In June 2026, Navient Corp experienced a third-party data breach, which was disclosed through a SEC filing on July 2, 2026. The breach involved unauthorized access to the systems of a law firm providing services to Navient, not Navient's own systems.
The incident affected approximately 2.5 million student loan borrowers. The exposed data types included names, dates of birth, addresses, and Social Security numbers. Navient has stated that it does not believe the incident will have a material impact on its financial condition.
Details about this incident are still emerging and consumer notifications are being issued.