Navia reveals security incident; 2.7M affected.
Mar 20, 2026 // 11:17 - Norina Velotta


Navia Benefit Solutions, Inc. (Navia) is alerting almost 2.7 million people about a security incident where their private data was compromised.

The investigation showed that unauthorized parties had access to Navia’s systems from December 22, 2025, to January 15, 2026. The company noticed the unusual activity on January 23.

Navia claims they took immediate action and began looking into the potential effects of the incident.

“The investigation showed that an unauthorized party accessed and obtained some information between December 22, 2025, and January 15, 2026,” the company stated in the notification to affected individuals.

Navia is a benefits administrator serving consumers and supporting over 10,000 employers nationwide.

The company offers software and support for managing Flexible Spending Accounts (FSA), Health Savings Accounts (HSA), Health Reimbursement Arrangements (HRA), Commuter Benefits, and COBRA Services.

They also assist with commuter benefits, lifestyle accounts, education benefits, compliance/risk services, and retirement plans.

According to the company, the probe indicated that hackers accessed and might have stolen the following data:

  • Full name
  • Date of birth
  • Social Security Number (SSN)
  • Phone number
  • Email address
  • Participation in HRA (Health Reimbursement Arrangements)
  • FSA (Flexible Spending Accounts) information
  • Consolidated Omnibus Budget Reconciliation Act (COBRA) enrollment information

Navia emphasizes that the compromise didn’t involve claims details or financial information. However, the exposed data could enable malicious actors to conduct phishing and social engineering schemes against those affected.

The organization mentions that it has examined its security measures and data storage policies to find areas for improvement and has informed law enforcement about the event.

Those whose information was involved will receive a complimentary 12-month identity protection and credit monitoring service from Kroll. Notification recipients are also advised to think about adding a fraud alert and security freeze to their credit reports.

Currently, no ransomware organization has taken responsibility for the Navia breach.

#2.7m  #affected.  #incident  #navia  #news  #reveals  #security   —   News