HackerOne discloses employee data breach after Navia hack
好的,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,理解主要信息。 文章讲的是HackerOne的一个漏洞赏金平台,他们通知员工数据被窃取了。攻击者入侵了他们的美国福利管理员Navia。HackerOne管理着很多公司的漏洞披露和安全服务,这次事件影响了287名员工,泄露了敏感信息如社保号、地址等。 接下来,我需要提取关键点:HackerOne的数据泄露、Navia被黑、287名员工受影响、泄露的信息类型、建议员工防范措施。然后把这些信息浓缩到100字以内。 可能的结构是:HackerOne因Navia被黑导致员工数据泄露,涉及社保号等敏感信息,建议员工提高警惕并提供保护服务。 检查字数是否符合要求,确保没有遗漏重要信息。最后,确保语言简洁明了。 </think> HackerOne因Navia被黑导致287名员工数据泄露,涉及社保号、地址等敏感信息。建议员工警惕异常活动并使用免费身份保护服务。 2026-3-24 14:15:18 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

HackerOne

Bug bounty platform HackerOne is notifying hundreds of employees that their data was stolen after attackers hacked Navia, one of its U.S. benefits administrators.

HackerOne manages over 1,950 bug bounty programs and provides vulnerability disclosure, penetration testing, and code security services to high-profile companies like General Motors, Goldman Sachs, Anthropic, GitHub, and Uber, as well as to U.S. government agencies such as the Department of Defense.

Navia is a leading consumer-focused benefits administrator serving over 10,000 employers across the United States.

In a filing with the Office of the Maine Attorney General, HackerOne also revealed that the data breach exposed the sensitive information of 287 employees.

"At this time, we have been informed that a Broken Object Level Authorization (BOLA) vulnerability led to an unknown actor accessing Navia data between December 22, 2025, and January 15, 2026," the company said. "On January 23, 2026, Navia became aware of suspicious activity in their environment. Navia sent letters dated February 20, 2026 to impacted companies."

The exposed information includes a combination of Social Security numbers, full names, addresses, phone numbers, dates of birth, email addresses, plan enrollment dates, effective dates, and termination dates for each affected employee and their dependents.

HackerOne also encouraged impacted employees to be cautious of suspicious messages, monitor their financial accounts for unusual activity, and take advantage of the 12-month free identity protection and credit monitoring service provided by Navia.

"You may also want to consider changing passwords or password hints/security questions if they involve the personal data listed above," the company added.

When it disclosed the incident earlier this month, Navia underlined that the data breach did not impact affected individuals' claims or financial information.

However, the exposed data is sufficient for threat actors to launch phishing and social engineering attacks against people impacted by the incident.

Although Navia flagged the incident as a data theft attack, no cybercrime group or ransomware operation has taken responsibility for the breach.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/hackerone-discloses-employee-data-breach-after-navia-hack/
如有侵权请联系:admin#unsafe.sh