---
title: "RXNT solution data incident"
description: "Evidence-backed account of RXNT solution data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/rxnt-solution-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/rxnt-solution-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/rxnt-solution-data-incident-2026/stix.json"
---

# RXNT solution data incident

Unauthorized access within an RXNT solution used by a portion of its healthcare customers, with data acquisition between March 1 and March 3, 2026. Acquisition of personal and medical data held in the affected RXNT solution for healthcare-provider customers.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access within an [RXNT](https://www.rxnt.com/) solution used by a portion of its healthcare customers, with data acquisition between March 1 and March 3, 2026. [1](#source-1)

## Impact

Acquisition of personal and medical data held in the affected RXNT solution for healthcare-provider customers. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Names — Names; affected fields varied by person. [1](#source-1) [3](#source-3)
- Social Security numbers — Social Security numbers; affected fields varied by person. [1](#source-1) [3](#source-3)
- Clinical information — Medical information reported by the Texas and Massachusetts registries; affected fields varied by person. [1](#source-1) [3](#source-3)
- Dates of birth — Dates of birth; affected fields varied by person. [1](#source-1) [3](#source-3)

A cited record reports 49,338 individuals (Texas residents in report BR-0005076; a subset of the overall count and not additive; as of 2026-05-29). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,183 individuals (Massachusetts residents in report 2026-869; a subset of the overall count and not additive; as of 2026-05-29). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 65,795 individuals (Total individuals affected in Texas Attorney General report BR-0005076; regulator-reported and not independently verified; as of 2026-05-29). [1](#source-1) [2](#source-2) [3](#source-3)

RXNT said the incident did not involve payment-card, bank-account, or other financial information and that it was not aware of related identity theft or fraud at the time of notice. [1](#source-1)

## Timeline

### March 1, 2026 — Activity began

Beginning of the data-acquisition window determined by RXNT's investigation. [1](#source-1)

### March 3, 2026 — Documented activity ended

End of the data-acquisition window determined by RXNT's investigation. [1](#source-1)

### March 3, 2026 — Discovery

Date RXNT says it became aware of unauthorized activity. [1](#source-1)

### May 1, 2026 — Public disclosure

Date RXNT says it began notifying affected customers; individual and regulator notices could occur later. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

RXNT notified law enforcement during its response. RXNT offered affected people a templated 12 or 24 months of complimentary credit monitoring, depending on the individual notice. RXNT said it contained the activity with external cybersecurity experts and confirmed the unauthorized actor was eliminated from the environment. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/rxnt-solution-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### RXNT Notice of Data Event

official · Networking Technology, Inc.

<https://www.mass.gov/doc/2026-869-networking-technology-inc/download>

<a id="source-2"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-3"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Disclosed At · 100% confidence · current**  
   RXNT customer and individual notifications: 2026-05-01
2. **Ended At · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: 2026-03-03
3. **Exposed Data Category · 100% confidence · current**  
   RXNT customer-patient data exposure: Names
4. **Resulted In · 100% confidence · current**  
   RXNT customer-patient data exposure: RXNT said the incident did not involve payment-card, bank-account, or other financial information and that it was not aware of related identity theft or fraud at the time of notice.
5. **Exposed Data Category · 100% confidence · current**  
   RXNT customer-patient data exposure: Social Security numbers
6. **Began At · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: 2026-03-01
7. **Exposed Data Category · 100% confidence · current**  
   RXNT customer-patient data exposure: Clinical information
8. **Exposed Data Category · 100% confidence · current**  
   RXNT customer-patient data exposure: Dates of birth
9. **Resulted In · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: RXNT notified law enforcement during its response.
10. **Resulted In · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: RXNT customer-patient data exposure
11. **Discovered At · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: 2026-03-03
12. **Affected Individual Count · 100% confidence · current**  
   RXNT customer-patient data exposure: 49,338 individual
13. **Resulted In · 100% confidence · current**  
   RXNT customer and individual notifications: RXNT offered affected people a templated 12 or 24 months of complimentary credit monitoring, depending on the individual notice.
14. **Resulted In · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: RXNT customer and individual notifications
15. **Affected Individual Count · 100% confidence · current**  
   RXNT customer-patient data exposure: 1,183 individual
16. **Resulted In · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: RXNT said it contained the activity with external cybersecurity experts and confirmed the unauthorized actor was eliminated from the environment.
17. **Affected Organization · 100% confidence · current**  
   March 2026 RXNT unauthorized activity: Networking Technology, Inc.
18. **Affected Individual Count · 100% confidence · current**  
   RXNT customer-patient data exposure: 65,795 individual

</details>
