[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffHv9VU8p9sn9vWj1NauDxa84t4tJplM5FGcbcAG40WM":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"severity":32,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66b59ec60a8a05e03e26d2","HackerOneNavia2025","HackerOne Navia 2025 Data Breach","hackerone-navia-2025","hackerone.com",{"name":12,"sector":13,"country":14,"website":10},"HackerOne Inc.","Cybersecurity","United States","2025-12-22T00:00:00.000Z","2026-07-27T01:34:22.754Z",287,[19,20,21,22,23,24,25,26,27,28],"Social Security numbers","Full names","Physical addresses","Phone numbers","Dates of birth","Email addresses","Benefits plan enrollment dates","Benefits plan effective dates","Benefits plan termination dates","Dependent information","\u003Cp>\u003Cstrong>The HackerOne Navia 2025 data breach\u003C\u002Fstrong> is a third-party incident in which HackerOne notified 287 employees that sensitive information belonging to them and relevant dependents was stolen in the attack on its U.S. benefits administrator, Navia Benefit Solutions. An unknown actor accessed Navia data between December 22, 2025, and January 15, 2026.\u003C\u002Fp>\n\u003Cp>This entry is not a separate attack from Navia's broader breach; it represents the verified HackerOne employee subset of the same parent event. The Maine Attorney General record reports a total of 287 employees for HackerOne. LeakData supports company-level discovery while stating clearly that these people may overlap the wider total in the parent Navia record.\u003C\u002Fp>\n\u003Ch2>How Was the HackerOne Impact Confirmed?\u003C\u002Fh2>\n\u003Cp>HackerOne's notification attached to the regulatory record explains that Navia held benefits data on the company's behalf and that it was informed a Broken Object Level Authorization vulnerability allowed an unknown person to access the data. The Maine Attorney General filing identifies 287 affected HackerOne employees. Together, these documents confirm actual data theft and the company-specific scope.\u003C\u002Fp>\n\u003Cp>BleepingComputer compared the regulatory documents and published the access window, employee total, affected fields, and Navia timeline. Navia detected suspicious activity on January 23, 2026, and sent letters dated February 20 to impacted companies. No cybercrime group claimed responsibility, so LeakData adds no attacker name.\u003C\u002Fp>\n\u003Ch2>What Employee and Dependent Information Was Affected?\u003C\u002Fh2>\n\u003Cp>Depending on the person, the data may include a combination of Social Security numbers, full names, physical addresses, phone numbers, dates of birth, and email addresses. It can also include benefits-plan enrollment dates, effective dates, and termination dates describing employment and plan relationships. Information about relevant dependents may have appeared within employee files.\u003C\u002Fp>\n\u003Cp>Not every field should be assumed to have appeared for all 287 employees or every dependent. The notice describes a combination and provides no category-level subtotals. LeakData does not add financial accounts, passwords, health claims, or treatment details; according to Navia's parent disclosure, claims and financial information were not affected.\u003C\u002Fp>\n\u003Ch2>What Does the BOLA Vulnerability Mean?\u003C\u002Fh2>\n\u003Cp>Broken Object Level Authorization occurs when an application does not adequately verify whether a user may access a requested object or record. According to information passed to HackerOne, this flaw enabled an unknown actor to reach Navia data. The entry uses this as the provider-reported technical explanation and does not speculate about the exact endpoint or exploit code.\u003C\u002Fp>\n\u003Cp>The incident does not mean HackerOne's bug-bounty platform or customer security programs were compromised. The affected environment was Navia, which HackerOne used for employee benefits. HackerOne customers, researchers, and program data should not be treated as victims solely because of their relationship with the company.\u003C\u002Fp>\n\u003Ch2>How Do the 287 People Relate to the Parent Navia Record?\u003C\u002Fh2>\n\u003Cp>pwnCount and totalRecords use the 287 HackerOne employees in the Maine filing. This number is not a new pool of unique people added on top of the overall Navia total; it is a company-level subset of the same incident. One person can be represented in both the parent Navia entry and this HackerOne entry.\u003C\u002Fp>\n\u003Cp>The purpose of the child entry is not to inflate an aggregate but to let HackerOne employees find the incident and their specific scope when searching by company. LeakData preserves the relationship in the title, source, tags, and description. It does not create a second attack, separate access window, or independent attacker claim.\u003C\u002Fp>\n\u003Ch2>Notifications and Steps Employees Can Take\u003C\u002Fh2>\n\u003Cp>Navia offered affected people 12 months of complimentary identity protection and credit monitoring. HackerOne advised employees to watch for suspicious messages, monitor financial accounts for unusual activity, and consider changing password hints or security questions if they rely on the personal information listed in the notice.\u003C\u002Fp>\n\u003Cp>People whose Social Security number or birth date was involved may consider a credit freeze or fraud alert. Criminals who know benefits-enrollment dates can impersonate human resources or a health plan, so employees should verify messages requesting plan changes, bank details, or identity documents through known HackerOne and Navia channels.\u003C\u002Fp>\n\u003Ch2>How Should This LeakData Record Be Read?\u003C\u002Fh2>\n\u003Cp>breachDate is December 22, 2025, the start of the confirmed Navia data-access window. Access continued through January 15, 2026, Navia detected suspicious activity on January 23, company notices followed in February, and the regulatory disclosure became public in March. These dates form the timeline of one parent Navia incident.\u003C\u002Fp>\n\u003Cp>The verified HackerOne subset is 287 employees, with some information about employee dependents potentially involved. Names, contact and address details, birth dates, Social Security numbers, and plan enrollment and effective dates were affected. Claims and financial information are excluded, and the HackerOne platform and customer programs are not presented as compromised.\u003C\u002Fp>","HackerOne employee subset of the Navia Benefit Solutions data theft",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fhackerone_com.svg"]