HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Health Records

Aesto Health disclosed that attackers breached its AWS environment, exposing personal and protected health information for over 9.5 million people. The incident underscores the need for continuous access‑control monitoring and audit‑ready evidence of cloud‑IAM hygiene.

Verisq™ Intelligence · 📅 September 02, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Health Records

What Happened – Attackers gained unauthorized access to a portion of Aesto Health’s Amazon Web Services (AWS) environment, resulting in the exposure of personal and protected health information for more than 9.5 million individuals. The breach was discovered on 18 December 2025 and publicly disclosed in September 2026.

Why It Matters for Trust & Control Assurance

  • This incident illustrates the exact scenario a continuous access‑control monitoring program is built to detect, document, and remediate – unauthorized cloud‑infrastructure access.
  • Demonstrable evidence of privileged‑access reviews, MFA enforcement, and real‑time logging provides a defensible audit trail for regulators and partners.
  • Leveraging Verisq’s Access Controls capability helps organizations collect, correlate, and retain the control evidence needed to satisfy multiple framework objectives (e.g., NIST CSF 2.0 “Protect” function).

Who Is Affected – U.S. healthcare technology providers, EHR‑exchange platforms, and any organization that stores or processes PHI on third‑party cloud services.

Recommended Actions

  1. Map the “cloud‑access management” control to your audit‑readiness framework and capture current evidence (IAM policies, MFA logs, privileged‑session recordings).
  2. Initiate a focused review of AWS IAM roles, trust relationships, and network segmentation; remediate any over‑privileged permissions.
  3. Deploy continuous monitoring tools that generate immutable logs for every privileged action and integrate them into your Trust Center for audit‑ready reporting.

Technical Notes – The attackers accessed the AWS environment between 2 December 2025 and 18 December 2025. Exposed data includes names, birth dates, medical and insurance details, driver’s‑license numbers, financial account information, taxpayer IDs, and, for a subset, Social Security numbers. No specific vulnerability (CVE) was disclosed; the entry vector remains unconfirmed.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →