HackingTechnologyInformationVulnerability ExploitSupply Chain (3P Vendor)Employee Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Navia Benefit Solutions, Inc.
bd_7e58946c463fbc0e · schema v1 · pii pii-v1
Full breach record for Navia Benefit Solutions, Inc. →HackerOne's benefits administrator Navia Benefit Solutions experienced a breach via a BOLA vulnerability. An unknown actor accessed Navia data Dec 22, 2025–Jan 15, 2026; discovered Jan 23, 2026. Exposed employee data includes SSNs, names, addresses, DOBs, emails, and health plan details. 287 total affected; 1 Maine resident. Kroll credit monitoring (12–24 months) offered.
Maine clockDiscovered Jan 23, 2026 → Filed with AG Mar 23, 202659d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 14 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1327b0f8f436b5ebVermont State AGfiled 2026-03-23Candidate
- bd_46937c0f13e509b6Washington State AGfiled 2026-03-23Verified
- bd_3a19611a035e6141Texas State AGfiled 2026-03-20(3d gap)Verified
- bd_0c9adf1c54ef13f5Vermont State AGfiled 2026-03-18(5d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 7d gap
- bd_19b19fa6294fd428New Hampshire State AGfiled 2026-03-18(5d gap)Verified
- bd_4c79396a99036546HHS OCRfiled 2026-03-18(5d gap)Candidate
- bd_66f47ef5b3b4b5efMaine State AGfiled 2026-03-18(5d gap)Verified
- bd_80d300d85996db11Washington State AGfiled 2026-03-18(5d gap)Verified
- bd_a686e7254f7a3644Delaware State AGfiled 2026-03-18(5d gap)Verified
- bd_7682fb52f3657c51New Hampshire State AGfiled 2026-03-30(7d gap)Verified
Showing first 10 of 13 linked disclosures.
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7a57bd2b-9c89-4b3c-8ff9-41f55eea067c.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 23, 2026
- Raw hash
- a22dc396ffabc7353e344f6d4408b732822e5383af4600d23c5a1b77dc9712fa
Reporting entity
- Name
- HACKERONE INC.norm: hackerone
- Domain
- hackerone.com
- Industry
- Other Commercial
Victim entity
- Name
- Navia Benefit Solutions, Inc.norm: navia benefit
- Domain
- naviabenefits.com
- Industry
- Benefits Administration
- Industry
- Technologyllm
Incident
- Discovered
- Jan 23, 2026
- Materiality determined
- —
- Notification sent
- Mar 17, 2026
- Affected individuals
- 1
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Federal law enforcement was notified
- Third party
- via Navia Benefit Solutions, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- ME AG >30d · 59d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 23, 2026→ Filed with AG: Mar 23, 202659d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.