Bug bounty platform HackerOne disclosed a data breach affecting 287 employees and their dependents after its benefits administrator, Navia, was hacked. The breach exposed sensitive PII including Social Security numbers, names, addresses, and dates of birth due to a Broken Object Level Authorization (BOLA) vulnerability.
Initial Access
Benefits Portal Breach
confirmed
An unknown actor exploited a Broken Object Level Authorization (BOLA) vulnerability in Navia's systems, gaining unauthorized access to data between December 22, 2025, and January 15, 2026.
Defender cut points
Implement robust API security testing to identify and remediate BOLA vulnerabilities.Enforce strict authorization checks at every API call to ensure users can only access their own data.