Xsolis targeted-phishing data incident

Targeted phishing led to unauthorized access to a limited portion of Xsolis's environment from January 20 through January 22, 2026. An unauthorized actor acquired files containing personal identifiers and protected health information provided by Xsolis clients.

Last modified

Summary

  • Environment: Vendor holding client-provided personal and protected health information in the affected environment.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Targeted phishing led to unauthorized access to a limited portion of Xsolis’s environment from January 20 through January 22, 2026. [4]

Impact

An unauthorized actor acquired files containing personal identifiers and protected health information provided by Xsolis clients. [2][4]

Documented data types include:

  • Clinical information — Medical-treatment information; data elements varied by individual. [4]
  • Contact information — Addresses; data elements varied by individual. [4]
  • Dates of birth — Dates of birth; data elements varied by individual. [4]
  • Health insurance information — Health-insurance information; data elements varied by individual. [4]
  • Names — Names; data elements varied by individual. [4]
  • Social Security numbers — Social Security numbers; data elements varied by individual. [4]

A cited record reports 139,424 individuals (Texas residents in report BR-0005192; a subset of the overall count and not additive; as of 2026-07-23). [2][4]

A cited record reports 2,523,302 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005192; regulator-reported and not independently verified; as of 2026-07-23). [2][4]

Xsolis said it would mail notice letters to potentially affected individuals for whom it had address information. [4]

Timeline

  1. Activity began

    Date of the targeted phishing attack and start of the Texas regulator-reported access range.

    [4]
  2. Documented activity ended

    End of the unauthorized-access range reported in Texas Attorney General report BR-0005192.

    [2]
  3. Discovery

    Date Xsolis said it became aware of unauthorized activity.

    [4]
  4. Public disclosure

    Publication date embedded in Xsolis’s dedicated incident website.

    [4]
  5. Public disclosure

    Initial Xsolis record date in the California Attorney General incident list.

    [1]
  6. Public disclosure

    Later Xsolis record date in the California Attorney General incident list; modeled as a supplemental notification, not a second incident.

    [1]
  7. Public disclosure

    Publication date of Texas Attorney General report BR-0005192 with revised population figures.

    [2]
  8. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Xsolis attributed the unauthorized activity to a targeted phishing attack on January 20, 2026. [4]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

Xsolis said it contained the activity, investigated with external cybersecurity experts, and reported the incident to law enforcement. Xsolis’s investigation determined that an unauthorized actor acquired certain files from the affected environment. Xsolis offered eligible potentially affected individuals free credit monitoring and identity-protection services. As of its June 5 public notice, Xsolis said it was not aware of actual or attempted misuse of information from the incident. Xsolis said it implemented additional safeguards to enhance information security and help prevent similar incidents. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [4]