---
title: "Xsolis targeted-phishing data incident"
description: "Evidence-backed account of Xsolis targeted-phishing data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/xsolis-targeted-phishing-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/xsolis-targeted-phishing-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/xsolis-targeted-phishing-data-incident-2026/stix.json"
---

# Xsolis targeted-phishing data incident

Targeted phishing led to unauthorized access to a limited portion of Xsolis's environment from January 20 through January 22, 2026. An unauthorized actor acquired files containing personal identifiers and protected health information provided by Xsolis clients.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Vendor holding client-provided personal and protected health information in the affected environment.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Targeted phishing led to unauthorized access to a limited portion of [Xsolis](https://www.xsolis.com/)'s environment from January 20 through January 22, 2026. [4](#source-4)

## Impact

An unauthorized actor acquired files containing personal identifiers and protected health information provided by Xsolis clients. [2](#source-2) [4](#source-4)

Documented data types include:

- Clinical information — Medical-treatment information; data elements varied by individual. [4](#source-4)
- Contact information — Addresses; data elements varied by individual. [4](#source-4)
- Dates of birth — Dates of birth; data elements varied by individual. [4](#source-4)
- Health insurance information — Health-insurance information; data elements varied by individual. [4](#source-4)
- Names — Names; data elements varied by individual. [4](#source-4)
- Social Security numbers — Social Security numbers; data elements varied by individual. [4](#source-4)

A cited record reports 139,424 individuals (Texas residents in report BR-0005192; a subset of the overall count and not additive; as of 2026-07-23). [2](#source-2) [4](#source-4)

A cited record reports 2,523,302 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005192; regulator-reported and not independently verified; as of 2026-07-23). [2](#source-2) [4](#source-4)

Xsolis said it would mail notice letters to potentially affected individuals for whom it had address information. [4](#source-4)

## Timeline

### January 20, 2026 — Activity began

Date of the targeted phishing attack and start of the Texas regulator-reported access range. [4](#source-4)

### January 22, 2026 — Documented activity ended

End of the unauthorized-access range reported in Texas Attorney General report BR-0005192. [2](#source-2)

### January 22, 2026 — Discovery

Date Xsolis said it became aware of unauthorized activity. [4](#source-4)

### June 5, 2026 — Public disclosure

Publication date embedded in Xsolis's dedicated incident website. [4](#source-4)

### June 19, 2026 — Public disclosure

Initial Xsolis record date in the California Attorney General incident list. [1](#source-1)

### July 21, 2026 — Public disclosure

Later Xsolis record date in the California Attorney General incident list; modeled as a supplemental notification, not a second incident. [1](#source-1)

### July 23, 2026 — Public disclosure

Publication date of Texas Attorney General report BR-0005192 with revised population figures. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Xsolis attributed the unauthorized activity to a targeted phishing attack on January 20, 2026. [4](#source-4)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566 — Phishing](https://attack.mitre.org/techniques/T1566/) [4](#source-4)

## Response

Xsolis said it contained the activity, investigated with external cybersecurity experts, and reported the incident to law enforcement. Xsolis's investigation determined that an unauthorized actor acquired certain files from the affected environment. Xsolis offered eligible potentially affected individuals free credit monitoring and identity-protection services. As of its June 5 public notice, Xsolis said it was not aware of actual or attempted misuse of information from the incident. Xsolis said it implemented additional safeguards to enhance information security and help prevent similar incidents. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/xsolis-targeted-phishing-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-2"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-3"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<a id="source-4"></a>

### Website Notice of Data Security Incident

official · Xsolis, Inc. · Jun 5, 2026

<https://www.xsolisdataincident.com/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis said it contained the activity, investigated with external cybersecurity experts, and reported the incident to law enforcement.
2. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Clinical information
3. **Affected Individual Count · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: 139,424 individual
4. **Used Attack Technique · 90% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: https://attack.mitre.org/techniques/T1566/
5. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis's investigation determined that an unauthorized actor acquired certain files from the affected environment.
6. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis client-provided personal and health-data exposure
7. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Contact information
8. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Dates of birth
9. **Resulted In · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: Xsolis offered eligible potentially affected individuals free credit monitoring and identity-protection services.
10. **Affected Organization · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Xsolis, Inc.
11. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Health insurance information
12. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Names
13. **Disclosed At · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: 2026-06-19
14. **Disclosed At · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: 2026-06-05
15. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis public, individual, and regulator notifications
16. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis attributed the unauthorized activity to a targeted phishing attack on January 20, 2026.
17. **Affected Individual Count · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: 2,523,302 individual
18. **Disclosed At · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: 2026-07-21
19. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: As of its June 5 public notice, Xsolis said it was not aware of actual or attempted misuse of information from the incident.
20. **Affected Organization · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis, Inc.
21. **Ended At · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: 2026-01-22
22. **Disclosed At · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: 2026-07-23
23. **Exposed Data Category · 100% confidence · current**  
   Xsolis client-provided personal and health-data exposure: Social Security numbers
24. **Began At · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: 2026-01-20
25. **Resulted In · 100% confidence · current**  
   Xsolis public, individual, and regulator notifications: Xsolis said it would mail notice letters to potentially affected individuals for whom it had address information.
26. **Resulted In · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: Xsolis said it implemented additional safeguards to enhance information security and help prevent similar incidents.
27. **Discovered At · 100% confidence · current**  
   January 2026 Xsolis targeted-phishing intrusion: 2026-01-22

</details>
