2 Remove Virus

Navia data breach affects 2.7 million people in benefits systems

Navia Benefit Solutions, a US-based benefits administration provider, has disclosed a data breach affecting nearly 2.7 million individuals following unauthorised access to its systems.

 

 

The company said attackers accessed its network between December 22, 2025, and January 15, 2026. Suspicious activity was identified on January 23, after which Navia initiated an investigation to determine the scope and impact of the incident.

Navia provides services to more than 10,000 employers in the United States, supporting the administration of workplace benefits such as Flexible Spending Accounts, Health Savings Accounts, and COBRA programmes.

According to the company, the investigation found that an unauthorised actor accessed and may have acquired personal data stored within its systems. The exposed information includes full names, dates of birth, Social Security numbers, phone numbers, and email addresses. Additional data related to benefits participation, including Health Reimbursement Arrangements and Flexible Spending Accounts, may also have been affected.

Navia stated that the breach did not involve financial account details or claims information. However, the combination of personal identifiers and benefits-related data may be used in targeted phishing or social engineering activity, based on the company’s assessment.

The company said it responded to the incident by reviewing its systems and data handling practices to identify potential weaknesses. It also reported the breach to federal law enforcement authorities and is continuing its investigation into the incident.

Affected individuals are being notified and offered identity protection and credit monitoring services for a limited period. The company has not identified a specific threat group responsible for the breach at the time of disclosure.

The incident involves data connected to workplace benefits systems, which often contain personal and employment-related information collected over multiple years.