[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3lpr9rvm40u09":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"6a4ce5f9a3e9fd3552ce5f47","Xsolis","Xsolis Data Breach","xsolis","xsolis.com","2026-01-20T00:00:00.000Z","2026-07-07T11:41:45.233Z",null,"2026-07-29T09:59:45.149Z","Data breach","https:\u002F\u002Fwww.xsolisdataincident.com\u002F",[16,18,19],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf",2523302,"known","people","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35,36],"Names","Physical addresses","Dates of birth","Social security numbers","Health insurance information","Personal health data","\u003Cp>Xsolis data breach involves Xsolis, Inc., which provides case and utilization management services to healthcare organizations. It is associated with a spear phishing incident that started on January 20, 2026. The institution noticed that there was unauthorized activity in a limited area on January 22, 2026, and announced that it stopped the activity, separated the relevant hosts and user accounts, initiated an investigation with external security experts, and notified law enforcement units. As a result of the investigation, it was determined that the unauthorized person obtained some files and that these files may contain personal and protected health information provided by customers. This record was published with the scope of verified person, as the official health breach record lists the number of affected people as 2,523,302.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In this case, the data fields that may vary depending on the person are name and surname, physical address, date of birth, health insurance information, Social Security number and medical treatment information. This type of combination of data coming through a health technology service provider creates broader risk than classic membership leakage. Social Security number and date of birth can be misused in identity verification processes; Address information can make targeted fraud and fake correspondence more believable. Health insurance and medical treatment information may be used for unrecognized service reporting, fraudulent invoices, insurance abuse or misleading communications conducted on behalf of the patient. The fact that the incident started with spear phishing indicates that users should be more wary of messages coming on behalf of a healthcare provider, insurance plan, or Xsolis customer.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>Verified contact coverage for Xsolis is 2,523,302 individuals. January 20, 2026, when the spearphishing activity began, was used as the incident date; January 22, 2026 is the date when the institution noticed the unauthorized activity, cut off access and started the investigation process. The announcement process for individuals was carried out in June 2026. Data types are not the same for every person; It is not mandatory for a person to have all fields in their record. Therefore, this record is limited to the data fields clearly listed in the official announcement. The internal log volume is not shown as different from the official contact total because an individual leak line volume has not been reliably verified. The Authority stated that it did not know of any evidence of actual misuse of information resulting from this incident at the time of the announcement.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk group includes people who have used the services of hospitals, health systems or payment institutions that are Xsolis customers. The user should also check for notifications from their healthcare provider or insurance provider as there is no single publicly available list of which entities are all affected. Individuals whose Social Security number and date of birth are affected should consider credit file verification, identity verification, and risk of opening new accounts first. Users with health insurance or medical treatment information should regularly review their disclosure documents, patient account and insurance transactions for unrecognized transactions, services, providers or payment requests. The risk of fraudulent notifications via mail, telephone and e-mail also increases for people with address information.\u003C\u002Fp>\u003Ch2>Urgent Measures to be Taken\u003C\u002Fh2>\u003Cp>Users who see a match in this breach should first check which data fields are affected in the official notification letter they receive. If the Social Security number is affected, credit reports should be reviewed, and if an unrecognized credit inquiry or new account application is seen, the appeal process should be initiated quickly. When necessary, credit freezing or fraud warning options should be considered. Users with health insurance and medical treatment information should check the patient portal, insurance disclosure documents and billing transactions. Personal information should not be entered in unexpected connections coming on behalf of the health care provider or insurance institution; The person calling or writing must be verified through known institution channels. Email account and patient portal passwords must be unique, with additional authentication enabled.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Since identity, address and health data are present together in this case, long-term monitoring is required. Users should review their credit reports, insurance disclosure documents, patient accounts, and financial transactions every few months. Health data misuse can sometimes occur not as an immediate financial transaction but as an inaccurate service record, unrecognized payment request, or insurance reimbursement process. For this reason, users should keep the actual healthcare services and billing documents they receive, and should reach the relevant healthcare provider and insurance institution through known communication channels when they receive transactions that they do not recognize. If the same password is used on other accounts, it should be changed. Documents containing identification number, date of birth and health insurance information should be kept securely and should not be shared in unnecessary messages.\u003C\u002Fp>\u003Ch2>Ongoing Monitoring for Affected People\u003C\u002Fh2>\u003Cp>Notice recipients should rely on the data fields stated in their own letters and should not stop at changing a password. If a Social Security number or birth date was affected, review credit reports and new-account applications; if health-insurance or treatment information was involved, monitor insurance explanations, patient accounts, and bills. Unexpected links or requests using the name of a healthcare provider, insurance plan, or Xsolis should be verified through an independent channel, and suspicious activity should be reported promptly to the relevant institution.\u003C\u002Fp>","Xsolis Data Breach (2.5 Million People Affected)","Xsolis Data Breach. 2.5 Million people affected are reported. Reported data: Names, Physical addresses, Dates of birth. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fxsolis.svg",false,{"name":43,"sector":44,"country":45,"website":10,"websiteArchiveUrl":46,"websiteStatus":46,"websiteCheckedAt":13},"Xsolis, Inc.","Healthcare \u002F Utilization Management Technology","United States",""]