Menu
Browse

Cyber Incident Victim: Xsolis, Inc.

Date

Jan 2026

Location

United States of America

Status

Unknown

Updated

2026-07-23 00:21

Timeline
Occurred
Jan 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Xsolis, Inc., a healthcare technology company that provides utilization management and revenue cycle solutions, disclosed a data breach after detecting unauthorized activity on its systems resulting from a targeted phishing attack. The intrusion exposed files containing personal and protected health information, including names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment data, affecting approximately 1.4 million individuals. The company stated it is not aware of any actual or attempted misuse of the information, and no ransomware group has claimed responsibility for the incident. A national class action law firm has launched an investigation into potential legal claims on behalf of those whose data may have been compromised.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 20, 2026, a targeted phishing attack was launched against Xsolis, Inc.'s network. Two days later, on January 22, 2026, the company detected unauthorized activity on its systems. Upon discovering the breach, Xsolis contained the intrusion and terminated the unauthorized access. The incident was not publicly disclosed until early June 2026, when the company issued a data security notice detailing the event.

Cyber Incident Image

The breach exposed files containing personal and protected health information that Xsolis receives from its hospital, health system, and payer clients. Compromised data included names, dates of birth, addresses, Social Security numbers, health insurance information, and medical treatment information. According to the U.S. Department of Health and Human Services, the breach affected 1,396,519 individuals, a figure added to the HHS data breach tracker on June 21, 2026. Xsolis stated in its disclosure that it is not aware of any actual or attempted misuse of the information resulting from the incident.

Individuals who received a data breach notification from Xsolis were informed that they may face an increased risk of identity theft and fraud. No ransomware group has claimed responsibility for the attack, and the company has not confirmed whether any extortion attempt or ransom payment occurred. Edelson Lechtzin LLP launched an investigation into the breach to evaluate potential class action claims on behalf of affected individuals. The notification advised recipients to remain vigilant for suspicious activity related to their personal and health information.

Sources
Sources available to members
2 sources