Aesto Health, a US healthcare data migration and archiving provider, disclosed that an unauthorized actor accessed a limited portion of its Amazon Web Services environment and may have acquired personal information and protected health information for 9,540,683 individuals. The activity occurred between December 2 and December 18, 2025; the company detected unauthorized activity on December 18 and concluded following forensic investigation and document review on May 26, 2026, that data had been exfiltrated during that period.
The breach affects data supplied by at least two dozen healthcare-provider clients across multiple US states, some of which have issued their own notifications to potentially affected patients. Aesto said it notified impacted provider customers and reported the incident to the US Department of Health and Human Services, but it has not identified the threat actor, entry method, affected AWS resource, or volume of stolen data. The company said it has no evidence so far of resulting identity theft or financial fraud.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
Aesto began notifying healthcare-provider clients whose patient information may have been involved; several providers subsequently issued their own notifications.
Aesto Health publicly disclosed the breach involving its AWS infrastructure and potentially exposed healthcare and personal data.
Aesto concluded that an unauthorized actor had accessed and/or acquired protected health information and personally identifiable information in its environment.
Aesto Health detected unauthorized activity affecting a limited portion of its AWS environment, contained the incident, and engaged external cybersecurity specialists to investigate.
An unauthorized actor accessed portions of Aesto Health's AWS environment between December 2 and December 18, 2025, and exfiltrated personal and protected health information.
Reporting identified at least 30 healthcare organizations affected by the Aesto breach, including Together Women’s Health, for which Aesto filed breach notices in Texas and California. This expands the known organizational impact beyond the at-least-two-dozen clients previously reported.
Aesto reported the breach to the U.S. Department of Health and Human Services as affecting 9,540,683 individuals. The incident involved data associated with at least two dozen healthcare-provider clients.
Following detection of the AWS intrusion, Aesto secured the affected data center and notified relevant law-enforcement authorities. It said potentially exposed data could include medical, insurance, financial-account, and government-identification information, including Social Security numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcesecurityweek.com
Open sourceaestohealth.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.