Compare shared topics, actors and incident patterns before opening the full signal.
Xsolis·Jun 26, 2026Same sectorSame action patternSame impact area
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Yonsei·Jul 21, 2026Same sectorSame action patternSame impact area
On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.
Dystar·Jun 28, 2026Same sectorSame action patternSame impact area
Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks This page displays the 100 most recent victim disclosures attributed to ransomware groups, as detected by Ransomware.live . Our platform continuously monitors and scrapes ransomware group leak sites to identify and list newly published victims. Recent Breaches › dystar.com Listed by settra Ransomware Group dystar.com Listed by settra Ransomware Group: What Was Exposed & What To Do Occurred June 2026 · publicly disclosed June 28, 2026. Dystar.com was listed by the Settra ransomware group on June 28, 2026, with internal files reported exfiltrated in the attack. An undisclosed number of people may be affected; check the listing and monitor your accounts for signs of compromise. The incident was reported on 28 June 2026. dystar.com appears on a listing attributed to the settra ransomware group. The group claims to hold 1.3 terabytes of data described as the complete digital archive of DyStar. No independent confirmation of the volume, the date of access, or the method of entry has been released. The number of people affected remains undisclosed. Settra is a ransomware operator that lists victim organisations on a public site after encrypting systems and copying files. The group’s listings function as a claim that data has been taken and may be released if demands are not met. No additional statements from settra specific to dystar.com have been verified beyond the listing itself. dystar.com belongs to an organisation that operates in the specialty chemicals sector, supplying dyes and related products to industrial clients. Entities of this type routinely maintain records on production processes, customer accounts, supplier arrangements and internal communications. A breach that exposes such material can affect both commercial operations and any personal details contained in those records. The only category named in available reports is internal files exfiltrated during a ransomware attack. The precise contents of the 1.3 terabytes referenced in the listing have not been itemised by the organisation or independently verified. Organisations in this sector commonly store employee records, contractual documents and operational data, yet the exact composition of the material in this case stays unconfirmed. Internal files can contain identifying information, financial references or communications that retain value long after the initial incident. Individuals named in those files may encounter follow-on risks such as targeted fraud or unwanted contact. For the organisation, the exposure of proprietary material can complicate business relationships and regulatory compliance even if the number of personal records remains unknown. Begin by monitoring accounts linked to any email address you have used with dystar.com or its partners. Enable multi-factor authentication on those accounts and review recent login activity. Request a copy of any personal data the organisation holds about you under applicable data-protection rules. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings. Change passwords for any accounts that may share credentials with dystar.com systems. Watch bank and credit statements for unusual activity over the next several months. Contact dystar.com directly to ask what categories of personal information were held and whether they have been notified of the listing. Read GalaxyWarden’s full analysis of the dystar.com Listed by settra Ransomware Group → Publicly posted by settra — unverified claim, pending independent verification Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated a
Lvm·Jun 26, 2026Same sectorSame action pattern
Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor
Originenergy·Jul 28, 2026Same sectorSame action patternSame impact area
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
Gabia·Jul 26, 2026Same action patternSame impact area
South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains. The incident led to the exposure of data belonging to 350,000 users. The compromised information included names, user IDs, passwords, and registration numbers. This breach highlights the significant risks associated with compromised credential reuse, as a large portion of the exposure originated from "Combolist sources." Additionally, active infostealer activity, linked to malware families such as LummaC2, Redline, and Rhadamanthys, was identified, further indicating a focus on credential theft impacting both clients and employees. The incident also revealed 245 compromised employee accounts, posing an infrastructure risk, and 30,782 leaked client credentials, creating regulatory liability. The timeline of related events showed an increase in client-related incidents from August 2025 through April 2026, with a peak in March 2026, and spikes in employee-related events in January, April, and May 2026. Remediation efforts should prioritize credential hygiene, multi-factor authentication enforcement, and enhanced monitoring for suspicious login activity, particularly targeting login forms and account management services. The incident was reported by the Korea Herald on Monday, July 28, 2026.