FEDERALItem 1.05 · mandatoryMalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Navient Corporation
bd_b5e45f0d9efde57c · schema v1 · pii pii-v1
Full breach record for Navient Corporation →Navient Corporation (CIK 0001593538) filed an 8-K on July 2, 2026, disclosing a material cybersecurity incident under Item 1.05. On June 8, 2026, Navient became aware that a third-party law firm experienced a ransomware attack. The attacker accessed Navient-related borrower data (names, DOB, addresses, SSNs) maintained by the firm. Navient's own systems were not directly accessed. The incident was deemed material on June 29, 2026. Navient engaged external experts, notified law enforcement, and is notifying affected individuals and regulators.
SEC clockMateriality determined Jun 29, 2026 → Filed Jul 2, 20263d ✓ SEC 4-day OK24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1593538/000114036126027441/ef20077249_8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 2, 2026
- Raw hash
- 2dcb8d1aa166e163e4b667487361512b6ba2160be661f10ad6be99aa1122419e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Navient Corporationnorm: navient
- SEC CIK
- 0001593538
Victim entity
- Name
- Navient Corporationnorm: navient
- SEC CIK
- 0001593538
Incident
- Discovered
- Jun 8, 2026
- Materiality determined
- Jun 29, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- conducting notifications to affected individuals and regulators
- Third party
- via Third-party law firm
- Initial access
- supply_chain
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 3d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 29, 2026→ Filed: Jul 2, 20263d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.