2026 Xsolis — phishing Jan 20; HHS 1,396,519 people (SSNs, health insurance, treatment)
Data compromised
Per company/BleepingComputer: names, addresses, dates of birth, health insurance information, Social Security numbers, medical treatment information. HHS OCR breach report: 1,396,519 individuals.
Technical writeup
Verified company / HHS disclosure — phishing January 20, 2026; detected January 22; public reporting June 23, 2026 (BleepingComputer). Xsolis, a U.S. healthtech vendor whose Dragonfly platform supports utilization management for hundreds of hospitals and insurers, said a targeted phishing attack produced unauthorized activity in a limited portion of its environment. Investigation found accessed files containing customer information including names, addresses, dates of birth, health insurance data, Social Security numbers, and medical treatment information. HHS OCR materials cited by BleepingComputer list 1,396,519 people impacted. Xsolis reported to law enforcement, reset passwords, expanded monitoring and training, and began mailing notices with 12 months of Kroll identity monitoring. BreachHistory indexes 1,396,519 per the HHS-attested count.
Root cause
Targeted phishing attack January 20, 2026 led to unauthorized activity in a limited portion of the Xsolis environment discovered January 22 (company notice)