LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Xsolis Data Breach Exposes PHI for 1.4 Million via Phishing

CRITICAL severityReportedHow we verify

Xsolis Data Breach Exposes PHI for 1.4 Million via Phishing: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 5, 2026
Xsolis Data Breach Exposes PHI for 1.4 Million via Phishing

Reported June 5, 2026. Approximately 1.4M people affected.

CRITICAL
Severity
1.4M
People affected
4
Data types exposed
June 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Xsolis disclosed a data breach on June 5, 2026, exposing personal information, protected health information, Social Security numbers, and medical records for 1.4 million individuals after a phishing incident. Anyone potentially affected should check the organization’s notice and take steps to protect their data.

Severity & verification
CRITICAL severityReported
Exposes government-ID/medical data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
1.4M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare technology firm Xsolis reported a data breach on June 5, 2026, that exposed personal and protected health information of 1,396,519 individuals. The incident followed a targeted phishing attack in January 2026 that granted unauthorized access to files the company had received from hospital and payer clients. No ransomware was involved and there is no reported evidence of data misuse to date.

Incidents involving healthcare data continue to draw attention because they combine sensitive personal details with information that retains value over time. The scale of this exposure places it among larger breaches disclosed in recent years, underscoring how phishing remains an effective entry point even against organizations that handle regulated information.

What happened

Xsolis disclosed that a phishing campaign in January 2026 succeeded in obtaining access to internal files. Those files contained personal information and protected health information supplied by the firm’s hospital and payer clients. The company stated that 1,396,519 individuals were affected. No claim of ransomware deployment was made, and the organization has not reported any confirmed misuse of the exposed data.

How a breach like this happens

Targeted phishing typically begins with messages crafted to appear as legitimate communications from known contacts or internal systems. When an employee interacts with the message, attackers obtain credentials or install tools that allow further movement inside the network. Once inside, they locate and copy files containing client-supplied data before detection occurs. Organizations that store aggregated records from multiple sources can inadvertently increase the volume of information accessible through a single successful entry point.

Xsolis and its sector

Xsolis operates as a healthcare technology company that works with hospitals and payers. In this role it receives and processes personal and medical information on behalf of those clients. Healthcare technology firms routinely hold records that include identifiers, clinical details, and insurance data because their services depend on integrating information across providers and insurers. A breach at such a firm can therefore affect individuals whose records were never stored directly by the company itself.

The information in question

The disclosure identifies the exposed data as personal information, protected health information, Social Security numbers, and medical records. These categories align with the types of client data the company is known to receive. The exact fields contained in each record have not been itemized beyond these descriptions, so the precise combination of elements for any individual remains unconfirmed.

What's at stake

Individuals whose information appears in the affected files face the possibility of identity theft or fraud that relies on medical or financial identifiers. Healthcare data can also be used for targeted scams or to file false claims. For the organization, the incident adds to regulatory reporting obligations and may prompt reviews of access controls and employee training. Because the data originated from multiple client sources, downstream effects could extend to the hospitals and payers that supplied the records.

If your data was in this claimed breach

People who believe their information may have been involved should review statements or notices issued by Xsolis or their healthcare providers for specific instructions. Standard steps include monitoring financial and insurance accounts for unusual activity, placing fraud alerts with credit bureaus if Social Security numbers may have been exposed, and requesting free credit reports. Individuals can also run a free exposure scan of their email address against known breach datasets to check for appearances in public listings of compromised information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyXsolis security record
68/100
DoxxScan™ · Moderate doxx risk
D+ 59Weak record

1 reported incident on record.

See Xsolis’s full breach history →

More recent breaches

AdaptHealth Patient Data Stolen via Contractor PhishingJune 27, 2026Baylor Genetics Notifies on Cybersecurity IncidentAugust 14, 2026Golden State Orthopedics & Spine Breached by BrainCipherJuly 2, 2026Eagle Crest Communities Hit by SafePay RansomwareJuly 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Xsolis Data Breach Exposes PHI for 1.4 Million via Phishing →

Source: SecurityWeek

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram