Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationmass-credential-exposurethird-party-vendor-breachhealthcare-sector-threat

Navia Benefit Solutions Breach Exposes Data on 2.7 Million Benefits Enrollees

Updated 3mo agoFirst seen Mar 20, 202613 sources

Navia Benefit Solutions, a Washington-based third-party workplace benefits administrator serving more than 10,000 U.S. employers, disclosed a cyberattack that gave unauthorized actors read-only access to its network between December 22, 2025, and January 15, 2026. The company said the breach may have affected 2,697,540 individuals and exposed a broad set of personal and benefits data, including names, dates of birth, Social Security numbers, phone numbers, email addresses, and enrollment information tied to FSA, HRA, and COBRA accounts, with some records reportedly dating back to 2018.

Navia detected suspicious activity on January 23 and said it notified federal law enforcement and regulators, including the U.S. Department of Health and Human Services, in a breach reportable under HIPAA. Notification letters began going out on March 18 after a substitute notice was posted on March 13, and the company is offering 12 months of credit monitoring and identity theft protection through Kroll. One confirmed affected client, the Washington State Health Care Authority, said the incident involved records spanning seven years for tens of thousands of PEBB, SEBB, and COFA members, as well as data linked to 37 school districts; Navia has not said ransomware was involved and no ransomware group has claimed the attack.

Share:
Navia Benefit Solutions Breach Exposes Data on 2.7 Million Benefits Enrollees
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 24, 20263mo ago

Report links Navia breach to BOLA flaw in API endpoint

A March 24, 2026 report said the Navia breach was caused by a Broken Object Level Authorization vulnerability in an API endpoint, which allegedly enabled an unknown actor to obtain read-only access to sensitive data. This introduced new technical detail about the mechanism behind the broader 2.7 million-person incident.

HackerOne Data Breach - Employees Data Stolen Following Navia Hack

HackerOne says Navia breach affected nearly 300 employees

HackerOne disclosed that a breach at benefits administrator Navia Benefit Solutions exposed sensitive employee and benefits data belonging to nearly 300 of its workers. The company said the incident originated in Navia's environment rather than HackerOne's own systems and criticized the delayed notification.

HackerOne slams supplier over delayed breach notice • The Register
Mar 20, 20263mo ago

Washington State Health Care Authority confirms impact

The Washington State Health Care Authority said the breach affected records spanning seven years for tens of thousands of PEBB, SEBB, and COFA members, as well as data tied to 37 school districts. This identified a confirmed downstream client affected by the Navia incident.

Navia discloses 2.7 million-person breach and notifies authorities

Navia publicly disclosed that a cyberattack may have exposed personal and benefits data of nearly 2.7 million individuals, including names, dates of birth, Social Security numbers, contact details, and FSA, HRA, and COBRA information. The company also notified federal law enforcement and regulators, including the U.S. Department of Health and Human Services.

Mar 18, 20263mo ago

Navia begins mailing breach notification letters

On March 18, 2026, Navia began sending notification letters to affected individuals about the breach. The company said 2,697,540 people may have been impacted and offered 12 months of credit monitoring and identity theft protection.

Mar 13, 20264mo ago

Navia posts substitute breach notice

Navia posted a substitute notice about the data breach as part of its public notification process. This occurred before individual letters were mailed to affected people.

Jan 23, 20265mo ago

Navia detects suspicious activity

Navia said it detected suspicious activity in its environment on January 23, 2026, prompting an investigation into the incident. The company later linked the activity to unauthorized access affecting benefits and personal data.

Dec 22, 20256mo ago

Attackers access Navia systems

Navia Benefit Solutions later determined that unauthorized actors had read-only access to its network and systems during this period. The exposure window ran from December 22, 2025 through January 15, 2026.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Organizations
10 linked
Navia Benefit SolutionsHackerOneKrollSecurity AffairsTransUnionBleepingComputerExperianEquifaxPentest-Tools.comCertes
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.