← Back to Tech & Science

Hackers steal data of 9.5 million in breach at Aesto Health

Tech & ScienceAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

BIRMINGHAM, Ala. — Aesto Health has confirmed additional reports corroborating the scope of the data breach affecting more than 9.5 million individuals. The company stated that further evidence supports the initial findings regarding the unauthorized access to personal and health information. These new details reinforce the severity of the intrusion discovered on Sept. 1, 2026, which remains one of the most significant compromises in the healthcare technology sector this year. While the specific nature of the additional reports was not disclosed, their emergence validates the timeline and impact previously outlined by the firm. Aesto Health continues to investigate the full extent of the incident as it works to secure its systems and notify affected parties. The confirmation of these corroborating elements marks a critical step in understanding the breach's reach and ensuring appropriate remediation measures are implemented across all impacted patient records.

Original Report —

BIRMINGHAM, Ala. — More than 9.5 million individuals had their personal and health information stolen in a significant data breach affecting healthcare technology company Aesto Health, the firm announced Monday. The incident, triggered by unauthorized activity from hackers, marks one of the largest compromises of patient records in the sector this year.

Aesto Health confirmed that the intrusion occurred over an unspecified period leading up to the discovery on Sept. 1, 2026. The company stated that attackers gained access to its systems and exfiltrated sensitive data belonging to patients across the United States. While the specific methods used by the cybercriminals have not been detailed, Aesto Health described the event as a targeted breach involving unauthorized access to internal databases.

The compromised information includes names, dates of birth, Social Security numbers, addresses, and medical history for the affected individuals. In some cases, insurance policy details and billing records were also accessed. The scale of the breach impacts patients who have utilized Aesto Health's digital platforms for telehealth services, appointment scheduling, and electronic health record management over the last several years.

Aesto Health immediately engaged cybersecurity experts to investigate the scope of the intrusion and secure its networks. The company has notified federal authorities and is cooperating with law enforcement agencies in Birmingham and at the national level. As part of its response, Aesto Health is offering free credit monitoring and identity theft protection services to all affected individuals for a period of 24 months.

The breach has raised concerns among healthcare advocates regarding the vulnerability of digital health infrastructure. Patients are being urged to monitor their financial statements and credit reports for signs of fraudulent activity. Those who suspect their identities have been compromised are advised to contact the Federal Trade Commission and consider placing fraud alerts on their credit files.

Aesto Health stated that it is reviewing its security protocols to prevent future incidents, though no specific timeline for these upgrades was provided. The company emphasized its commitment to protecting patient privacy but acknowledged the severity of the exposure. No ransom demand has been publicly reported in connection with the breach.

Questions remain regarding the full extent of the data loss and whether additional records may have been accessed before the intrusion was detected. Investigators are working to determine if the stolen information has already appeared on dark web marketplaces or if it remains in the possession of the attackers. Aesto Health expects to provide further updates as more details emerge from the ongoing investigation.

Discussion

0 / 2000