← HackerOne

2026 HackerOne — 287 employees via Navia (BOLA; ~2.7M total Navia ecosystem)

2026 287 records affected Share on X

Data compromised

SSNs, names, addresses, phones, DOB, emails, benefit enrollment metadata

Technical writeup

Bug bounty platform HackerOne notified employees that personal data was exposed through U.S. benefits administrator Navia Benefit Solutions. Maine Attorney General filings and press reporting (March 2026) cited 287 affected individuals. Navia attributed unauthorized access to a Broken Object Level Authorization (BOLA) API issue with access between approximately December 22, 2025 and January 15, 2026; suspicious activity was identified January 23, 2026. Data types described included Social Security numbers, names, addresses, phones, dates of birth, emails, and benefit enrollment dates for employees and dependents. HackerOne pointed affected staff to Navia-provided identity protection. This incident is downstream of the same Navia event affecting ~2.7M individuals broadly.

Root cause

Third-party breach (Navia); BOLA/API unauthorized access per Navia description

References