Menu
Browse

Cyber Incident Victim: Aesto Health

Date

Dec 2025

Location

United States of America

Status

Unknown

Updated

2026-08-10 17:38

Timeline
Occurred
Dec 2025
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

A data breach affecting Aesto Health's Amazon Web Services infrastructure exposed personal information including full names, Social Security numbers, driver's license numbers, state identification numbers, and dates of birth. The exposure occurred over a limited timeframe and prompted a national class action law firm to begin investigating potential claims on behalf of individuals whose data may have been compromised.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or about December 18, 2025, Aesto Health reported a data breach affecting a portion of its Amazon Web Services infrastructure. An investigation determined that between December 2, 2025, and December 18, 2025, personal information was accessed and acquired from the company's network. The exposed data included full names, Social Security numbers, driver's license numbers, state identification numbers, and dates of birth. The breach was identified after unauthorized access to the AWS environment was detected. The investigation revealed the timeframe during which the data was compromised. No further details about the attack vector or threat actors were disclosed in the source.

Cyber Incident Image

Individuals who received a data breach notification from Aesto Health were advised that they may face an increased risk of identity theft and fraud. Aesto Health is described as an Alabama-based healthcare technology company that assists medical organizations with managing, transferring, archiving, and connecting patient data. In response to the incident, the national class action law firm Edelson Lechtzin LLP announced an investigation into potential data privacy claims. The firm stated it would provide free case evaluations to individuals whose sensitive personal data may have been compromised. Contact information for the firm was included in the original announcement for those seeking a confidential consultation. The press release noted that the investigation aims to pursue legal remedies on behalf of affected individuals.

Sources
Sources available to members
1 source