Navia Confirms Data Breach Exposing Sensitive Information of 2.7 Million Users
Navia Benefit Solutions recently experienced a data breach affecting approximately 2.7 million individuals. The breach involved unauthorized access to sensitive personal and health plan information.
Navia Benefit Solutions recently experienced a data breach affecting approximately 2.7 million individuals. The breach involved unauthorized access to sensitive personal and health plan information.
The breach originated from a vulnerability in an Application Programming Interface (API) used by Navia. The unauthorized party exploited this vulnerability to gain read-only access to participant data, delaying detection of the breach. Navia has since patched the API vulnerability and temporarily disabled participant registration to enhance authentication controls. No evidence of system-wide encryption or ransomware involvement has been found.
The breach affected records from 2018 onward, impacting current and former members of public employee benefit programs. The compromised data includes:
Navia Benefit Solutions recently experienced a data breach affecting approximately 2.7 million individuals.
Personal identifiers: full names, dates of birth, and physical addresses Contact details: email addresses and phone numbers Social Security numbers and Navia ID numbers Health plan details: participation in HRAs, FSAs, and COBRA, along with termination dates
Upon identifying the breach, Navia secured the affected API endpoints and initiated an internal investigation with external forensic specialists. Federal law enforcement and relevant regulatory authorities, including the U.S. Department of Health and Human Services, were notified. Employers currently or previously contracted with Navia have also been informed about the data exposure.
To assist affected individuals, Navia is providing 12 months of complimentary identity protection and credit monitoring services through Kroll. Users are advised to monitor their credit reports and place fraud alerts for any suspicious activity. Navia has strengthened its systems by implementing enhanced multi-factor authentication requirements.
Based on reporting by GBHackers.
