PrivacySignal
Breach

Health data of more than 9.5 million people leaked from Aesto record system

The Record · · International · Data Breaches

Aesto, a healthcare data company, disclosed to federal regulators that a cyberattack last December exposed sensitive information belonging to more than 9.5 million people. The breach was reported this week.

Why this matters: Nine and a half million people did not choose to share their health information with Aesto. They had no real option. Health data follows you. It can affect insurance, employment, and personal relationships in ways a leaked password never will. A breach this size means real harm to real people, most of whom probably do not know their records were taken. The accountability question is simple: what security standards did Aesto have, and were they anywhere near adequate for the sensitivity of what they were holding?

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Oncology Firm Novocure Announces Cyberattack and Data Breach

Novocure, a medical technology company focused on oncology, has confirmed a cyberattack that exposed data belonging to patients and employees. The company has not publicly detailed the scope of the breach or the type of information compromised.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BBC — Tech · · International

Criminals publish data of 8.7m people after airports hack

Criminals have published personal data belonging to 8.7 million people following a hack on a company that operates Manchester, Stansted, and East Midlands airports. The breach occurred last month and the stolen data has now been released publicly.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highland Oncology Group, a cancer care practice based in Arkansas, has reached a settlement in litigation connected to a ransomware attack that occurred in 2025. The practice serves patients across Arkansas, Missouri, and Oklahoma.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
Microsoft Threat Intelligence · · International

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Attackers are running an active campaign that mimics legitimate software vendors, using fake download pages and tampered installer files to deliver malware. Microsoft Defender Experts documented the attack methods and published detection guidance and indicators of compromise to help organizations respond.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#surveillance#security Read original →