← SEC 公告列表 | NAVI SEC 公告 | NAVIENT CORP(NAVI)

重大事件 即時報告 8-K 2026-07-02

Navient 披露第三方律師事務所遭勒索軟件攻擊,客戶敏感資料外洩

於 SEC 網站開啟原文

AI 繁中摘要

Navient Corporation(納斯達克:NAVI)於2026年6月29日提交8‑K表格,披露一宗重大網絡安全事故。 事件於6月8日被發現,涉及為公司提供服務的第三方律師事務所遭到勒索軟件攻擊 📁🔒。該事務所通知Navient,有未經授權的行為者存取其系統中存儲的部分公司相關數據,包括客戶姓名、出生日期、地址及社會安全號碼。 公司立即展開調查,聘請外部網絡安全專家協助,並按聯邦及州法律要求通知受影響人士及監管機構,同時已通報執法部門。 Navient強調,事故僅限於該律師事務所的環境,公司自身系統未發現任何未經授權存取的證據,業務運作及客戶服務亦未受干擾。然而,考慮到被洩露信息的數量及敏感程度,董事會於6月29日判斷此事項屬於「重大」。 截至報告提交日期(7月2日),管理層認為該事件目前及合理可預見的未來,不太可能對公司的財務狀況或經營業績構成重大影響 ⚖️。投資者需留意潛在的監管後續或集體訴訟風險,但短期內財務影響似乎有限。
展開英文正文
false000159353800015935382026-06-292026-06-290001593538us-gaap:CommonStockMember2026-06-292026-06-290001593538navi:SixSeniorNotesDueDecember152043Member2026-06-292026-06-290001593538navi:PreferredStockPurchaseRightsMember2026-06-292026-06-29

 

 
 
 
 
 UNITED STATES

 SECURITIES AND EXCHANGE COMMISSION

 WASHINGTON, DC 20549

 

 

 
 

 

 

 FORM 8-K

 

 

 
 

 

 

 CURRENT REPORT

 

 

 Pursuant to Section 13 or 15(d)

 of The Securities Exchange Act of 1934

 

 

 Date of Report (Date of earliest event reported): June 29, 2026

 

 

 
 

 

 

 

 

 

 
 Navient Corporation

 

 

 

 

 
 (Exact name of registrant as specified in its charter)

 

 

 

 

 
 

 

 

 

 

 
 Delaware

 

 

  

 
 001-36228

 

 

  

 
 46-4054283

 

 

 

 

 
 (State or other jurisdiction of incorporation)

 

  

 
 (Commission File Number)

 

  

 
 (IRS Employer Identification No.)

 

 

 
 

 

 

 

 

 
 13865 Sunrise Valley Drive,
 Herndon, Virginia

 

  

 
 20171

 

 

 

 

 
 (Address of principal executive offices)

 

  

 
 (Zip Code)

 

 

 
 

 

 

 
 Registrant’s telephone number, including area code (302) 283-8000

 

 

 Not Applicable

 (Former name or former address, if changed since last report)

 

 

 
 

 

 
 

 

 Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the
 following provisions (see General Instruction A.2. below):

 

 

 

 

 

 ☐

 
 Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

 

 

 

 

 ☐

 

 
 Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

 

 

 

 

 ☐

 
 Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

 

 

 

 

 ☐

 
 Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))

 

 

 
 

 

 Securities registered pursuant to Section 12(b) of the Act:

 

 

 

 

 

 
 Title of each class

 

 
 Trading Symbol(s)

 

 
 Name of each exchange on which registered

 

 

 

 
 Common stock, par value $.01 per share

 

 

 
 NAVI

 

 

 
 The Nasdaq Global Select Market

 

 

 

 

 
 6% Senior Notes due December 15, 2043

 

 

 JSM

 
 The Nasdaq Global Select Market

 

 

 

 

 
 Preferred Stock Purchase Rights

 

 

 
 None

 

 

 
 The Nasdaq Global Select Market

 

 

 

 
 

 

 Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§230.405 of this
 chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§240.12b-2 of this chapter).

 

 

 

 
 Emerging growth company ☐

 

 
 

 

 If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new
 or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

 

  

 
 

 
 
 

 

 

 

 Item 1.05

 
 Material Cybersecurity Incidents

 

 

 

 

 On June 8, 2026, the Company became aware of a cybersecurity incident involving a third‑party law firm (the “Firm”) that provides services to the Company. The incident
 involved a ransomware attack affecting certain of the Firm’s information systems.

  

 The Company was informed by the Firm that an unauthorized actor accessed certain Company-related data maintained by the Firm as a result of the Firm’s provision of legal
 services to the Company. Such data includes borrower information such as customer names, date of birth, addresses and Social Security numbers. The Company promptly initiated an investigation, with the assistance of external cybersecurity experts,
 and is conducting notifications to affected individuals and regulators as required by applicable federal and state laws. Law enforcement has also been notified.

  

 The incident was limited to the Firm’s environment; the Company has not identified any evidence of unauthorized access to its own systems and has not experienced any
 disruption to its operations or customer services as a result of the incident. Notwithstanding the foregoing, the Company determined the incident to be material on June 29, 2026 in light of the volume and sensitivity of the information involved.

  

 As of the date of this report, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on its financial condition or results
 of operations.

  

 
 
 
 

 

 SIGNATURE

 

 
 

 

 

 
 Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on
 its behalf by the undersigned hereunto duly authorized.

 

 

 

 

 

  

 
 NAVIENT CORPORATION

 

 

 

  

  

  

 

 

  

 
 By:

 

 
 /s/ Matthew Sheldon

 

  

 

 

  

 
 Name:

 

 
 Matthew Sheldon

 

 

 

  

 
 Title:

 

 
 Senior Vice President & General Counsel

 

 

 

  

  

  

 

 

 
 
 Date: July 2, 2026