Navia Benefit Solutions
Disclosed Mar 18, 20266 months ago2,697,540 affectedConfirmed
Navia benefits breach exposes SSNs of 2.7 million people
Benefits administrator Navia said attackers accessed its systems between December 22, 2025 and January 15, 2026 and notified nearly 2.7 million people whose names, SSNs and FSA, HRA or COBRA details were exposed. Client HackerOne said the flaw was a broken object level authorization bug.
What is known
| People affected | 2,697,540 (as reported by the organization) |
|---|---|
| Disclosed | Mar 18, 2026 |
| Discovered | Jan 23, 2026 |
| Happened | Dec 22, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health, Dates of birth, Social Security numbers, Phone numbers, Emails, Insurance, Addresses |
| Sector | Finance · US |
| Status | Confirmed |
Sources
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Mar 18 | |
| Washington AGresidents of WA | Mar 18 | 319,208 |
| Delaware DOJresidents of DE | Mar 18 | 599 |
| Oregon DOJresidents of OR | Mar 18 | 2,697,540 |
| HHS OCRtotal | Mar 18 | 2,151,330 |
| Vermont AGresidents of VT | Mar 18 | |
| Indiana AGresidents of IN | Mar 18 | 6,088 |
| Researchtotal | Mar 19 | |
| Texas AGresidents of TX | Mar 20 | 62,821 |
History of this record
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-7_2026.pdf · backfill source
- 2026-09-25 · source: empty to https://ago.vermont.gov/document/2026-03-18-navia-benefit-solutions-data-breach-notice-consumers · backfill source
- 2026-09-25 · data_types: ["names","health","dob","ssn","phone","emails","insurance"] to ["names","health","dob","ssn","phone","emails","insurance","addresses"] · backfill source
- 2026-09-25 · records_basis: hhs to organization · backfill source
- 2026-09-25 · records: 2151330 to 2697540 · backfill source
- 2026-09-25 · sector: health to finance · seed source
- 2026-09-25 · data_types: ["names","health"] to ["names","health","dob","ssn","phone","emails","insurance"] · seed source
- 2026-09-25 · summary: empty to Benefits administrator Navia said attackers accessed its systems between December 22, 2025 and January 15, 2026 and notified nearly 2.7 million people whose names, SSNs and FSA, HRA or COBRA details were exposed. Client HackerOne said the f · seed source
- 2026-09-25 · title: empty to Navia benefits breach exposes SSNs of 2.7 million people · seed source
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 2151330 · backfill source
- 2026-09-25 · data_types: [] to ["names"] · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · discovered: empty to 2026-01-23 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.