Aesto Health Breach Exposes Data of More Than 9.5 Million People 

Aesto Health says a December 2025 cyberattack affected more than 9.5 million people, potentially exposing medical, financial and identity data.

Sep 3, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Aesto Health cyberattack is nearly a year old, but its most consequential detail is only now coming into view: more than 9.5 million people were affected.

Aesto detected unauthorized activity in its AWS infrastructure in December 2025 and later determined that an attacker may have accessed or acquired patient information. The company disclosed the incident publicly on June 24 without revealing its full scope.

Aesto has since reported 9,540,683 affected individuals to the U.S. Department of Health and Human Services, according to BleepingComputer. The company says it has found no evidence of identity theft or financial fraud connected to the incident.

From a December intrusion to a 9.5-million-person breach

The incident began late last year, when Aesto reported that an unauthorized actor gained access to part of its AWS infrastructure.

The company launched an investigation, which continued into the following months. By May 26, 2026, the company had confirmed that patient information may have been accessed during the incident.

Aesto then began notifying its healthcare clients on June 26, before alerting affected individuals on August 21, roughly 8 months after the intrusion was first detected.

The HIPAA Journal currently lists 30 healthcare providers that it is certain were affected by the breach.

Image: Screenshot from the HIPAA Journal

Aesto says impacted users had some, but not necessarily all, of the following potentially accessed by the attackers:

  • full names
  • dates of birth
  • medical information
  • driver’s license numbers
  • financial account numbers only
  • health insurance information
  • individual taxpayer identification numbers
  • other government identification numbers, and Social Security numbers for a limited number of people

Those responsible for the breach remain unknown, and the company has also not revealed how the intrusion occurred.

Advertisement

Cyberattacks are increasingly hitting healthcare providers 

Aesto Health isn’t an isolated case. The healthcare sector has seen several breaches this year alone. Cases from MCBS, Boston Scientific, and DentaQuest all show that some threat actors are focusing on the critical sector.

The incidents differ in scope and attack method, but they underscore why healthcare remains particularly exposed to cyber risk: organizations and their vendors often hold large volumes of identity, financial and medical information that can remain sensitive for years.

That consistency gives healthcare organizations and their vendors something to work on regarding strengthening basic defenses around access, authentication, permissions, and monitoring.

It will not stop every attack, but catching attackers earlier or limiting what a compromised account can reach could reduce both the number of successful breaches and the amount of data exposed when one occurs. 

With incidents repeatedly affecting millions of people at a time, even reducing the blast radius of a successful intrusion could make a meaningful difference.

What affected individuals should do now

If you received a breach notification from Aesto Health, start by checking exactly what information was involved rather than assuming every type of data was exposed. Aesto says the affected data varied by individual, so the notification should help clarify what you need to protect.

  • Take up Aesto’s identity protection offer: Affected individuals are being offered identity-theft protection and credit monitoring. BleepingComputer reports that coverage lasts 24 months, but check your notification letter for the exact services and enrollment deadline.
  • Watch your financial accounts: Look for unfamiliar transactions, new accounts, or other activity you do not recognize. 
  • Consider a credit freeze: If your Social Security number or other government identification information was exposed, a credit freeze can help prevent someone from opening new credit accounts in your name.
  • Be cautious with unexpected messages: Exposed personal and health information can make phishing attempts more convincing, so treat unexpected emails, texts, or calls asking for passwords, payments, or additional personal information with caution.
  • Keep the breach notice: Save Aesto’s notification and any reference number or instructions it contains. You may need them when contacting credit bureaus, law enforcement, financial institutions, or Aesto’s support team.
Advertisement

Because names, government identifiers, financial information, and medical data can remain useful to criminals long after a breach, affected individuals should continue watching for suspicious activity even after any complimentary monitoring period ends. 

Aesto says it has found no evidence of identity theft or financial fraud tied to the incident so far.

More news: CrowdStrike and international law enforcement partners disrupted the Sality botnet after more than 20 years, cutting its operator off from infected systems through a coordinated peer-to-peer sinkholing operation.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.