Aesto Health disclosed a data breach affecting over 9.5 million individuals. The company discovered the unauthorized access to patient information recently.
Aesto LLC, which operates as Aesto Health, revealed that a data breach has exposed personal information belonging to more than 9.5 million patients.
The healthcare company detected the breach and has begun notifying affected individuals. Aesto Health has not yet disclosed full details about what types of personal or medical information were accessed during the incident.
Data breaches affecting healthcare providers have become increasingly common. The healthcare sector remains a frequent target for cybercriminals seeking sensitive patient data, including names, addresses, Social Security numbers, and medical records.
Aesto Health's disclosure comes as healthcare organizations face mounting pressure from regulators and patients to secure sensitive information. Companies are typically required to notify affected individuals and relevant authorities when breaches exceed specific thresholds.
The company has not yet provided information about the scope of exposed data categories, the timeframe during which unauthorized access occurred, or whether the breach has been fully contained.
Patients affected by such breaches often face risks of identity theft and medical fraud. Aesto Health is expected to provide additional details about the incident, recommended security measures for affected individuals, and steps being taken to prevent similar incidents.
The breach adds to a growing list of major healthcare data incidents in recent years, underscoring ongoing cybersecurity challenges in the medical industry.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.
Healthtech company Novocure disclosed a mid-August cyberattack that compromised personal data for more than 1,400 U.S. cancer patients and an undisclosed number of employees.