Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
Aesto Health confirmed a data breach affecting more than 9.5 million patients after unauthorized access to its AWS infrastructure. Stolen data includes names, Social Security numbers, financial details, and medical records. The incident impacted more than two dozen of the firm's clients. This follows a separate, larger breach at McKesson where the ShinyHunters hacking group claimed to have stolen 284 million patient records. While McKesson works to restore services, the Aesto Health disclosure provides specific figures on the volume of exposed sensitive medical and personal data.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Aesto Health confirmed a data breach affecting more than 9.5 million patients.
- ✓ Stolen information includes names, Social Security numbers, and medical data.
- ✓ Unauthorized access to AWS infrastructure caused the Aesto Health breach.
What changed
Aesto Health disclosed the exposure of 9.54 million patient records via its AWS infrastructure.
Live updates
-
Aesto Health confirms breach of 9.5 million patient records
Aesto Health confirmed a data breach affecting more than 9.5 million patients after unauthorized access to its AWS infrastructure. Stolen data includes names, Social Security numbers, financial details, and medical records. The incident impacted more than two dozen of the firm's clients. This follows a separate, larger breach at McKesson where the ShinyHunters hacking group claimed to have stolen 284 million patient records. While McKesson works to restore services, the Aesto Health disclosure provides specific figures on the volume of exposed sensitive medical and personal data.
Why it matters
Healthcare providers are facing a surge of cyberattacks targeting sensitive patient information. These breaches expose individuals to identity theft and financial fraud. The scale of these incidents varies from targeted employee record theft to massive infrastructure compromises.
What is confirmed
- Aesto Health confirmed a data breach affecting more than 9.5 million patients.
- Stolen information includes names, Social Security numbers, and medical data.
- Unauthorized access to AWS infrastructure caused the Aesto Health breach.
Still unconfirmed
- More than two dozen Aesto clients were affected by a December 2025 cyberincident.
- Ceva Logistics faces a lawsuit alleging employee records were stolen during a cyberattack.
What to watch next
- Verification of the 284 million record claim by McKesson
- Legal filings or regulatory penalties against Aesto Health
- Identification of the threat actor responsible for the AWS infrastructure breach
confidence 90%Sources used for this update (4)
- www.yahoo.com — More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen
- www.freightwaves.com — Ceva Logistics sued over theft of employee records during data breach
- www.yahoo.com — More than 9.5 million patient records affected by Aesto Health data breach: what you need to know
- dailyhodl.com — Healthcare Firm Breach Exposes 9,540,683 Patient Records – Names, Social Security Numbers, Medical Data and More at Risk
-
McKesson confirms data breach, 284M patient records stolen
Healthcare giant McKesson has confirmed a data breach after hackers claimed to have stolen 284 million patient records. The breach was discovered after ShinyHunters, a hacking group, claimed responsibility for the theft. McKesson is working to restore services and investigate the incident. The breach is one of several recent cyberattacks targeting healthcare companies.
Why it matters
The breach raises concerns about the security of sensitive patient information and the vulnerability of healthcare systems to cyberattacks. McKesson is a large pharmaceutical and healthcare company that handles a vast amount of patient data. The incident highlights the need for robust cybersecurity measures to protect patient information.
What is confirmed
- McKesson has confirmed a data breach.
- 284 million patient records were stolen.
- ShinyHunters is the hacking group that claimed responsibility for the theft.
- The breach is one of several recent cyberattacks targeting healthcare companies.
Still unconfirmed
- The hacking group ShinyHunters set a deadline for McKesson to respond.
What to watch next
- McKesson's investigation into the breach
- The company's plan to notify and support affected patients
- Any potential regulatory actions or lawsuits resulting from the breach
confidence 95%Sources used for this update (13)
- TechCrunch — Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
- SecurityWeek — McKesson Confirms Data Breach as Attacker Deadline Looms
- The HIPAA Journal — ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson
- cyberinsider.com — ShinyHunters claims McKesson data breach exposing 284 million patient records
- helpnetsecurity.com — ShinyHunters claims it stole 284 million patient records from McKesson
- malwarebytes.com — McKesson confirms cyber incident after ShinyHunters claims patient-data theft
- The Register — Healthcare cyberattacks hit pacemakers and millions of patient records
- The Record from Recorded Future News — Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
- www.yahoo.com — Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices
- www.securityweek.com — 9.5 Million Impacted by Aesto Health Data Breach
- cyberinsider.com — Aesto healthcare data breach impacts 9.5 million people
- securityaffairs.com — Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community