Navient
Disclosed Jul 2, 20262 months agoConfirmed
Navient borrower SSNs exposed in ransomware attack on outside law firm
Student loan servicer Navient told the SEC that a ransomware attack on a third-party law firm exposed borrower names, birth dates, addresses and SSNs held by the firm. Navient's own systems were not compromised.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 2, 2026 |
| Discovered | Jun 8, 2026 |
| Attack | Vendor breach |
| Data exposed | Names, Dates of birth, Addresses, Social Security numbers |
| Sector | Finance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Navient Corp Form 8-K, Item 1.05 (2026-07-02)sec.gov · SEC filing | SEC filing |
Notices filed
History of this record
- 2026-09-25 · sector: other to finance · seed source
- 2026-09-25 · attack: unknown to third-party · seed source
- 2026-09-25 · data_types: [] to ["names","dob","addresses","ssn"] · seed source
- 2026-09-25 · discovered: empty to 2026-06-08 · seed source
- 2026-09-25 · summary: empty to Student loan servicer Navient told the SEC that a ransomware attack on a third-party law firm exposed borrower names, birth dates, addresses and SSNs held by the firm. Navient's own systems were not compromised. · seed source
- 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Navient borrower SSNs exposed in ransomware attack on outside law firm · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (SEC 8-K), confirmed by SEC 8-K. Record counts are as reported. Not legal advice.