Navient Corp disclosed a cybersecurity incident involving a third-party law firm that provides legal services. A ransomware attack on the firm allowed an unauthorized actor to access client data, including borrower names, addresses, dates of birth, and Social Security numbers. Navient stated it found no evidence of intrusion into its own systems and no disruption to services, but deemed the incident material because of the volume and sensitivity of the information involved. As of the report date, the company does not believe the incident will have a material impact on its financial condition.
View Full Filing (SEC EDGAR)