2026 data breach report: Navia Benefit Solutionsin.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAMar 18
Washington AGresidents of WAMar 18319,208
Delaware DOJresidents of DEMar 18599
Oregon DOJresidents of ORMar 182,697,540
HHS OCRtotalMar 182,151,330
Vermont AGresidents of VTMar 18
Indiana AGresidents of INMar 186,088
ResearchtotalMar 19
Texas AGresidents of TXMar 2062,821
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-7_2026.pdf · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2026-03-18-navia-benefit-solutions-data-breach-notice-consumers · backfill source
  • 2026-09-25 · data_types: ["names","health","dob","ssn","phone","emails","insurance"] to ["names","health","dob","ssn","phone","emails","insurance","addresses"] · backfill source
  • 2026-09-25 · records_basis: hhs to organization · backfill source
  • 2026-09-25 · records: 2151330 to 2697540 · backfill source
  • 2026-09-25 · sector: health to finance · seed source
  • 2026-09-25 · data_types: ["names","health"] to ["names","health","dob","ssn","phone","emails","insurance"] · seed source
  • 2026-09-25 · summary: empty to Benefits administrator Navia said attackers accessed its systems between December 22, 2025 and January 15, 2026 and notified nearly 2.7 million people whose names, SSNs and FSA, HRA or COBRA details were exposed. Client HackerOne said the f · seed source
  • 2026-09-25 · title: empty to Navia benefits breach exposes SSNs of 2.7 million people · seed source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 2151330 · backfill source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2026-01-23 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Navia Benefit Solutions

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.