The Aesto Health cyberattack is nearly a year old, but its most consequential detail is only now coming into view: more than 9.5 million people were affected.
Aesto detected unauthorized activity in its AWS infrastructure in December 2025 and later determined that an attacker may have accessed or acquired patient information. The company disclosed the incident publicly on June 24 without revealing its full scope.
Aesto has since reported 9,540,683 affected individuals to the U.S. Department of Health and Human Services, according to BleepingComputer. The company says it has found no evidence of identity theft or financial fraud connected to the incident.
From a December intrusion to a 9.5-million-person breach
The incident began late last year, when Aesto reported that an unauthorized actor gained access to part of its AWS infrastructure.
The company launched an investigation, which continued into the following months. By May 26, 2026, the company had confirmed that patient information may have been accessed during the incident.
Aesto then began notifying its healthcare clients on June 26, before alerting affected individuals on August 21, roughly 8 months after the intrusion was first detected.
The HIPAA Journal currently lists 30 healthcare providers that it is certain were affected by the breach.

Image: Screenshot from the HIPAA Journal
Aesto says impacted users had some, but not necessarily all, of the following potentially accessed by the attackers:
- full names
- dates of birth
- medical information
- driver’s license numbers
- financial account numbers only
- health insurance information
- individual taxpayer identification numbers
- other government identification numbers, and Social Security numbers for a limited number of people
Those responsible for the breach remain unknown, and the company has also not revealed how the intrusion occurred.
Cyberattacks are increasingly hitting healthcare providers
Aesto Health isn’t an isolated case. The healthcare sector has seen several breaches this year alone. Cases from MCBS, Boston Scientific, and DentaQuest all show that some threat actors are focusing on the critical sector.
The incidents differ in scope and attack method, but they underscore why healthcare remains particularly exposed to cyber risk: organizations and their vendors often hold large volumes of identity, financial and medical information that can remain sensitive for years.
That consistency gives healthcare organizations and their vendors something to work on regarding strengthening basic defenses around access, authentication, permissions, and monitoring.
It will not stop every attack, but catching attackers earlier or limiting what a compromised account can reach could reduce both the number of successful breaches and the amount of data exposed when one occurs.
With incidents repeatedly affecting millions of people at a time, even reducing the blast radius of a successful intrusion could make a meaningful difference.
What affected individuals should do now
If you received a breach notification from Aesto Health, start by checking exactly what information was involved rather than assuming every type of data was exposed. Aesto says the affected data varied by individual, so the notification should help clarify what you need to protect.
- Take up Aesto’s identity protection offer: Affected individuals are being offered identity-theft protection and credit monitoring. BleepingComputer reports that coverage lasts 24 months, but check your notification letter for the exact services and enrollment deadline.
- Watch your financial accounts: Look for unfamiliar transactions, new accounts, or other activity you do not recognize.
- Consider a credit freeze: If your Social Security number or other government identification information was exposed, a credit freeze can help prevent someone from opening new credit accounts in your name.
- Be cautious with unexpected messages: Exposed personal and health information can make phishing attempts more convincing, so treat unexpected emails, texts, or calls asking for passwords, payments, or additional personal information with caution.
- Keep the breach notice: Save Aesto’s notification and any reference number or instructions it contains. You may need them when contacting credit bureaus, law enforcement, financial institutions, or Aesto’s support team.
Because names, government identifiers, financial information, and medical data can remain useful to criminals long after a breach, affected individuals should continue watching for suspicious activity even after any complimentary monitoring period ends.
Aesto says it has found no evidence of identity theft or financial fraud tied to the incident so far.
More news: CrowdStrike and international law enforcement partners disrupted the Sality botnet after more than 20 years, cutting its operator off from infected systems through a coordinated peer-to-peer sinkholing operation.





