Data leak
β Supply Chain
Navia Benefit Solutions BOLA Vulnerability Data Breach
Primary Source βIncident Details
Navia Benefit Solutions, an employee benefits administration company, suffered a data breach due to a BOLA (Broken Object Level Authorization) API vulnerability. An unknown threat actor accessed Navia’s systems between December 22, 2025 and January 15, 2026. Navia became aware on January 23, 2026. The breach affected 2,697,540 individuals whose data was held by Navia as a benefits third-party processor. Exposed information included names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information. Downstream victims included employees of numerous companies, including 287 HackerOne employees. Notification letters were dated February 20, 2026 but received delayed by some companies.
Technical Details
- Initial Attack Vector
- Broken Object Level Authorization (BOLA) vulnerability in Navia's systems allowed unauthorized access to benefit plan data
- Vendor / Product
- Navia Benefit Solutions (employee benefits administration platform)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-12-22 Breach occurred
- 2026-01-23 Publicly disclosed
- 2026-02-20 Customers notified