In April 2026, Xtium, a managed service provider, reportedly suffered a data breach and extortion, as detailed by a dark web post. A threat actor claimed to have breached Xtium's network and accessed Veeam backup instances for approximately eight months. The attacker then allegedly breached the network a second time after initial extortion negotiations failed, and is now selling the stolen data and directly soliciting Xtium's clients.
The alleged breach involved 485.8TB of data. This reportedly included 480TB of client Virtual Machine (VM) backups from a compromised Veeam instance, client file-level restore data, and 5.8TB of internal Xtium and client TeamShares data extracted from Synology ShareSync. The number of affected individuals remains unclear, and there is no public confirmation of specific data types like SSNs, financial data, or medical data being exposed.
Details about the full scope of the breach, including the exact number of individuals affected and states impacted, have not yet been publicly confirmed by Xtium or regulatory bodies. Information about consumer notifications or any regulatory involvement has not been disclosed.