CSIDB logo
Incident

Aesto Health

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 14:29

Linked entities

Victim
Aesto Health
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Dec 2025
Discovered
Dec 2025
Disclosed
Jun 2026
Resolved
Pending

Summary

Aesto Health reported that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million individuals. The compromised data included names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical and health insurance details, and taxpayer identification numbers. After detecting unauthorized activity, the company contained the incident and launched an investigation that confirmed exfiltration of the data. It notified the U.S. Department of Health and Human Services, which added the incident to its breach portal, and noted that at least two dozen healthcare provider clients across several states were affected, with some choosing to inform the potentially affected people themselves.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Aesto Health, a healthcare technology company headquartered in Birmingham, Alabama, provides secure data migration, electronic health record exchanges, and legacy data archiving services to healthcare providers and medical practices. On December 18, 2025, the company discovered unauthorized activity affecting portions of its Amazon Web Services infrastructure. Upon detection, Aesto Health immediately contained the incident and launched a thorough investigation, enlisting leading cybersecurity experts to determine what personal information might have been involved. The company disclosed the breach in a June 2026 incident notice.

The investigation concluded on May 26, 2026, that hackers had exfiltrated personally identifiable information and protected health information between December 2 and December 18, 2025. The compromised data included names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers. Aesto Health reported to the U.S. Department of Health and Human Services that 9,540,683 individuals were impacted by the breach. The company’s notice indicated that at least two dozen healthcare provider clients across several states were affected by the incident. Some of those clients elected to notify the potentially affected individuals themselves.

HHS added Aesto Health to its data breach portal on the Monday preceding the article’s September 1, 2026 publication date. The breach exposed names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers for the reported 9,540,683 individuals. At least two dozen Aesto Health healthcare provider clients across several states were affected, with some choosing to notify potentially affected individuals directly. No additional details about the incident were provided in the source articles.

Sources

Sources available to members: 2 sources.

CSIDB