Back Feeds.Feedburner 9.5 Million Impacted by Aesto Health Data Breach
More than 9.5 million people had their personal and health information stolen in a data breach at healthcare technology company Aesto Health.
Based in Birmingham, Alabama, Aesto Health offers secure data migration, electronic health record (EHR) exchanges, and legacy data archiving services to healthcare providers and medical practices.
The data breach, the company said in a June 2026 incident notice , was discovered on December 18, 2025, and involved portions of its Amazon Web Services (AWS) infrastructure.
“Upon detecting the unauthorized activity, we immediately contained the incident and commenced a thorough investigation. As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved,” Aesto Health said.
On May 26, 2026, the company’s investigation determined that hackers exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and 18.
The compromised information includes names, Social Security numbers, driver’s license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.
Aesto Health has notified the US Department of Health and Human Services (HHS) that 9,540,683 individuals are impacted by the data breach. HHS added the company to its data breach portal on Monday.
At least two dozen Aesto Health healthcare provider clients across several states have been affected by the incident, some of which have chosen to notify the potentially affected people themselves.
Related: McKesson Confirms Data Breach as Attacker Deadline Looms
Related: Extortion Group Claims Manchester Airports Group Data Breach
Related: Personal Information Exposed in Apollo Global Data Breach
Related: CareCloud Data Breach Impact Grows to 3.7 Million Individuals
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Extortion Group Claims Manchester Airports Group Data Breach
Berlin Won’t Pay Extortion Group Claiming Data Theft
Critical Isolated-vm Vulnerability Leads to RCE on Host
Rust Supply Chain Attack Linked to North Korean Hackers
Microsoft Patches Exploited Entra ID Vulnerability
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
WatchGuard Patches Critical Vulnerabilities
PaperCut Exploitation Escalates to Active Intrusions
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
McKesson Confirms Data Breach as Attacker Deadline Looms
What the Hugging Face Incident Teaches Security Leaders AI Agent Access
Anthropic Warns Claude Users of Infostealer Malware Infections
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Virtual Event: Attack Surface Management Summit 2026
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover?
In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
