[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuAbbBCel1hh-ZiqXIYznKPMd1TTSldezME_4DHxJinQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"74ac1774-8125-4686-901b-9c8896eae5f2","third-party-vendor-vulnerability-exposes-employee-data","723df3cf-12f8-4eff-ae35-c9a764569d67","Third-Party Vendor Vulnerability Exposes Employee Data","HackerOne experienced a data breach affecting 287 employees through their third-party benefits administrator Navia, which had a Broken Object Level Authorization (BOLA) vulnerability. This incident demonstrates how organizations can be compromised through weaknesses in their vendor ecosystem, even when their own systems remain secure. The breach exposed highly sensitive personal information including Social Security numbers, highlighting the critical importance of third-party risk management. Even security-focused companies like HackerOne are vulnerable when their vendors fail to properly secure systems and implement adequate access controls.","**Immediate actions:**\n- HackerOne should have conducted regular security assessments of Navia, including vulnerability scanning and penetration testing of systems handling sensitive employee data\n- Implementing contractual requirements for vendors to maintain specific security standards, conduct regular security testing, and promptly patch known vulnerabilities like BOLA would have reduced risk\n- requiring vendors to undergo periodic security audits and implementing data minimization practices to limit what sensitive information is shared with third parties could have reduced the impact\n\n**Long-term improvements:**\n- This breach could have been prevented through comprehensive third-party risk management practices",[12,13,14,15,16],"CIS Control 15","NIST SP 800-161","NIST AC-3","ISO 27036","GDPR Article 28","published","2026-03-24T15:43:00.641509+00:00","2026-03-24T15:43:00.517+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackerone-discloses-employee-data-breach-after-navia-hack\u002F","hackerone-discloses-employee-data-breach-after-navia-hack","HackerOne discloses employee data breach after Navia hack",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]