INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Misconfigured Storage Bucket Exposes Medical Data of Thousands

| 2025-07-26 03:27 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 26, 2025, nearly 14,000 documents containing financial, medical, and personal information were exposed by Medico Inc., a healthcare vendor that provides billing and insurance data processing. The breach was attributed to an Amazon S3 bucket misconfigured for sensitive files related to healthcare. These documents included explanations of insurance benefits, insurance claims, medical records and reports, legal documents, and internal business data for Medico itself. The exposed data contained approximately 1.7GB of PDFs, spreadsheets, text files, and images, including bank account and routing numbers, social security numbers (SSNs), and more. The attack worked by exploiting a misconfigured storage bucket that allowed unauthorized access to the sensitive information. As a result of this breach, individuals whose medical business was processed by Medico are at risk due to the presence of personally identifiable information in these documents.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
VA
financefinance healthhealth technologytechnology
Incident Timeline
‎2025/07/26
Threat actors used a misconfigured Amazon S3 bucket to expose nearly 14,000 documents containing financial, medical, and personal information.
data_breach 1.7 GB
Tactical Metrics
Metrics
data_breach
2
Gb