CSIDB logo
Incident

Xsolis, Inc.

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 16:26

Linked entities

Victim
Xsolis, Inc.
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Jan 2026
Discovered
Jan 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Xsolis, Inc., a healthcare technology company that provides utilization management and revenue cycle solutions for hospitals, health systems, and payers, disclosed a data breach affecting approximately 1.4 million individuals after detecting unauthorized activity on its systems that stemmed from a targeted phishing attack. The intrusion allowed attackers to access files containing personal and protected health information, including names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment data. The company stated it is not aware of any actual or attempted misuse of the information, and no ransomware group has claimed responsibility for the incident. The breach was later recorded on the federal health department’s tracker, confirming the number of affected individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Xsolis discovered unauthorized activity on its systems on January 22, 2026, resulting from a targeted phishing attack that occurred on January 20, 2026. Upon detection, the company contained the issue and terminated the unauthorized access. The intrusion allowed attackers to access files storing personal and protected health information received from clients, including names, dates of birth, addresses, Social Security numbers, health insurance information, and medical treatment information. The breach affected approximately 1.4 million individuals, with the U.S. Department of Health and Human Services later reporting 1,396,519 affected individuals. Xsolis disclosed the breach in early June 2026, and the incident was subsequently added to the HHS data breach tracker.

The exposed data includes personal and health information, which may increase the risk of identity theft and fraud for affected individuals. Xsolis stated that it is not aware of any actual or attempted misuse of information resulting from the incident. No known ransomware group has claimed responsibility for the attack, and SecurityWeek inquired whether the breach involved an extortion attempt or ransom payment. Following the disclosure, Edelson Lechtzin LLP launched an investigation into the breach and is evaluating potential class action claims on behalf of affected individuals. The law firm is offering free case evaluations to individuals whose data may have been compromised in the Xsolis incident.

Sources

Sources available to members: 3 sources.

CSIDB