U.S. healthtech vendor Xsolis disclosed that a targeted phishing attack on January 20, 2026 led to unauthorized access that ultimately touched files covering nearly 1.4 million people.
This is the classic health-vendor blast radius: one phished inbox, then files that hold other people’s Social Security numbers and treatment details.
What happened
Per BleepingComputer and Xsolis’s incident site, the company detected unauthorized activity on January 22 tied to phishing two days earlier, contained the activity, and hired outside investigators. Attackers reached certain files in a limited portion of the Xsolis environment—not a claim that every Dragonfly customer database was dumped wholesale.
What data was exposed
Accessed information included names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information. HHS OCR reporting cited by BleepingComputer lists 1,396,519 individuals.
Who is at risk
Patients and members whose data sat in files pulled during the intrusion—often people whose hospitals or insurers use Xsolis for utilization management. If you get a mailed notice (or a parent/guardian notice for a child), treat it as real and enroll in the Kroll monitoring offered.
Action items
- Freeze credit at Equifax, Experian, and TransUnion if your notice lists an SSN.
- Watch Explanation of Benefits and insurer portals for unfamiliar claims.
- Ignore cold calls offering “Xsolis breach remediation”—use the notice packet or xsolisdataincident.com.
- Hospital/payer security teams: confirm which outbound file shares still hold bulk PHI with vendors.
Canonical record
Xsolis phishing breach 2026. Sources: company incident site, BleepingComputer.