HackerOne Data Breach – Employees Data Stolen Following Navia Hack
HackerOne has reported a data breach impacting 287 employees due to a cyberattack on its U.S. benefits administrator, Navia Benefit Solutions. The breach was caused by a Broken Object Level Authorization (BOLA) vulnerability in Navia's API, exposing…
HackerOne has reported a data breach impacting 287 employees due to a cyberattack on its U.S. benefits administrator, Navia Benefit Solutions. The breach was caused by a Broken Object Level Authorization (BOLA) vulnerability in Navia's API, exposing personal and health information of approximately 2.7 million individuals nationwide.
The unauthorized access occurred between December 22, 2025, and January 15, 2026. Navia detected the activity on January 23, 2026, and initiated an internal investigation with federal law enforcement. Despite the breach being identified in late January, HackerOne was informed in March 2026.
HackerOne met with Navia on March 13, 2026, to assess the data compromise scope. The platform has criticized the notification delay and is seeking an explanation. An internal investigation has been launched to evaluate Navia’s privacy and security practices, with potential consideration of alternative benefits providers.
HackerOne has reported a data breach impacting 287 employees due to a cyberattack on its U.S.
Although financial and claims data were not accessed, the exposed dataset could facilitate social engineering, identity theft, and phishing attacks. HackerOne employees have been advised to be vigilant against phishing attempts exploiting the stolen data.
Recommendations for Affected Individuals
Monitor financial accounts for unusual activities. Update passwords and security questions. Utilize complimentary identity protection services.
Based on reporting by Cyber Security News.
