Data leak β›“ Supply Chain

Navia Benefit Solutions BOLA Vulnerability Data Breach

πŸ“… 2025-12-22 🏒 Navia Benefit Solutions (employee benefits administration platform)
Primary Source β†—

Incident Details

Navia Benefit Solutions, an employee benefits administration company, suffered a data breach due to a BOLA (Broken Object Level Authorization) API vulnerability. An unknown threat actor accessed Navia’s systems between December 22, 2025 and January 15, 2026. Navia became aware on January 23, 2026. The breach affected 2,697,540 individuals whose data was held by Navia as a benefits third-party processor. Exposed information included names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. Downstream victims included employees of numerous companies, including 287 HackerOne employees. Notification letters were dated February 20, 2026 but received delayed by some companies.

Technical Details

Initial Attack Vector
Broken Object Level Authorization (BOLA) vulnerability in Navia's systems allowed unauthorized access to benefit plan data
Vendor / Product
Navia Benefit Solutions (employee benefits administration platform)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-12-22 Breach occurred
  2. 2026-01-23 Publicly disclosed
  3. 2026-02-20 Customers notified