HackMyIP
← Back to News
2026-09-02 The Record

Aesto Breach Exposes 9.5M Healthcare Records in AWS Attack

Data BreachCloud SecurityPrivacy

Healthcare data migration firm Aesto disclosed to federal regulators this week that more than 9.5 million individuals had sensitive personal and medical information stolen during a cyberattack on its Amazon Web Services infrastructure. The Birmingham, Alabama-based company reported the breach to the Department of Health and Human Services, revealing that stolen data includes names, Social Security numbers, medical records, driver's license numbers, financial account numbers, and health insurance information. The exposure of Social Security numbers and financial data makes this incident particularly severe for affected patients, who should immediately verify whether their credentials appear in known compromises using an email breach checker and update any associated passwords through a secure password checker.

The breach occurred between December 2 and December 18, when threat actors gained unauthorized access to Aesto's cloud environment and exfiltrated troves of patient data belonging to the company's healthcare clients. Aesto, which provides data migration and archiving services to medical facilities transitioning electronic health record systems, initially warned customers about the incident in June but did not specify the scope until notifying HHS. At least 30 healthcare organizations were affected, including Together Women's Health in Texas and California, with Aesto filing breach notices on behalf of multiple clients. No ransomware group or threat actor has publicly claimed responsibility for the attack.

The Aesto incident is part of a broader wave of healthcare cyberattacks in 2024. Baylor Genetics disclosed a separate breach affecting 2.8 million people, while electronic health records vendor CareCloud reported a March incident impacting 3.7 million individuals. Additional healthcare companies including McKesson, Nutex, and Paylogix announced cyberattacks in recent weeks involving patient and customer data. Park Dental Partners also reported an attack to the SEC, citing possible access to patient data as the reason for public disclosure. Organizations handling protected health information should conduct regular privacy checkups and review their cloud security posture to mitigate similar risks.

Healthcare data remains a prime target for threat actors due to the richness of personal information stored in electronic health records, which can fuel identity theft, insurance fraud, and targeted phishing campaigns. The reliance on third-party service providers like Aesto also introduces supply chain risk, as a single vendor compromise can cascade across dozens of healthcare clients simultaneously. Security experts recommend that affected individuals monitor financial accounts, place fraud alerts with credit bureaus, and remain vigilant against phishing attempts leveraging stolen medical and personal data.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →