Aesto Health
Incident posture
Linked entities
- Victim
- Aesto Health
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Aesto Health reported that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million individuals. The compromised data included names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical and health insurance details, and taxpayer identification numbers. After detecting unauthorized activity, the company contained the incident and launched an investigation that confirmed exfiltration of the data. It notified the U.S. Department of Health and Human Services, which added the incident to its breach portal, and noted that at least two dozen healthcare provider clients across several states were affected, with some choosing to inform the potentially affected people themselves.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Aesto Health, a healthcare technology company headquartered in Birmingham, Alabama, provides secure data migration, electronic health record exchanges, and legacy data archiving services to healthcare providers and medical practices. On December 18, 2025, the company discovered unauthorized activity affecting portions of its Amazon Web Services infrastructure. Upon detection, Aesto Health immediately contained the incident and launched a thorough investigation, enlisting leading cybersecurity experts to determine what personal information might have been involved. The company disclosed the breach in a June 2026 incident notice.
The investigation concluded on May 26, 2026, that hackers had exfiltrated personally identifiable information and protected health information between December 2 and December 18, 2025. The compromised data included names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers. Aesto Health reported to the U.S. Department of Health and Human Services that 9,540,683 individuals were impacted by the breach. The company’s notice indicated that at least two dozen healthcare provider clients across several states were affected by the incident. Some of those clients elected to notify the potentially affected individuals themselves.
HHS added Aesto Health to its data breach portal on the Monday preceding the article’s September 1, 2026 publication date. The breach exposed names, Social Security numbers, driver’s license numbers, other identification numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers for the reported 9,540,683 individuals. At least two dozen Aesto Health healthcare provider clients across several states were affected, with some choosing to notify potentially affected individuals directly. No additional details about the incident were provided in the source articles.
Sources
Sources available to members: 2 sources.