Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: Xerox said its U.S. subsidiary, Xerox Business Solutions U.S. (XBS U.S.), experienced a security incident in late December 2023 after the INC Ransom extortion group published samples of allegedly stolen files. Xerox said it detected and contained the incident, that the event was limited to XBS U.S., and that business operations were not disrupted. However, the company had not publicly established how many people were affected, exactly what records were accessed, or whether systems were encrypted.
What happened to XBS U.S.?
INC Ransom listed XBS U.S. on its extortion website on December 29, 2023. The group claimed it had stolen confidential information and published samples intended to support that claim. The incident was publicly reported on January 2, 2024—not as a new 2026 breach.
Xerox subsequently said that its cybersecurity personnel had detected and contained a security incident involving XBS U.S. Xerox described the affected environment as limited to its U.S. subsidiary and said neither Xerox Corporation nor XBS operations had been affected. Those statements address operational disruption; they do not mean that no confidential or personal information was exposed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
BleepingComputer reported Xerox’s statement and the incident chronology.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What is XBS U.S.?
Xerox Business Solutions provides document-technology and related business services, including printers, copiers, digital printing systems, supplies, consulting, and support. Its systems may therefore contain information about more than Xerox employees. Customer contacts, suppliers, partners, vendors, invoices, purchase orders, and business correspondence could all appear in an affected environment.
What data may have been exposed?
Reports describing the samples published by INC Ransom said they included:
- Email messages and email addresses;
- Payment-related information;
- Invoices;
- Completed request forms; and
- Purchase orders and other business correspondence.
These are categories reportedly seen in published samples, not a confirmed inventory of every compromised record. Xerox’s preliminary investigation indicated that a limited amount of personal information may have been exposed, but the available reporting did not establish which specific identifiers were involved.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteThe Peruvian National Center for Digital Security alert also described the reported sample contents and INC Ransom’s listing.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Was Xerox itself breached?
The most accurate answer is that Xerox confirmed a security incident at XBS U.S., a Xerox subsidiary. That is narrower than saying the entire Xerox Corporation network was breached.
- Parent company: Xerox Corporation.
- Affected entity identified publicly: Xerox Business Solutions U.S.
- Operational impact: Xerox said Xerox and XBS operations were not affected.
- Information risk: Xerox said its preliminary review indicated limited personal information exposure.
There is no basis in the available reporting for claiming that every Xerox system was accessed or that all XBS data was stolen.
Was this a ransomware attack?
INC Ransom is a ransomware-related extortion group, and the incident involved an extortion-site listing and alleged data theft. “Ransomware attack” is therefore a reasonable shorthand when properly attributed. But the public account does not establish that XBS systems were encrypted, that operations were held hostage, or that Xerox paid a ransom.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesA more precise description is a cybersecurity incident linked to INC Ransom involving alleged unauthorized access and data theft. In a typical double-extortion operation, attackers steal files and threaten to publish them, whether or not they also encrypt the victim’s systems.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What remains unknown?
The available public account did not establish:
- The number of affected individuals or customers;
- The volume of data taken;
- The exact records accessed;
- Whether Social Security numbers, bank-account numbers, payment-card data, passwords, or medical information were involved;
- How the attackers initially gained access;
- Whether any systems were encrypted;
- Whether a ransom was demanded or paid;
- Whether Xerox’s wider corporate network was accessed; or
- Whether the published samples represented the complete stolen dataset.
INC Ransom’s files were published as part of a criminal extortion effort. Their publication supports the existence of an alleged data-theft claim, but it does not independently prove that every displayed file is authentic or that the group accessed everything it claimed.
What did Xerox say it was doing?
Xerox said it was working with outside cybersecurity experts, investigating the incident, and taking additional steps to secure the XBS information-technology environment. It also said it would notify individuals confirmed to have been affected.
Detection and containment are important, but they do not by themselves show that the investigation, remediation, notification process, or legal obligations were complete.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Who could be affected?
Potentially relevant groups include XBS employees, customers, suppliers, business partners, vendors, and other contacts whose information appeared in invoices, purchase orders, email messages, forms, or payment records. A person could therefore be at risk even if they never personally bought a Xerox printer or copier.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The risk depends on the actual fields exposed. An email address or invoice presents a different risk from a password, government identifier, or complete bank-account record. “Limited personal information” is Xerox’s characterization and cannot be converted into a precise risk assessment without knowing the affected data.
What should potentially affected people do?
- Watch for targeted phishing. Be cautious with messages mentioning Xerox, XBS, purchase orders, invoices, account balances, or service contracts. A criminal may use genuine business details to make a fraudulent message look credible.
- Verify payment changes independently. Confirm new bank details, payment instructions, or requests to change a vendor account using a known telephone number or trusted contact. Do not rely on the phone number, link, or reply address in the unexpected message.
- Change reused passwords. If you reused a password for an account connected to XBS dealings, replace it with a unique password. Enable multifactor authentication wherever it is available.
- Review relevant financial activity. If you handled payments or payment-related records with XBS, check bank and payment accounts for unusual activity and report suspicious transactions promptly.
- Keep official notices. Preserve any letter or email from Xerox or XBS and follow its instructions. A legitimate notification may arrive well after the original incident.
Do not assume that everyone connected with XBS needs a credit freeze or paid identity-monitoring service. Those steps may be appropriate if a later notice confirms exposure of government identifiers or other high-risk data, but the available reporting does not establish that those fields were involved.
The financial takeaway
This was not publicly described as a new 2026 Xerox-wide breach. It was a late-December 2023 incident involving XBS U.S. that became public after INC Ransom posted alleged stolen-data samples. Xerox said the event was detected and contained and did not disrupt operations, while also acknowledging that limited personal information may have been exposed.
For readers, the practical concern is not an assumed mass identity-theft event. It is the possibility of targeted fraud using business emails, invoices, purchase orders, or payment-related details. Treat unexpected payment requests and account messages as untrusted until independently verified, and rely on an official Xerox or XBS notification for any confirmed information about your records.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

