Hackers silently accessed Navia's systems for 24 days between December 2025 and January 2026, stealing sensitive personal, health, and benefits data belonging to nearly 2.7 million individuals across 10,000 employers before the company even noticed anything was wrong.
Initial Access
Silent Entry
likely
Threat actors gained unauthorized access to Navia Benefit Solutions' internal systems on December 22, 2025 through an undisclosed method. No ransomware group has claimed responsibility and the exact entry vector remains unknown.