Threat reportData BreachTL-2026-1023

Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals

highACTIVE

Xsolis Data Breach (TL-2026-1023), also tracked as Xsolis Phishing Breach 2026, is a high-severity data breach, first published 2026-07-01. It has no confirmed attribution, affects Xsolis Xsolis Utilization Management / Clinical Decision Support, maps to 18 MITRE ATT&CK techniques (T1005, T1020, T1071), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-1023

Threat ID
TL-2026-1023
Also known as
Xsolis Phishing Breach 2026, Xsolis PHI Exposure
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
health, health insurance, healthcare technology business associates
Target regions
united states of america, North America
Detection rules
9
Indicators of compromise
18

Malware and tooling in Xsolis Data Breach

Malware and tooling: Xsolis Dragonfly platform

How Xsolis Data Breach works

Tennessee-based healthcare AI vendor Xsolis, which provides utilization-management and revenue-cycle software to 600+ hospitals and health insurers, suffered unauthorized network access from a targeted phishing attack on January 20, 2026, discovered January 22, 2026. The breach exposed names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment data for 1,396,519 individuals, with public/HHS disclosure delayed until June 2026.

Xsolis, a Tennessee-based healthcare technology company that develops AI-powered utilization management and clinical decision-support software used by more than 600 hospitals, health systems, and health insurers (including client relationships with organizations such as VHC Health in the Northern Virginia/Washington D.C. metro area and Rochester Regional Health in New York), suffered a targeted phishing attack on January 20, 2026. An unauthorized third party gained access to a limited portion of the Xsolis environment and remained present until the intrusion was detected on January 22, 2026. Xsolis engaged external cybersecurity specialists and law enforcement, contained the incident, and reviewed the affected files to determine that attackers acquired data including patient names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information belonging to 1,396,519 individuals — data that was received from Xsolis's healthcare-provider and payer clients in its capacity as a HIPAA business associate.

Notably, Xsolis did not report the breach to HHS Office for Civil Rights until June 5, 2026 — approximately 135 days after discovery, exceeding HIPAA's Breach Notification Rule requirement that business associates notify covered entities without unreasonable delay (generally within 60 days). Public disclosure followed via a company data security notice in early June and press coverage on June 23-24, 2026, with the incident subsequently added to the HHS OCR public breach-report tracker.

Xsolis's remediation included immediate containment and termination of unauthorized access, password resets across all user and key accounts, expanded system/network monitoring, deployment of new protective technologies, acceleration of employee security-awareness training, and strengthening of credential-management processes. Affected individuals are being offered 12 months of complimentary credit monitoring and identity-theft protection services through Kroll. As of disclosure, Xsolis reported no evidence of attempted or actual misuse of the exposed data, no ransomware group publicly claimed responsibility, and the company did not confirm whether an extortion demand was made or paid. This incident is the third healthcare-sector data breach disclosed within roughly a month (following breaches at iRhythm Technologies and Novo Nordisk), reflecting a continuing trend of attackers targeting healthcare technology vendors and business associates — who aggregate PHI/PII across many downstream provider and payer clients — as a high-leverage single point of compromise via social-engineering/phishing rather than technical exploitation.

MITRE ATT&CK techniques used in TL-2026-1023

Collection

T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1566 Phishing

Persistence

T1078 Valid Accounts

Privilege Escalation

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1083 File and Directory Discovery; T1087 Account Discovery

Execution

T1204 User Execution

Impact

T1531 Account Access Removal

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Affected products and versions in Xsolis Data Breach

  • Xsolis — Xsolis Utilization Management / Clinical Decision Support Platform (corporate network / email environment)
    Vulnerable versions: Production environment as of January 2026

Remediation for Xsolis Data Breach

Immediate actions

  • Reset credentials for all users and privileged/key accounts across the affected environment
  • Terminate unauthorized access and isolate compromised accounts/endpoints
  • Engage external incident response and forensics specialists
  • Report incident to federal law enforcement
  • Notify affected individuals and offer credit monitoring / identity theft protection (Kroll, 12 months)

Workarounds

  • Enforce conditional access / geofencing on webmail and VPN portals pending MFA rollout
  • Increase email gateway sensitivity for credential-phishing indicators targeting healthcare-sector staff

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/hardware tokens) for all remote and email access
  • Expand continuous system and network monitoring / EDR coverage
  • Accelerate and recur security-awareness and phishing-simulation training for all employees
  • Strengthen credential management and privileged access governance
  • Implement DLP and egress monitoring for bulk PHI file access/exfiltration
  • Review and tighten business-associate data minimization and retention practices for downstream client PHI

Weaknesses (CWE) in Xsolis Data Breach

CWE-1173, CWE-287, CWE-522

Timeline of Xsolis Data Breach

  • Targeted phishing attack executed against Xsolis, granting an unauthorized third party access to a limited portion of the Xsolis network environment.
  • Xsolis establishes a toll-free support center for affected individuals and confirms no evidence of unauthorized access to the environment after this date.
  • Forensic investigation launched to determine scope of accessed files and affected individuals; no evidence of unauthorized access found after this date.
  • Xsolis detects unauthorized network activity, terminates unauthorized access, and begins containment; engages external cybersecurity specialists and law enforcement.
  • Xsolis submits breach report to U.S. Department of Health and Human Services Office for Civil Rights, roughly 135 days after discovery — exceeding HIPAA's Breach Notification Rule 60-day expectation for business associates.
  • Xsolis files a sample data breach notification letter with the California Attorney General's Office, disclosing the incident to state regulators in addition to HHS OCR.
  • Xsolis publishes a data security notice disclosing the breach and begins notifying affected individuals with an offer of 12 months of Kroll credit monitoring and identity-theft protection.
  • Plaintiffs' law firms (e.g., ClassAction.org) announce investigations into potential class-action litigation on behalf of affected individuals.
  • Breach widely reported by security and healthcare trade media (Help Net Security, HIPAA Journal, SecurityWeek, BleepingComputer, SecurityAffairs, TechTarget, Cybernews) citing the HHS OCR breach tracker figure of 1,396,519 affected individuals.

Sources cited for Xsolis Data Breach

Detection coverage for TL-2026-1023

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1023 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats