DisclosureLens
FEDERALItem 1.05 · mandatoryMalwareFinancial ServicesFinanceRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainIdentity (basic)Government IDMediumActive

Navient Corporation

bd_b5e45f0d9efde57c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 8, 2026

Filed

Jul 2, 2026

To disclose

24 days

Affected

Not disclosed

Confidence

67%
Full breach record for Navient Corporation

Navient Corporation (CIK 0001593538) filed an 8-K on July 2, 2026, disclosing a material cybersecurity incident under Item 1.05. On June 8, 2026, Navient became aware that a third-party law firm experienced a ransomware attack. The attacker accessed Navient-related borrower data (names, DOB, addresses, SSNs) maintained by the firm. Navient's own systems were not directly accessed. The incident was deemed material on June 29, 2026. Navient engaged external experts, notified law enforcement, and is notifying affected individuals and regulators.

SEC clockMateriality determined Jun 29, 2026Filed Jul 2, 20263d SEC 4-day OK24 days discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 25 days

Jun 8, 2026

Discovered

Jun 29, 2026

Scope determined

Jul 2, 2026

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.