THE TELL

You never heard of Aesto. It was holding your Social Security number anyway

A company most patients have never heard of told US health regulators this week that more than 9.5 million people had their data leaked. Not a hospital. The firm that moves the files between hospitals.

A healthcare data company called Aesto, based in Birmingham, Alabama, informed federal regulators this week that more than 9.5 million people had sensitive information leaked in a cyberattack last December. Almost none of those people ever chose to deal with Aesto, or knew it existed.

Here is what Aesto actually does: it moves and archives medical records for facilities that are upgrading their technology, switching electronic health record vendors, or being bought by another company. Your file gets copied to a contractor whose name was never on the form you signed. According to the company's June statement, hackers were inside its Amazon Web Services infrastructure between December 2 and December 18, taking information about the patients of its customers. Aesto warned those customers in June. What it had not shared until this week was the scope.

What it means

The list of what was taken is the reason this one matters: names, Social Security numbers, medical information, driver's license numbers, financial account numbers, health insurance data and more. That is not a password leak. That is a complete identity, plus a diagnosis attached to it.

A credit card can be reissued in a week. A Social Security number and a medical history cannot.
Share this

And the shape of the breach explains why these numbers keep getting so large. At least 30 healthcare organizations were affected by this single incident, and Aesto filed breach notices in several states on behalf of its customers. One break-in at one back-office vendor reached through 30 front doors at once. That is the whole business model working exactly as designed, in reverse.

It isn't a one-off. Baylor Genetics also told federal regulators this week that more than 2.8 million people had medical testing information and laboratory results stolen in a June incident. Another 3.7 million were hit by a March incident at electronic health records company CareCloud. McKesson, Nutex and Paylogix all announced attacks involving patient and customer data over the last two weeks. Park Dental Partners told the SEC on Tuesday night about an attack last week, reporting it because of "the possible access of patient data."

Who it matters to

Two groups, and neither of them did anything wrong. First: anyone whose clinic changed its record system or got bought by a bigger group — that's when your chart gets handed to a company like Aesto. You were never asked. Second, and this is the one people underestimate: everyone in their twenties and thirties who is about to apply for a first apartment, a car loan, or just a phone contract. A stolen Social Security number and driver's license number are the exact two documents somebody needs to open credit in your name. You don't need savings to be a target here. You need an identity, and you already have one. Patients of Together Women's Health, one of the customers Aesto filed notices for in Texas and California, are in this file too.

What's next

Two things are still open, and the source is blunt about both: no hacking group has publicly taken credit for the attack, and Aesto did not respond to requests for comment. Watch the state breach notices — Aesto has been filing them on behalf of its customers, so more of the 30 affected healthcare organizations may surface by name. No timeline has been given for any of it.

One detail to hold on to

9.5 million people's identity files are somewhere, and nobody has claimed them. No group boasting, no ransom note made public, no explanation. We don't know who has them or what they plan to do. The unsettling part isn't the theft — it's the silence around it.

Sources: The Record (Recorded Future News), September 2, 2026, reporting by Jonathan Greig, citing Aesto's June statement and its notification to the US Department of Health and Human Services.

Why we ran this8/10

Компания, о существовании которой пациенты не подозревали, хранила их номера соцстрахования, диагнозы и банковские счета — и потеряла их 9,5 млн человек, причём узнали об этом только через девять месяцев после взлома.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: Same job, two prices: £27 for one Uber dri… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X