Aesto Health Data Breach Exposes 9.5 Million Records

Aesto Health breach exposes data of 9.5 million via AWS compromise

Aesto Health has suffered a major data breach, with attackers stealing sensitive health and personal data from its AWS cloud infrastructure. The Aesto Health data breach affects 9.5 million individuals, highlighting the growing risks to healthcare data stored in the cloud.

Details of the Aesto Health Data Breach

The Aesto Health data breach was reported in early July 2025. According to Aesto Health, the incident involved unauthorised access to its Amazon Web Services (AWS) environment. Attackers successfully extracted a vast amount of personal and health information, impacting a reported 9.5 million people across the United States.

  • Date of Breach: Disclosed in July 2025, with unauthorised access believed to have occurred in the months prior.
  • Who is Affected: Patients and clients whose data was processed or stored by Aesto Health, including individuals served by healthcare providers using Aesto’s technology services.
  • Type of Data Exposed: Personal information such as names, dates of birth, addresses, and protected health information (PHI). In some cases, data sets may also have included medical histories, insurance details, and contact information.
  • Compromised Infrastructure: The breach was confined to Aesto Health’s AWS environment, where sensitive customer data was hosted.

Aesto Health is a technology provider serving a range of healthcare organisations with cloud-based data solutions. The breach has triggered mandatory notifications to affected individuals and regulatory authorities, as required by healthcare and data protection laws.

How the Attackers Breached AWS Infrastructure

While full technical details have not been disclosed, the incident underscores risks associated with cloud-hosted sensitive data, particularly in healthcare. Attackers are believed to have gained unauthorised access by exploiting weaknesses in cloud security configurations or credentials management within Aesto Health’s AWS environment.

Cloud breaches of this scale often involve one or more of the following methods:

  • Compromised credentials, such as leaked or weak AWS account passwords or keys
  • Misconfigured AWS storage (e.g., S3 buckets left publicly accessible)
  • Inadequate monitoring of cloud activity, delaying breach detection
  • Insufficient network segmentation or access controls within the cloud

Once inside, the attackers accessed and exfiltrated large data sets containing personal and health information. The breach timeline suggests the attackers maintained access for an extended period before detection and containment, increasing the risk that stolen data could be used for identity theft, fraud, or further attacks targeting affected individuals.

Timeline and Response to the Incident

The following timeline summarises key events in the Aesto Health data breach:

  • Early 2025: Initial unauthorised access is believed to have occurred, though the exact date has not been publicly confirmed.
  • June 2025: Suspicious activity detected within Aesto Health’s AWS environment.
  • July 2025: Aesto Health publicly discloses the breach following internal investigation and notifies regulatory bodies.
  • July 2025 onwards: Notifications sent to affected individuals outlining the nature and scope of the data breach, with recommendations for monitoring accounts and credit activity.

As of July 2025, there is no public evidence of the stolen data being leaked online or sold on criminal forums. However, given the value of health and personal data, ongoing monitoring is advised. The breach is under investigation by Aesto Health, law enforcement, and regulatory agencies.

Impact on the Healthcare Sector and Cloud Security

The Aesto Health data breach is significant due to the volume and sensitivity of data exposed. Healthcare organisations increasingly rely on third-party technology providers and cloud platforms such as AWS to store and process patient data. This incident highlights the risks associated with cloud adoption in regulated sectors, especially where large data sets and sensitive information are involved.

Key lessons from the breach include:

  • Even reputable cloud providers can be compromised if security controls are not robustly implemented and maintained
  • Third-party technology vendors represent a supply chain risk that must be assessed and monitored
  • Healthcare data continues to be a prime target for cybercriminals due to its value and potential for misuse

What Organisations Should Do Next

Organisations working with cloud technology providers or handling sensitive health data should:

  • Review their own and third-party providers’ cloud security controls and incident response capabilities
  • Ensure contractual obligations cover breach notification, monitoring and remediation
  • Promptly notify affected individuals if their data is compromised

This breach is a timely reminder of the need for continuous oversight and robust security governance when entrusting sensitive data to cloud platforms and technology partners.

Originally reported by securityweek.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call