Summary
- Environment: Vendor holding client-provided personal and protected health information in the affected environment.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
An unauthorized actor acquired files containing personal identifiers and protected health information provided by Xsolis clients. [2][4]
Documented data types include:
- Clinical information — Medical-treatment information; data elements varied by individual. [4]
- Contact information — Addresses; data elements varied by individual. [4]
- Dates of birth — Dates of birth; data elements varied by individual. [4]
- Health insurance information — Health-insurance information; data elements varied by individual. [4]
- Names — Names; data elements varied by individual. [4]
- Social Security numbers — Social Security numbers; data elements varied by individual. [4]
A cited record reports 139,424 individuals (Texas residents in report BR-0005192; a subset of the overall count and not additive; as of 2026-07-23). [2][4]
A cited record reports 2,523,302 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005192; regulator-reported and not independently verified; as of 2026-07-23). [2][4]
Xsolis said it would mail notice letters to potentially affected individuals for whom it had address information. [4]
Timeline
Activity began
Date of the targeted phishing attack and start of the Texas regulator-reported access range.
[4]Documented activity ended
End of the unauthorized-access range reported in Texas Attorney General report BR-0005192.
[2]Discovery
Date Xsolis said it became aware of unauthorized activity.
[4]Public disclosure
Publication date embedded in Xsolis’s dedicated incident website.
[4]Public disclosure
Initial Xsolis record date in the California Attorney General incident list.
[1]Public disclosure
Later Xsolis record date in the California Attorney General incident list; modeled as a supplemental notification, not a second incident.
[1]Public disclosure
Publication date of Texas Attorney General report BR-0005192 with revised population figures.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Xsolis attributed the unauthorized activity to a targeted phishing attack on January 20, 2026. [4]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
Response
Xsolis said it contained the activity, investigated with external cybersecurity experts, and reported the incident to law enforcement. Xsolis’s investigation determined that an unauthorized actor acquired certain files from the affected environment. Xsolis offered eligible potentially affected individuals free credit monitoring and identity-protection services. As of its June 5 public notice, Xsolis said it was not aware of actual or attempted misuse of information from the incident. Xsolis said it implemented additional safeguards to enhance information security and help prevent similar incidents. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [4]
