DisclosureLens
HackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIPHIIdentity (basic)Government IDFinancial accountMediumContained

AESTO, LLC

bd_64f64f39cb8a849a · schema v1 · pii pii-v2

Severity

Medium

Discovered

May 26, 2026

Filed

Aug 28, 2026

To disclose

13 weeks

Affected

10state residents only

Linked

9 filings

Confidence

70%
Full breach record for AESTO, LLC

Diana Health, Inc. notified the New Hampshire Attorney General of a data security incident involving its vendor, Aesto LLC d/b/a Aesto Health. Between December 2 and December 18, 2025, an unauthorized actor accessed and copied data from Aesto's AWS infrastructure. The incident impacted approximately 10 New Hampshire residents, exposing names, Social Security numbers, and other personal identifiers. Diana Health began mailing notices on August 28, 2026, and provided credit monitoring services.

Incident timeline

undetected · 175 days
discovery → filing · 13 weeks / 94 days

Dec 2, 2025

Begins

May 26, 2026

Discovered

Aug 28, 2026

Filed

vs. sector median

+2 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 28d gap

Filing propagation · 9 filings · 5 states

View merged incident ↗

Pattern: first filing Jul 31 (AL), last Sep 1 (MA) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.