Navia Data Breach Impacts 2.7 Million People

Related

Female Cybersecurity Leaders to Watch in North Carolina

North Carolina’s cybersecurity leadership strength cuts across state government,...

Female Cybersecurity Leaders to Watch in Minnesota

Minnesota’s cybersecurity leadership strength shows up across agriculture, banking,...

Google Deploys Gemini AI to Monitor Dark Web for Cyber Threats

What happened Google has deployed Gemini AI agents within its...

Infinite Campus Warns of Breach After ShinyHunters Claims Data Theft

What happened Infinite Campus, a major U.S. K-12 student information...

Dutch Ministry of Finance Discloses Breach Affecting Employees

What happened The Dutch Ministry of Finance confirmed that some...

Share

What happened

Navia Benefit Solutions disclosed a data breach affecting nearly 2.7 million individuals after an unauthorized actor accessed its systems between December 22, 2025, and January 15, 2026, with the activity discovered on January 23. The attacker accessed and potentially exfiltrated sensitive data including full names, dates of birth, Social Security numbers, phone numbers, email addresses, and benefits-related information such as FSA, HRA, and COBRA enrollment details. Navia said no claims or financial payment data were exposed but warned the stolen information could be used in phishing and identity theft campaigns. 

Who is affected

Customers and individuals whose data was managed by Navia, including employees of over 10,000 U.S. organizations using its benefits services, are affected. 

Why CISOs should care

The breach highlights the risks posed by third-party benefits administrators that store large volumes of sensitive personal and healthcare-related data, making them high-value targets for attackers. 

3 practical actions

  1. Assess third-party data exposure. Review vendors that manage employee benefits and sensitive personal data. 
  2. Monitor for identity theft and phishing risks. The exposed data includes key identifiers that can be used in social engineering attacks. 
  3. Offer protection services to affected individuals. Navia is providing credit monitoring and identity protection support. 

For more coverage of major security incidents affecting organizations worldwide, explore our reporting on Data Breaches.