
Frost Bank Data Breach via Third-Party Vendor
Fraud Management & Cybercrime , Ransomware , Video Protect Your Small & Mid-Sized Business From Cyberthreats This Holiday As the holiday season approaches, small businesses face a heightened risk of cyberthreats.
Key points
- Data posted by Everest ransomware group on April 20, 2026.
- Breach originated from a compromised third-party vendor.
- Over 250,000 Social Security numbers and TINs claimed by attackers.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
- Published
- Apr 20, 2026
- Updated
- Jul 22, 2026
- Confidence
- High
- Evidence
- 7 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch phishing, executive impersonation and account-takeover exposure.
- Source type: supplier or third-party involvement
Business impact
- Impact area
- Confidentiality, Availability
- Likely asset
- User or customer data
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?+
Fraud Management & Cybercrime , Ransomware , Video Protect Your Small & Mid-Sized Business From Cyberthreats This Holiday As the holiday season approaches, small businesses face a heightened risk of cyberthreats. In 2023, the eCrime Index saw a 30% spike just before the start of the holiday season. This webinar is designed to equip you with the knowledge and tools needed to help safeguard your business from ransomware, credential theft and other cyber crimes. Join us to learn from our industry experts, Kurt Baker and Dana Larson, about the latest eCrime trends, practical security measures, and best practices for keeping your business and customer data secure. Don’t let cybercriminals ruin your holiday cheer - register now to protect your business during this critical time! Learn about common threats like phishing, ransomware, credential theft, payment-system attacks and consumer-focused scams; Discover actionable next steps you can take to prepare your business for the rise in eCrime; See how dedicated cybersecurity can protect you around the clock during the holiday rush.
When was this signal reported?+
Shadow Tier lists Apr 20, 2026 as the signal date.
Which organization is connected to this signal?+
Frostbank is the organization connected to this public signal.
Explore FrostbankWhich attack pattern is relevant?+
This signal is connected to current ransomware incidents based on its reported incident context.
Explore current ransomware incidentsWhich sector context is relevant?+
This signal is connected to current banking cyber incidents.
Explore current banking cyber incidentsRelated signals
Compare shared topics, actors and incident patterns before opening the full signal.
Singapore Land Authority Data Breach Exposes 70,000 Records via IBM Testing Environment
Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially exposed the personal information of more than 17,000 employees and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the human factor is a growing threat as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank BDO is shoring up its cyber security capabilities to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.
Related context
Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Related context
Alamo Heights ISD Reports Data Breach Following Ransomware Attack
Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.
Related context
Axios npm package compromised in supply chain attack on July 23, 2026
On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.
Related context
Xsolis Data Breach Exposes 1.4 Million Patient Records Across Eight Health Systems
A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes
Related context
Tata Electronics Data Leak Exposes Apple iPhone 18 Pro Details
India probes Tata Electronics breach exposing iPhone secrets India is investigating a data breach at Tata Electronics that reportedly exposed confidential information linked to Apple’s unreleased iPhone 18 Pro, the country’s IT secretary said on Thursday (July 3), marking the government’s first public response to the incident. Sensitive documents, including component lists, supplier details and images of the iPhone 18 Pro, were allegedly posted on the dark web by a ransomware group that targeted Tata Electronics, an Apple supplier in India, Reuters reported. “We are investigating,” said S. Krishnan, secretary at the Ministry of Electronics and Information Technology, adding that the case has been referred to India’s Computer Emergency Response Team, the national cybersecurity agency. The breach raises concerns over Apple’s tightly controlled global supply chain, where production of iPhones relies on multiple international suppliers. Apple is expected to launch the iPhone 18 Pro and Pro Max in September. The leaked files are said to include at least six documents revealing supplier assignments for specific components—information Apple does not publicly disclose. Tata Electronics has reportedly hired a global consultancy firm to carry out a forensic audit following the leak, which also allegedly involved documents related to Tesla, Qualcomm and TSMC being published on the dark web, according to Reuters. (Newswire)
Related context