Full Report
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
Analysis Summary
# Incident Report: Aesto Health AWS Infrastructure Breach
## Executive Summary
Aesto Health, a SaaS provider for healthcare data migration and archiving, suffered a significant data breach affecting approximately 9.5 million individuals across 29 healthcare providers. An unauthorized actor gained access to a portion of the company's Amazon Web Services (AWS) infrastructure, leading to the exfiltration of highly sensitive Protected Health Information (PHI) and Personally Identifiable Information (PII). The breach remained undetected for over five months, eventually leading to large-scale identity theft protection offerings for the affected population.
## Incident Details
- **Discovery Date:** May 26, 2026 (Internal confirmation)
- **Incident Date:** December 2, 2025 – December 18, 2025
- **Affected Organization:** Aesto LLC (dba Aesto Health)
- **Sector:** Healthcare Technology / SaaS
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** On or about December 2, 2025
- **Vector:** Unauthorized access to Amazon Web Services (AWS) infrastructure (specific entry method like credential stuffing or misconfiguration not explicitly disclosed).
- **Details:** Attackers gained access to a "limited portion" of Aesto’s cloud environment.
### Lateral Movement
- **Details:** The actor moved within the Aesto network to access data silos containing archives and migrated records from various "Covered Entity" (healthcare provider) clients.
### Data Exfiltration/Impact
- **Date Range:** December 2, 2025 – December 18, 2025
- **Details:** Forensic evidence confirmed that the actor accessed and/or acquired sensitive documents containing medical records, financial data, and government identifiers for over 9.5 million patients.
### Detection & Response
- **Discovery:** The incident was identified recently (specific trigger not named), leading to a forensic investigation by external specialists.
- **Confirmation:** May 26, 2026 – Manual document review confirmed the scope of compromised PHI.
- **Public Disclosure:** June 24, 2026 – Initial website notification.
- **Individual Notification:** August 21, 2026 – Direct letters sent to victims.
## Attack Methodology
*Note: Based on available disclosure data.*
- **Initial Access:** Compromise of AWS infrastructure (Cloud environment).
- **Collection:** Accessing stored archives and SaaS databases belonging to 29 different healthcare clients.
- **Exfiltration:** Unauthorized acquisition of patient files between Dec 2 and Dec 18, 2025.
- **Impact:** Massive data breach of PHI/PII; potential for identity theft and regulatory fines (HIPAA).
## Impact Assessment
- **Financial:** Cost of forensic specialists, legal counsel, and 24 months of Experian identity protection for 9.5 million people.
- **Data Breach:** 9,540,683 individuals; data includes SSNs, ITINs, Driver’s Licenses, financial account numbers, and medical history.
- **Operational:** Diversion of resources to manual document review and forensic investigation.
- **Reputational:** Impact on trust with 29 major healthcare clients including VillageMD and Together Women’s Health.
## Indicators of Compromise
- **Network indicators:** Not disclosed in public report.
- **File indicators:** Not disclosed in public report.
- **Behavioral indicators:** Unusual access patterns within AWS S3 buckets or EC2 instances outside of normal migration windows.
## Response Actions
- **Containment:** Secured the affected AWS infrastructure (timeline implies the hole was closed after Dec 18, 2025).
- **Eradication:** Engaged third-party forensic specialists to purge unauthorized access points.
- **Recovery:** Conducted a manual review of all documents to identify specific victims for notification.
- **Remediation:** Offered 24 months of credit monitoring and identity theft insurance through Experian.
## Lessons Learned
- **Dwell Time:** The attacker had access in December 2025, but the breach wasn't confirmed until May 2026. Improving Mean Time to Detect (MTTD) in cloud environments is critical.
- **Third-Party Risk:** Healthcare providers (Covered Entities) are heavily impacted by the security posture of their SaaS vendors (Business Associates).
- **Cloud Security:** "Limited" access to AWS infrastructure can still result in total data compromise if permissions (IAM) are not strictly segmented.
## Recommendations
- **Identity & Access Management:** Implement strict Multi-Factor Authentication (MFA) for all AWS console and API access.
- **Logging & Monitoring:** Deploy automated cloud-native security tools (e.g., Amazon GuardDuty) to alert on unusual data egress or unauthorized API calls in real-time.
- **Data Encryption:** Ensure all PHI is encrypted at rest and that encryption keys are managed with strict access controls.
- **Principle of Least Privilege:** Segment client data so that a compromise in one "limited portion" of the infrastructure cannot reach the entire 9.5-million-record database.