[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkr-qUkKEF4tcLlBFjmGwPw7QeKJn5jgWMyqf6dfPVeE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"ea41fcfc-2b94-4b0d-9547-fac1c6ff69de","95-million-records-exposed-in-aesto-health-aws-breach","885545a2-1bef-43c3-bb01-d3a35d995712","9.5 Million Records Exposed in Aesto Health AWS Breach","Hackers gained unauthorized access to Aesto Health's AWS infrastructure for over two weeks, exfiltrating highly sensitive personal, financial, and medical data on 9.5 million individuals. The 16-day dwell time suggests a failure in both access controls and monitoring, allowing attackers to operate undetected long enough to conduct large-scale data exfiltration. Healthcare organizations are high-value targets precisely because the data they hold — Social Security numbers, health records, insurance details — commands premium prices on criminal markets and causes lasting harm to victims. This breach underscores that cloud infrastructure requires the same rigorous security posture as on-premises systems, including least-privilege access, continuous monitoring, and data minimization practices.","**Immediate actions:**\n- Audit and rotate all AWS IAM credentials, access keys, and service account permissions to eliminate unauthorized or overprivileged access.\n- Enable AWS CloudTrail, GuardDuty, and Security Hub to provide continuous visibility into cloud infrastructure activity and trigger real-time alerts.\n- Apply encryption at rest and in transit for all datastores containing PII, PHI, and financial account information.\n\n**Long-term improvements:**\n- Enforce least-privilege access across all AWS roles and implement multi-factor authentication (MFA) for every account with access to sensitive data.\n- Adopt a cloud security posture management (CSPM) tool to continuously detect misconfigurations and policy violations in cloud environments.\n- Implement data minimization and retention policies to reduce the volume of sensitive records stored and limit breach impact.\n\n**Detection measures:**\n- Establish baseline behavioral analytics for cloud environment access patterns and alert on anomalous data transfer volumes or unusual API calls.\n- Define and regularly test an incident response playbook specifically for cloud-based breaches, including containment, notification, and regulatory reporting procedures.\n- Conduct quarterly third-party penetration testing of AWS infrastructure to proactively identify exploitable attack surfaces.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 3 – Data Protection","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 AU-6 (Audit Record Review)","NIST SP 800-53 IR-4 (Incident Handling)","NIST SP 800-53 SC-28 (Protection of Information at Rest)","HIPAA Security Rule §164.312(a)(1) – Access Control","HIPAA Security Rule §164.312(b) – Audit Controls","HIPAA Breach Notification Rule §164.400–414","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","AWS Well-Architected Framework – Security Pillar","published","2026-09-01T10:20:53.521422+00:00","2026-09-01T10:20:53.447+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fwww.securityweek.com\u002F9-5-million-impacted-by-aesto-health-data-breach\u002F","9-5-million-impacted-by-aesto-health-data-breach-b913d2","9.5 Million Impacted by Aesto Health Data Breach",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":48,"name":49,"slug":50,"description":51,"color":52},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]