TL;DR: Navia Benefit Solutions (a company that manages health spending accounts, COBRA benefits, and flexible spending for over 10,000 employers) left an API wide open for 24 days. An attacker exploited a Broken Object Level Authorization (BOLA) flaw to read Social Security numbers, dates of birth, health plan details, and personal information for 2,697,540 people. Among the victims: 287 employees of HackerOne, the cybersecurity firm that runs bug bounty programs. Navia took two months to notify victims. HackerOne is publicly furious about the delay.
The Breach: A Broken API Nobody Noticed for 24 Days
Between December 22, 2025 and January 15, 2026, someone exploited a BOLA vulnerability in Navia Benefit Solutions’ API. For 24 straight days, the attacker had read-only access to participant records.[1]
BOLA vulnerabilities are embarrassingly basic. They let an authenticated user manipulate API request identifiers to pull up someone else’s records. Change a number in the URL, see a different person’s Social Security number. It’s the digital equivalent of a filing cabinet with no locks, and Navia had 2.7 million files inside.
Navia didn’t catch it until January 23, eight days after the attacker stopped. The company didn’t post a public breach notice until March 13. Individual letters didn’t go out until March 18.[2]
That’s nearly three months from breach to notification.
What Was Exposed
According to Navia’s filing with the Maine Attorney General, the breach affected 2,697,540 individuals.[3] The attacker accessed:
- Social Security numbers
- Full names and addresses
- Dates of birth
- Phone numbers and email addresses
- Health plan participation details: COBRA, FSAs, HSAs, HRAs, dependent care accounts
- Navia and employee ID numbers
Navia says no claims data, financial account numbers, or bank information was accessed.[1] Cold comfort when someone has your SSN, date of birth, and health plan details: the trifecta for identity theft.
The Irony: HackerOne Got Hacked Through Its Benefits Admin
Here’s where this story gets painful.
HackerOne (the company that literally runs bug bounty programs for the US Department of Defense, Goldman Sachs, and dozens of Fortune 500 firms) had 287 employees caught in the Navia breach.[4]
A company that pays hackers to find security flaws got burned by its own benefits vendor’s broken API.
HackerOne didn’t take it quietly. The company publicly slammed Navia for delayed notification, stating it was “still waiting for a satisfactory reason for the delay.” Letters were dated February 20 but didn’t reach HackerOne until March.[5]
HackerOne told employees to monitor for fraud, consider credit freezes, and signaled it would “consider other potential options for benefits providers” if Navia’s security practices don’t improve.[5]
Washington State Workers Hit Hard
Navia is headquartered in Renton, Washington, and served as benefits administrator for Washington state’s public employees. The breach hit:[6]
- Approximately 27,000 Public Employees Benefits Board (PEBB) members
- Around 5,600 School Employees Benefits Board (SEBB) members
- About 3,000 COFA islander program members
- Employees from 37 school districts that contracted with Navia before January 2020
Teachers, state workers, school administrators: people who signed up for benefits through their employer and had no say in which company managed their data.
BOLA: The #1 API Vulnerability That Shouldn’t Exist in 2026
BOLA sits at the top of the OWASP API Security Top 10. It’s been the most common API vulnerability for years. Every API security guide warns about it. Every penetration test checks for it.
The fix? Proper authorization checks on every API endpoint. Verify that the user requesting data is actually authorized to see that specific record. It’s not exotic cryptography. It’s basic access control.
Navia has since “reinforced its API authorization, enabled multifactor authentication, and enforced strict data access controls.”[1] Which means they weren’t doing those things before.
A benefits administrator handling Social Security numbers for 2.7 million people didn’t have basic API access controls. Let that sink in.
Lawsuits Are Coming
Multiple law firms, including Edelson Lechtzin LLP, Murphy Law Firm, and The Lyon Firm, announced class action investigations by late March 2026.[7] No formal suits have been filed yet, but the ingredients are all there:
- 2.7 million affected individuals
- Social Security numbers exposed
- Months-long notification delay
- A preventable vulnerability (BOLA is well-documented)
- Health data implications under HIPAA
If you got a letter from Navia, don’t throw it out. You’ll need the enrollment code inside.
What You Should Do Right Now
Freeze Your Credit
Don’t just monitor, freeze. Contact Equifax, Experian, and TransUnion. It’s free. It blocks new accounts from opening in your name. Thaw it temporarily when you need credit.
Enroll in Kroll Monitoring
Navia is offering 12 months of free identity theft protection through Kroll. Use the enrollment code in your notification letter. It’s not much, but it’s free and includes credit monitoring, fraud consultation, and identity restoration.[2]
Check Your Health Benefits Accounts
Log into any FSA, HSA, HRA, or COBRA accounts managed by Navia. Look for unauthorized claims, address changes, or benefit modifications you didn’t make.
File an IRS Identity Protection PIN
With your SSN exposed, tax fraud is a real risk. Get an IP PIN from the IRS to prevent someone from filing a return in your name.
The Real Problem: You Don’t Choose Your Benefits Admin
Here’s what makes breaches like this especially frustrating: you didn’t pick Navia. Your employer did. Your school district did. Your state government did.
You signed up for health benefits through work. Your employer contracted with Navia. Navia had a broken API. Now your Social Security number is in the wind.
This is the supply chain problem applied to personal data. Every time you hand information to your employer for benefits, it flows to administrators, processors, and subcontractors you’ve never heard of. One weak link, one company that skips basic API security, and millions of records spill.
Navia serves 10,000 clients and over a million active participants.[1] They’ve been in business since 1989. And they couldn’t be bothered to implement proper authorization checks on their API.
References
- IDStrong: Navia Benefit Solutions Data Breach 2026 Exposes 2.7 Million Records
- ClassAction.org: Navia Benefit Solutions Data Breach May Have Exposed Info of 2.6M (March 2026)
- Office of the Maine Attorney General: Data Breach Notifications
- Cyber Security News: HackerOne Data Breach: Employees Data Stolen Following Navia Hack
- The Register: HackerOne slams supplier over delayed breach notice (March 2026)
- Levi & Korsinsky: Navia Benefit Solutions Data Breach Investigation
- CPO Magazine: Data Breach Hits Benefits Administrator Navia, Affecting Nearly 2.7 Million People