Social EngineeringPhishingTargetedCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMINORMediumContained
Xsolis
bd_7311690bbe2b92bd · schema v1 · pii pii-v1
Full breach record for Xsolis →Xsolis, Inc. experienced a targeted phishing attack on January 22, 2026, resulting in unauthorized access to a limited portion of its environment. The incident potentially exposed protected health information (PHI) and personal data of patients, including minors, served by healthcare provider clients. Xsolis contained the incident, engaged forensic experts, notified law enforcement, and implemented security enhancements including password resets and increased monitoring. Identity monitoring services were offered to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_346a5a948fd4d9e0California State AGfiled 2026-06-19(32d gap)Candidate
- bd_fe116170ecddcbebWashington State AGfiled 2026-06-19(32d gap)Verified
- bd_129f6c41c09a9313HHS OCRfiled 2026-06-05(46d gap)Verified
- bd_eda91ee6074a14d1Indiana State AGfiled 2026-06-05(46d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626828
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2026
- Raw hash
- 2ee072d24791bb5dd64a2ee7fbdc4e2d38b11bd00ba7d884c97fbbbdc91b5c66
Reporting entity
- Name
- Dragonfly, by Xsolisnorm: dragonfly by xsolis
- Domain
- dragonfly.xsolis.ai
Victim entity
- Name
- Xsolisnorm: xsolis
- Domain
- xsolis.com
Incident
- Discovered
- Jan 22, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(180 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.