Follow a leaked AWS access key through an AssumeRole escalation chain to scope an S3 data exposure, and learn why partial data-plane logging left a visibility gap
Larkwood Health System, a regional healthcare network, learns through GitHub's secret-scanning partner program that a long-lived AWS access key was committed to a contractor's public repository. Assemble the account's CloudTrail, GuardDuty, CloudWatch, and S3 access-log evidence to trace the intrusion from that leaked key through a misconfigured role trust policy, an IAM policy change that granted standing administrative access, and into two S3 buckets holding patient billing and claims data, then determine the full exposure scope despite an incomplete S3 data-plane logging gap.