← All filing news

Navient discloses ransomware attack on third-party law firm

Navient became aware on June 8, 2026 of a ransomware attack on a third-party law firm that provides legal services to the company. An unauthorized actor accessed company-related data maintained by the firm, including borrower information such as customer names, dates of birth, addresses, and Social Security numbers. The company determined the incident to be material on June 29, 2026 due to the volume and sensitivity of the information involved, though it stated the incident was limited to the law firm's environment, with no evidence of unauthorized access to its own systems or disruption to operations, and does not believe the incident has had or is reasonably likely to have a material impact on its financial condition or results of operations.

Key facts

  • Incident involved unauthorized access to borrower information including customer names, dates of birth, addresses, and Social Security numbers
  • Cybersecurity incident at third-party law firm discovered June 8, 2026
  • Company determined incident material on June 29, 2026
  • No evidence of unauthorized access to Navient's own systems
  • No disruption to operations or customer services

Why it matters

The incident exposed sensitive borrower personal information held by a service provider, triggering notification obligations to affected individuals and regulators under federal and state law and requiring disclosure as a material cybersecurity event, though Navient believes no financial impact will result.

Share

Get this as a morning email

The day's newsworthy SEC filings in one free daily brief. No account needed.

Derived from 8-K filed 2026-07-02. Not investment advice. View the source filing on SEC.gov →