HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Employee PII Breach at Navia Exposes 287 HackerOne Staff via BOLA Vulnerability

A Broken Object Level Authorization (BOLA) vulnerability in Navia, the benefits administrator for HackerOne, was leveraged to exfiltrate personal data of 287 HackerOne employees and their dependents. The breach underscores the risk that third‑party platform flaws pose to security‑services providers and their downstream customers.

LiveThreat™ Intelligence · 📅 March 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Employee PII Breach at Navia Exposes 287 HackerOne Staff via BOLA Vulnerability

What Happened — Attackers exploited a Broken Object Level Authorization (BOLA) flaw in Navia, a benefits‑administration platform used by HackerOne, to steal personal data of 287 HackerOne employees and their dependents between Dec 22 2025 and Jan 15 2026. The breach was disclosed in March 2026 after Navia reported suspicious activity.

Why It Matters for TPRM

  • Employee PII (SSNs, DOB, addresses) can be weaponised for credential‑stuffing and social‑engineering attacks against your own workforce and partners.
  • A third‑party benefits administrator’s vulnerability directly compromises the security posture of a critical security‑services vendor (HackerOne).
  • The incident highlights the need for continuous assessment of third‑party access controls and data‑handling practices.

Who Is Affected — Financial‑services/benefits administration sector (Navia) and security‑services sector (HackerOne).

Recommended Actions — Review contracts with Navia and HackerOne for data‑protection clauses, verify that BOLA remediation has been completed, and mandate multi‑factor authentication and monitoring for any accounts that may have been derived from the exposed data.

Technical Notes — Attack vector: exploitation of a BOLA vulnerability (unauthorised object access) leading to data exfiltration of SSNs, full names, addresses, DOB, email, and employment dates. No ransomware or extortion was reported. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackerone-discloses-employee-data-breach-after-navia-hack/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →