ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Aesto Health discloses breach after attackers access AWS infrastructure

Aesto Health, a healthcare data management company, has disclosed that it was the victim of a cybersecurity breach after threat actors compromised its infrastructure and gained access to a portion of its Amazon Web Services (AWS) environment.

 

Headquartered in Birmingham, Alabama, Aesto Health is a healthcare technology company that provides solutions for migrating, archiving and accessing healthcare data from legacy electronic health record systems.

 

In a data security notice submitted to the California Attorney General’s Office, Aesto Health disclosed that it detected an unauthorised intrusion into its network on December 18, affecting a limited segment of its Amazon Web Services (AWS) environment. The company promptly initiated an investigation, supported by external cybersecurity specialists, to assess the nature and extent of the breach.

 

It also took steps to secure the affected data center and notified relevant law enforcement authorities about the incident.

 

“After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorised actor,” Aesto said in its data security incident notice.

 

The compromised data included names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. Aesto is yet to share the number of affected individuals.

 

Although the healthcare data management company found no indication that the exposed information had been misused, it urged affected individuals to remain vigilant by regularly reviewing their credit reports, account and benefits statements, and to report any suspicious activity to law enforcement agencies, including local police and the state attorney general.

 

It has also offered complimentary credit monitoring services through Epiq to all affected individuals.

 

At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Aesto. The company also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543