Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Health Records
What Happened – Attackers gained unauthorized access to a portion of Aesto Health’s Amazon Web Services (AWS) environment, resulting in the exposure of personal and protected health information for more than 9.5 million individuals. The breach was discovered on 18 December 2025 and publicly disclosed in September 2026.
Why It Matters for Trust & Control Assurance
- This incident illustrates the exact scenario a continuous access‑control monitoring program is built to detect, document, and remediate – unauthorized cloud‑infrastructure access.
- Demonstrable evidence of privileged‑access reviews, MFA enforcement, and real‑time logging provides a defensible audit trail for regulators and partners.
- Leveraging Verisq’s Access Controls capability helps organizations collect, correlate, and retain the control evidence needed to satisfy multiple framework objectives (e.g., NIST CSF 2.0 “Protect” function).
Who Is Affected – U.S. healthcare technology providers, EHR‑exchange platforms, and any organization that stores or processes PHI on third‑party cloud services.
Recommended Actions
- Map the “cloud‑access management” control to your audit‑readiness framework and capture current evidence (IAM policies, MFA logs, privileged‑session recordings).
- Initiate a focused review of AWS IAM roles, trust relationships, and network segmentation; remediate any over‑privileged permissions.
- Deploy continuous monitoring tools that generate immutable logs for every privileged action and integrate them into your Trust Center for audit‑ready reporting.
Technical Notes – The attackers accessed the AWS environment between 2 December 2025 and 18 December 2025. Exposed data includes names, birth dates, medical and insurance details, driver’s‑license numbers, financial account information, taxpayer IDs, and, for a subset, Social Security numbers. No specific vulnerability (CVE) was disclosed; the entry vector remains unconfirmed.
Source: Security Affairs