LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Xsolis Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

Xsolis Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 19, 2026
Xsolis Data Breach Notice (Washington Attorney General)

Occurred January 20, 2026 · publicly disclosed June 19, 2026. Approximately 26203 people affected.

CRITICAL
Severity
26203
People affected
6
Data types exposed
June 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Xsolis disclosed a data breach on June 19, 2026, affecting 26,203 individuals. The breach occurred on January 20, 2026, exposing names, Social Security numbers, full dates of birth, health insurance policy or ID numbers, and medical information; affected individuals should verify their status and take protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
26203 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In early 2026, tens of thousands of people learned that personal and medical details tied to their care may have been exposed in a cybersecurity incident involving Xsolis. For anyone whose name, Social Security number, date of birth, insurance identifiers, or protected health information was among the records involved, the practical stakes are concrete: the combination of identity data and health-related details can support identity theft, insurance fraud, and unwanted contact long after the technical event itself ends.

According to a notice filed with the Washington State Attorney General and reported on June 19, 2026, Xsolis notified Washington residents that a data breach had occurred. The filing states that the incident itself took place on January 20, 2026, and that 26,203 people were affected. The notice lists name, Social Security number, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity among the categories of information exposed.

Inside the incident

Public detail available from the Washington Attorney General filing is limited to the core timeline and the categories of data named in the notice. Xsolis reported that the incident occurred on January 20, 2026. The organization later notified affected Washington residents, with the filing dated June 19, 2026. The notice identifies 26,203 people as affected and enumerates the data types listed above.

The filing does not describe the technical method of intrusion, whether systems were encrypted or exfiltrated, how long unauthorized access lasted, or whether a ransom demand was involved. No threat actor is named in the disclosed materials. Beyond the date of the incident, the count of people affected, the listed data categories, and the fact of notification to Washington residents, further operational detail remains undisclosed in the public summary.

How a breach like this happens

Incidents that expose mixed identity and health data often follow familiar patterns, though none of these should be read as a confirmed description of this specific event. Attackers commonly gain an initial foothold through stolen or guessed credentials, phishing messages that trick an employee into revealing access, unpatched remote-access software, or compromised vendor connections. Once inside a network, they may move laterally, locate databases or document stores that hold patient or member files, and copy large volumes of records.

In healthcare-adjacent environments, systems frequently hold both administrative identifiers and clinical or insurance details because those fields are needed for utilization review, billing support, or care coordination. When those repositories are reached without adequate segmentation or monitoring, the result can be a bulk exposure of exactly the kinds of fields named in many breach notices. Detection sometimes lags weeks or months, which is one reason notification filings can appear well after the stated incident date. None of this general background attributes a particular technique or group to the Xsolis matter; the public filing simply does not say how the January 20, 2026 incident unfolded.

Xsolis and its sector

Xsolis operates in the healthcare technology and utilization-management space, work that typically involves analyzing clinical and administrative information on behalf of providers, payers, or related entities. Organizations in this sector routinely process names, dates of birth, insurance identifiers, and protected health information because those data elements are central to determining medical necessity, coordinating benefits, and supporting care decisions.

A breach affecting such a firm is consequential precisely because the data is sensitive by design. Protected health information is regulated under HIPAA when held by covered entities or their business associates, and the combination of identity documents with medical and insurance details raises the risk profile beyond a simple contact-list leak. The Washington notice’s explicit reference to protected health information owned or licensed by a HIPAA covered entity underscores that the exposed material sat in a regulated healthcare context, even though the filing does not expand on Xsolis’s exact contractual role in each case.

What was likely exposed

The Washington Attorney General filing names the following categories as exposed: name, Social Security number, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. Those are the only data types confirmed in the disclosed notice.

Organizations that perform healthcare analytics or utilization work commonly also hold addresses, claim numbers, provider names, or clinical notes in the ordinary course of business, but the public filing does not confirm whether any additional fields were involved here. Readers should treat only the listed categories as established; anything beyond that remains unconfirmed.

The real-world impact

For affected individuals, the main risks are identity theft and misuse of health or insurance information. A Social Security number paired with full date of birth and name can be used to open credit accounts, file fraudulent tax returns, or impersonate someone with government agencies. Health insurance policy or ID numbers and medical information can support false claims, attempts to obtain prescriptions or services under another person’s coverage, or targeted scams that reference real medical details to appear legitimate. These harms may surface months later, so ongoing monitoring matters more than a single moment of panic.

For the organization, consequences typically include regulatory scrutiny, notification and credit-monitoring costs, potential contractual disputes with covered entities, and reputational damage among clients who entrusted it with regulated data. The filing itself does not assign fault or describe security controls that failed; it simply records that an incident occurred and that specified data types were involved for 26,203 people.

Were you affected?

If you received a notice from Xsolis or believe you may be among the 26,203 people referenced in the Washington filing, take measured steps. Review any official letter for enrollment instructions on credit monitoring or identity-protection services if they are offered. Consider placing a fraud alert or credit freeze with the major credit bureaus, and watch explanation-of-benefits statements and insurance accounts for unfamiliar claims. File your taxes early if a Social Security number was involved, and be skeptical of unsolicited calls or messages that cite your medical history.

You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets elsewhere. Keep records of any notices you receive, and report confirmed identity theft to the Federal Trade Commission and local law enforcement as needed. Public detail on this incident remains limited to the Washington Attorney General filing; treat unofficial claims with caution and rely on communications that come directly from Xsolis or regulators.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyXsolis security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See Xsolis’s full breach history →
RelatedMore incidents at Xsolis

More recent breaches

Cornerstone Staffing Solutions, Inc. Data Breach Notice (Washington Attorney General)September 11, 2026zHealth, Inc. Data Breach Notice (Washington Attorney General)September 11, 2026Quatrro Business Support Services, Inc. Data Breach Notice (Washington Attorney General)September 9, 2026Hibbett Retail, Inc. Data Breach Notice (Washington Attorney General)September 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Xsolis Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram