INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Misconfigured Storage Bucket Exposes Medical Data of Thousands

| 2025-07-26 03:27 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 26, 2025, nearly 14,000 documents containing financial, medical, and personal information were exposed by Medico Inc., a healthcare vendor that provides billing and insurance data processing. The breach was attributed to an Amazon S3 bucket misconfigured for sensitive files related to healthcare. These documents included explanations of insurance benefits, insurance claims, medical records and reports, legal documents, and internal business data for Medico itself, totaling approximately 1.7GB of PDFs, spreadsheets, text files, and images. The exposed data contained personally identifiable information (PII) including bank account and routing numbers, social security numbers, and more, affecting individuals whose medical business was processed by Medico. The attack worked through the misconfigured storage bucket allowing unauthorized access to sensitive healthcare data. As of now, no further updates on the current status are available in this source.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
VA
financefinance healthhealth technologytechnology
Incident Timeline
‎2025/07/26
Threat actors used misconfigured Amazon S3 bucket "medicoar" to expose nearly 14,000 documents containing financial, medical, and personal information.
data_breach 1.7 GB
Tactical Metrics
Metrics
data_breach
2
Gb