Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health, a U.S. healthcare technology company, disclosed a breach exposing personal and health information of more than 9.5 million individuals after attackers gained unauthorized access to its AWS infrastructure. The company discovered the incident on December 18, 2025. The breach resulted in exposure of sensitive healthcare and personal data across a significant portion of the affected population.
Nutex Health, a Houston-based healthcare facilities operator, disclosed a data breach occurring in August in which cybercriminals stole patient and employee information. The attackers subsequently attempted extortion using the compromised data, prompting the company to file a report with federal regulators.
Threat actors obtained a METR API key and exploited it for approximately three weeks to consume $600,000 worth of model credits. The incident highlights the financial impact and operational risks associated with compromised API credentials in AI service environments.
Aesto Health experienced a data breach affecting 9.5 million individuals, with attackers gaining unauthorized access to personal and health information stored in the company's AWS infrastructure. The incident highlights ongoing security challenges in healthcare technology environments and the sensitive nature of data at risk when cloud infrastructure is compromised.
Berlin's state government confirmed it suffered a data breach of its administrative network in August followed by an extortion attempt by the attackers. Governing officials publicly stated the city will not comply with the blackmailers' demands, characterizing the incident as a serious crime. The breach prompted an emergency Senate session where leadership addressed both the security incident and the extortion threat.