1.4 Million Affected by Phishing Attack on Healthcare Firm Xsolis

www.news4hackers.com-1-4-million-affected-by-phishing-attack-on-healthcare-firm-xsolis-1-4-million-affected-by-phishing-attack-on-healthcare-firm-xsolis

Phishing attack on healthcare firm Xsolis impacts 1.4 million people

Healthcare technology provider Xsolis disclosed that a targeted spear-phishing campaign led to unauthorized network access. The organization specializes in AI-driven solutions for medical institutions, including hospitals, health systems, and insurance providers, serving over 600 healthcare entities.

On January 22, 2026, the company identified anomalous activity linked to a phishing incident that occurred on January 20, 2026. Xsolis immediately initiated containment protocols and engaged external cybersecurity specialists to investigate.

The review revealed that threat actors obtained specific files containing sensitive data, which could include personal identifiers such as names, addresses, birth dates, health insurance details, Social Security numbers, and medical records.

A report submitted to the U.S. Department of Health and Human Services confirmed the breach affected 1,396,519 individuals. The company has informed law enforcement, enhanced security protocols, and begun direct communication with affected parties via postal notification.

A dedicated helpline has been established to address inquiries, provide complimentary credit monitoring, and offer identity protection services to those impacted. While describing the breach as confined, Xsolis advised affected individuals to monitor for signs of identity fraud.

No group has publicly asserted responsibility for the attack. This incident marks the third healthcare technology firm to report a cyber incident within a 30-day period, following similar breaches at iRhythm Technologies and Novo Nordisk.



About Author

en_USEnglish