← Navia Benefit Solutions

2026 Navia Benefit Solutions — 2.7M individuals (vulnerable API)

2026 2.7M records affected Share on X

Data compromised

Names, DOB, SSNs, phones, emails, benefit program information

Technical writeup

Navia Benefit Solutions, a third-party administrator for employee benefits (FSA, HRA, COBRA) serving 10,000+ U.S. employers, disclosed a breach affecting approximately 2.7 million individuals. Unauthorized access occurred December 22, 2025 through January 15, 2026 via a vulnerable API endpoint. Discovered January 23, 2026. Exposed: full names, DOB, SSNs, phone numbers, emails, Navia IDs, benefit participation info (FSA, HRA, COBRA enrollment/termination back to 2018). Claims data, financial accounts, and bank numbers were not accessed. Navia patched the API, enhanced MFA, suspended new registrations temporarily, notified HHS and law enforcement, and offered 12 months Kroll credit monitoring.

Root cause

Vulnerable API endpoint; unauthorized API access

References