Navient discloses ransomware breach at third-party law firm
Navient Corporation (NASDAQ: NAVI) disclosed a cybersecurity incident involving a third-party law firm that provides legal services to the company, according to an 8-K filing with the U.S. Securities and Exchange Commission.
The company said it became aware of the incident on June 8, 2026, when the unnamed law firm reported it had been hit by a ransomware attack affecting certain of its information systems. An unauthorized actor accessed company-related data held by the firm, including borrower names, dates of birth, addresses, and Social Security numbers.
Navient stated the incident was contained within the law firm's environment and that no unauthorized access to Navient's own systems was identified. The company said its operations and customer services were not disrupted.
Navient determined the incident to be material on June 29, 2026, citing the volume and sensitivity of the information involved. The company said it has engaged external cybersecurity experts, is notifying affected individuals and regulators as required under applicable federal and state laws, and has informed law enforcement.
As of the filing date, Navient said it does not believe the incident has had, or is reasonably likely to have, a material impact on its financial condition or results of operations.
