Navia Benefit Solutions, Inc.
bd_7e58946c463fbc0e · schema v1 · pii pii-v1
Navia Benefit Solutions, Inc. reported a security incident where an unknown actor exploited a Broken Object Level Authorization (BOLA) vulnerability to access employee and dependent data between Dec 22, 2025, and Jan 15, 2026. Navia discovered suspicious activity on Jan 23, 2026. Data exposed included SSNs, names, addresses, DOBs, and health plan details for 287 individuals. Navia notified law enforcement and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 22, 2025
Begins
Jan 23, 2026
Discovered
Mar 23, 2026
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_061161adbd92b99e2026-03-18 · +5dCandidate
- Indiana State AGbd_163f3268394278612026-03-18 · +5dCandidate
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Mar 18 (IN), last Mar 23 (ME) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.