
Bug bounty platform HackerOne is informing hundreds of workers that their private information was compromised after hackers broke into Navia’s systems, a company that manages benefits for them in the U.S.
HackerOne runs over 1,950 bug bounty programs, along with offering vulnerability reporting, penetration testing, and code security assistance to major organizations like General Motors, Goldman Sachs, Anthropic, GitHub, and Uber. They also provide services to U.S. government bodies, such as the Department of Defense.
Navia is a large benefits administrator for consumers, assisting over 10,000 employers throughout the country.
In a report filed with the Maine Attorney Generalâs office, HackerOne also disclosed that the data breach compromised the personal data of 287 employees.
The company stated that a Broken Object Level Authorization (BOLA) vulnerability allowed an unauthorized individual to access Navia data between December 22, 2025, and January 15, 2026. Navia became aware of the suspicious activity on January 23, 2026 and sent letters to impacted companies on February 20, 2026.
The compromised data included Social Security numbers, complete names, addresses, phone numbers, birth dates, email addresses, plan enrollment dates, effective dates, and termination dates for impacted employees and their dependents.
HackerOne is advising affected employees to remain vigilant for suspicious communications, keep an eye on their financial accounts for any unusual activity, and use the 12-month free identity protection and credit monitoring service from Navia.
The company also advised that you “May also want to consider changing passwords or password hints/security questions if they involve the personal data listed above.”
When announcing the breach earlier in the month, Navia emphasized that it did not affect claims or financial information.
However, the exposed information could be used by malicious actors to conduct phishing scams and social engineering attacks against those impacted.
Although Navia categorized the event as data theft, no cybercriminal group or ransomware operation has claimed responsibility.
#data #employee #exposed #hackerone #incident #navia #news #reveals #security — News
© Bulletproof Servers. All rights reserved.