Skip to content

Navient

Disclosed Jul 2, 20262 months agoConfirmed

SEC filing

Navient borrower SSNs exposed in ransomware attack on outside law firm

Student loan servicer Navient told the SEC that a ransomware attack on a third-party law firm exposed borrower names, birth dates, addresses and SSNs held by the firm. Navient's own systems were not compromised.

What is known

People affectedNot stated in the sources we have
DisclosedJul 2, 2026
DiscoveredJun 8, 2026
AttackVendor breach
Data exposedNames, Dates of birth, Addresses, Social Security numbers
SectorFinance · US
StatusConfirmed

Sources

Source
Navient Corp Form 8-K, Item 1.05 (2026-07-02)sec.gov · SEC filing

Notices filed

WhereFiledPeople
SEC 8-KtotalJul 2
ResearchtotalJul 2
History of this record
  • 2026-09-25 · sector: other to finance · seed source
  • 2026-09-25 · attack: unknown to third-party · seed source
  • 2026-09-25 · data_types: [] to ["names","dob","addresses","ssn"] · seed source
  • 2026-09-25 · discovered: empty to 2026-06-08 · seed source
  • 2026-09-25 · summary: empty to Student loan servicer Navient told the SEC that a ransomware attack on a third-party law firm exposed borrower names, birth dates, addresses and SSNs held by the firm. Navient's own systems were not compromised. · seed source
  • 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Navient borrower SSNs exposed in ransomware attack on outside law firm · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (SEC 8-K), confirmed by SEC 8-K. Record counts are as reported. Not legal advice.

Everything about Navient

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.