AESTO, LLC
bd_64f64f39cb8a849a · schema v1 · pii pii-v2
Full breach record for AESTO, LLC →Diana Health, Inc. notified the New Hampshire Attorney General of a data security incident involving its vendor, Aesto LLC d/b/a Aesto Health. Between December 2 and December 18, 2025, an unauthorized actor accessed and copied data from Aesto's AWS infrastructure. The incident impacted approximately 10 New Hampshire residents, exposing names, Social Security numbers, and other personal identifiers. Diana Health began mailing notices on August 28, 2026, and provided credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
May 26, 2026
Discovered
Aug 28, 2026
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- New Hampshire State AGbd_4fe674ca1413cfc02026-08-27 · +1dVerified
- Massachusetts State AGbd_d39e08ca3ce7e1182026-09-01 · +4dVerified
- California State AGbd_65f70444b3fbe6f72026-08-24 · +4dVerified
- New Hampshire State AGbd_b5839d18101d09ca2026-08-21 · +7dVerified
Show 4 more filings ↓Show fewer ↑up to 28d gap
- New Hampshire State AGbd_eac49aabb3a023ff2026-08-21 · +7dVerified
- Illinois State AGbd_49a6928816a82c852026-08-01 · +27dCandidate
- Illinois State AGbd_a10ec3898d9326e02026-08-01 · +27dVerified
- HHS OCRbd_6054557cd914ee672026-07-31 · +28dCandidate
Filing propagation · 9 filings · 5 states
View merged incident ↗Pattern: first filing Jul 31 (AL), last Sep 1 (MA) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.