Your S3 Bucket Is Now Public Domain
# Your S3 Bucket Is Now Public Domain
The page hits at 3am because the egress monitors are screaming. You see a massive spike in outbound traffic from an AWS region that should be quiet. By the time you're caffeinated, you realize it's not a glitch. It's an evacuation.
Aesto Health just confirmed they lost PII and PHI for over 9.5 million individuals. That is a staggering volume of data to lose from "infrastructure" in one go. When a healthcare tech firm mentions AWS exfiltration, you don't look for a zero-day. You look for a misconfigured S3 bucket or an over-privileged IAM role that someone left floating in the wind.
The attackers didn't need a master key. They likely found a door that was already propped open with a brick.
Healthcare is currently the #3 most targeted sector on my wire, with 151 stories hitting the desk this week. The volume is high, but the quality of the security is consistently low. CareCloud just leaked records for 3.75 million people. Aesto just tripled that number. It's a pattern of negligence masquerading as "sophisticated attacks."
Aesto's statements will be standard corporate theatre. They'll mention they're "working with leading forensic experts" and "taking the matter seriously." What they won't say is how long that data sat exposed before the attackers found it. Dwell time is the only metric that matters here. If 9.5 million records left the building, this wasn't a smash-and-grab. This was a slow bleed.
The gap between what they admit and what they avoid is where the truth lives. They'll focus on the "unauthorized access" as if it were an act of God. They'll avoid talking about why their logging didn't trigger an alert when terabytes of patient data started moving to a rogue IP.
Getting hit is common. Handling it this badly is a choice.
The cost here isn't just the immediate forensic bill or the inevitable class-action settlements. It's the second-order fallout. We are seeing a massive surge in identity theft capabilities because of these leaks. Look at Nexus, the dark web service currently selling scans of over 153 million drivers licenses. When you combine Aesto's PHI with those IDs, you have everything needed for high-end medical fraud and insurance scams that can last a decade.
The downstream victims are the patients who will find out their identities were stolen three years from now when they try to apply for a loan or see a doctor. The insurers are also exposed; they're the ones who will eventually pay the claims resulting from this failure of basic cloud hygiene.
Some will argue that the complexity of modern AWS environments makes these slips inevitable. That's mush.
Complexity isn't an excuse for failing at the basics. If you can't run a simple permission auditor on your buckets, you have no business hosting millions of medical records. The tools to prevent this are cheap and automated. Choosing not to use them is a decision to accept the risk on behalf of 9.5 million people who never signed that waiver.
This rhymes with every major cloud leak from the last five years. The story always starts with "sophisticated actors" and ends with a forgotten test environment or a legacy API key stored in plain text. The only difference here is the scale.
We're seeing a systemic failure in how healthcare vendors treat the "shared responsibility model." They assume AWS handles the security of the data, rather than just the security of the cloud. It's a fundamental misunderstanding of the contract.
If Aesto wants to actually fix this, they should stop hiring PR firms and start auditing every single IAM policy in their production environment. But they won't. They'll wait for the news cycle to move on to the next JFrog or Langflow exploit.
The real question is why we're still surprised by this. We've had a decade of "leaky bucket" headlines and yet firms are still uploading millions of SSNs to the cloud without checking if the door is locked.
I suspect we'll see more of this as these legacy health-tech stacks move to the cloud without updating their security culture. The migration is happening faster than the competence is growing.
Check your outbound traffic logs before the pager does it for you.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure The Hacker News
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild SecurityWeek
- Hackers Start Exploiting Critical Langflow Vulnerability SecurityWeek
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity The Hacker News
- Attackers Pounce on Critical Artifactory Flaw Following Disclosure Dark Reading
- McKesson Data Breach Exposes Millions to Patient Data Theft - The Cryptonomist Google News Security
- CareCloud Data Breach Exposes Medical Records, Social Security Numbers of 3.75 Million - wowo.com Google News Security
- FBI Probes Service Selling 153M+ Drivers Licenses Krebs on Security