Breach taxonomy
Summary
Navient became aware on June 8, 2026 of a ransomware attack on a third-party law firm providing services to the company. An unauthorized actor accessed Navient-related borrower data held by the firm, including names, dates of birth, addresses and Social Security numbers. The incident was limited to the firm's environment with no access to Navient systems or operational disruption, but Navient determined it material on June 29, 2026 given the volume and sensitivity of the information.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized actor' with no attribution -> UNKNOWN.
MethodsRansomwareData ExfilSupply Chain
Filing states the incident 'involved a ransomware attack affecting certain of the Firm's information systems' with company data accessed at the third-party law firm -> RANSOMWARE + DATA-EXFIL + SUPPLY-CHAIN.