2026 Branch Metrics — Navia COBRA/benefits admin breach; workforce & dependents in scope
Data compromised
Names, DOB, SSNs, phones, emails, and tax-advantaged health-plan program participation per Navia and client notices
Technical writeup
Third-party benefits administrator Navia Benefit Solutions, which Branch Metrics used for COBRA, HRA, FSA, and related programs, disclosed unauthorized access to its environment between December 22, 2025, and January 15, 2026, with forensic identification around mid-January 2026. Navia’s Maine Attorney General filing cited 2,697,540 individuals across its full client base; Branch issued a companion notice (e.g., Massachusetts regulatory posting) confirming current and former employees and dependents had categories such as name, DOB, SSN, phone, email, and health-plan participation metadata in scope. This row records the employer-facing incident without attributing the entire Navia-wide victim tally solely to Branch.
Root cause
Unauthorized access to benefits-administration systems at vendor Navia Benefit Solutions