Security Firm Victim Of Attack On Benefits Provider

June 30, 2026

INCIDENT

San Francisco, California-based cybersecurity provider HackerOne Inc. fell victim to an attack on one of its benefits administrators where the company suffered from a hack where a threat actor stole personally identifiable information from HackerOne’s employees.
HackerOne said it received notification via mail its benefits administrators, Navia, suffered an attack in December where the personal information ended up stolen. HackerOne met with Navia on March 13 to understand what data ended up impacted and the nature of the security incident.
“A Broken Object Level Authorization (BOLA) vulnerability led to an unknown actor accessing Navia data between December 22, 2025 and January 15, 2026,” HackerOne said in a notice to victims. “On January 23, 2026, Navia became aware of suspicious activity in their environment. Navia sent letters dated February 20, 2026 to impacted companies.”

Incident Date

December 22, 2025

Estimated Cost

Unknown at this time

Type of Malware

No Malware identified

Threat Source

No threat source identified