Security Firm Victim Of Attack On Benefits Provider
San Francisco, California-based cybersecurity provider HackerOne Inc. fell victim to an attack on one of its benefits administrators where the company suffered from a hack where a threat actor stole personally identifiable information from HackerOne’s employees.
HackerOne said it received notification via mail its benefits administrators, Navia, suffered an attack in December where the personal information ended up stolen. HackerOne met with Navia on March 13 to understand what data ended up impacted and the nature of the security incident.
“A Broken Object Level Authorization (BOLA) vulnerability led to an unknown actor accessing Navia data between December 22, 2025 and January 15, 2026,” HackerOne said in a notice to victims. “On January 23, 2026, Navia became aware of suspicious activity in their environment. Navia sent letters dated February 20, 2026 to impacted companies.”
