← Back to list

48 Hours Was Fast Enough to Steal 1.4 Million Records

Jeff Darrington, Technical Marketing Director, Graylog

Graylog in The Visibility Layer by Graylog · 2026-07-08 18:35 · 0 claps · 4.6 min read
#healthcare #cybersecurity #threat-detection #graylog #identity-theft
Open on Medium ↗
Wiki topics: ECO · Economy · General 🔒 · Cybersecurity 🎬 · Film & Television

48 Hours Was Fast Enough to Steal 1.4 Million Records

Photo by Marek Studzinski on Unsplash

Photo by Marek Studzinski on Unsplash

*Jeff Darrington, Technical Marketing Director, Graylog*

Forty-eight hours is a fast breach detection. Most healthcare organizations would consider that a win.

Xsolis detected unauthorized access two days after a targeted phishing attack on January 20, 2026. They contained it. They called in forensics. They notified regulators. By most incident response standards, that is a competent response.

It was also long enough for an attacker to pull the protected health information of 1,396,519 people across eight hospital systems, including names, Social Security numbers, health insurance details, and medical treatment records. Fast enough to detect. Not fast enough to prevent the damage.

The Same Month, a Very Different Timeline

Xsolis is not an isolated case. As of June 2026, it was the third healthcare technology company to disclose a cyber incident in less than a month, following breaches at iRhythm Technologies and Novo Nordisk.

A cyber-extortion group known as FulcrumSec claimed responsibility for the breach, asserting it had spent more than two months inside Novo Nordisk’s cloud and code infrastructure before exfiltrating what it described as 1.3 terabytes of files, including source code, drug research, clinical trial information, and internal AI models. The group reportedly demanded $25 million and said it was exploring private sales of the data after the company refused to pay.

Two months. One of the world’s largest pharmaceutical companies. Clinical trial data, AI models, proprietary drug research.

Novo Nordisk’s official statement was measured: “certain non-public data, including personal data, was copied externally without authorisation.” The gap between what the company confirmed and what the attackers claimed matters less than the fact both accounts agree on one thing. The detection came after the damage.

Three breaches. Three attacker profiles. Three different entry vectors. One consistent variable: how long the attacker was inside before anyone noticed.

Dwell Time Is the Financial Variable

Healthcare has held the highest average breach cost of any industry for fifteen consecutive years. The current average sits at $9.77 million per incident. That number is not explained by how sophisticated the attacks are. It is explained by how long they last.

The Xsolis breach notification puts the timeline in plain language. A targeted phishing attack on January 20, 2026, gave an unauthorized actor access to a portion of the Xsolis environment. The company identified the activity two days later, contained it, and terminated the access. In that 48-hour window, the attacker acquired files containing names, dates of birth, Social Security numbers, health insurance information, and medical treatment records belonging to 1,396,519 people.

That is the dwell time equation in its starkest form. Forty-eight hours produced 1.4 million patient records across eight hospital systems. Two months inside Novo Nordisk produced 700,000 files by the attacker’s own account. The volume of data that leaves a healthcare environment does not scale with attacker sophistication. It scales with time.

This is why dwell time is the variable that drives breach cost more than any other. The data that gets exfiltrated determines the regulatory scope. The regulatory scope determines the notification burden. The notification burden determines how long OCR is in the room with you. Under HIPAA, the Office for Civil Rights investigates every breach affecting 500 or more individuals. The Xsolis investigation is already open. Detecting a breach in 48 hours and detecting it in two months produce materially different regulatory outcomes. One is a manageable response. The other is a multi-year enforcement proceeding.

What the Logs Would Have Shown

This is the part of healthcare breach postmortems that rarely gets enough airtime.

Both breaches generated detectable behavioral signals before they became undeniable. The entry vector for Novo Nordisk was an unrotated cloud credential authenticating from an unusual source, accessing repositories outside its established scope. That is a behavioral baseline deviation, not a novel threat pattern. An entity with a three-year authentication history that suddenly starts querying systems it has never touched is detectable without prior knowledge of the attacker.

For Xsolis, the phishing compromise gave a threat actor two days inside the network. Accessing files containing records on 1.4 million individuals generates volume anomalies. Outbound data transfer at exfiltration scale deviates from any established baseline. The entity risk model that accumulates these signals onto the compromised account would have been escalating well before the exfiltration was complete.

Asset Risk Scoring

Asset Risk Scoring

The organizations closing the detection maturity gap fastest are not the ones with the biggest platforms. They are the ones with documented workflows and tool infrastructure that tells analysts exactly where they stand and what to build next. Lean teams without that framework are exposed in ways their platforms cannot compensate for.

Healthcare security teams are not failing because the attacks are too sophisticated. They are failing to detect them early enough because the behavioral monitoring infrastructure required to surface credential misuse, access volume anomalies, and pattern deviations is either absent or not configured to generate alerts at the speed required.

The Dwell Time Is Fixable

Three breaches in thirty days. Three different attack paths. One consistent detection architecture gap.

Behavioral anomaly detection that fires on credential baseline deviation. Volume monitoring that surfaces exfiltration-scale transfers before they complete. Entity risk accumulation that converts individually low-confidence signals into a high-confidence investigation trigger. These are not advanced capabilities reserved for large enterprise security teams. They are the detection baseline every organization handling PHI should already be running.

The forensic case for log retention is just as direct. HIPAA requires six years of policy and procedure documentation. Reconstructing the Novo Nordisk breach timeline requires two months of searchable log history. Organizations with 30-day retention policies discovered during investigation that the first portion of attacker activity was unrecoverable. A data lake architecture that retains parsed, normalized logs at cold-tier storage cost makes HIPAA-compliant retention financially viable and forensic reconstruction tractable when OCR comes asking.

The math is not close. A mid-market healthcare SIEM license runs $37,000 to $52,000 per year. At a 15 percent annual breach probability and a $9.77 million average breach cost, the expected annual value of detection improvement exceeds the license cost by a factor of three to five before counting any operational efficiency.

Forty-eight hours was fast enough to steal 1.4 million records. It was not fast enough to stop it. The detection infrastructure that closes that gap is not theoretical. It is a configuration decision that most healthcare organizations have not yet made.

The dwell time gap is fixable. Graylog is built to close it for healthcare.

Follow Graylog on LinkedIn for practical security guidance built for lean teams running healthcare security themselves.


메타데이터
post_id
e4e1ee7254ad
slug
48-hours-was-fast-enough-to-steal-1-4-million-records-e4e1ee7254ad
url
https://medium.com/the-visibility-layer/48-hours-was-fast-enough-to-steal-1-4-million-records-e4e1ee7254ad
canonical_url
https://medium.com/the-visibility-layer/48-hours-was-fast-enough-to-steal-1-4-million-records-e4e1ee7254ad
author_url
https://medium.com/@graylogcorporate
status
ok
fetched_at
2026-07-09 23:31:43