Security & Risk5 minNewsroom

Astrana Health reports SEC on spoofed phone attack

Americana Astrana Health reported a material cyber incident to the SEC: criminals spoofed the company’s number and posed as employees to gain system access.

Telefone de mesa fora do gancho em balcão de recepção de clínica, com atendente desfocada ao fundo.

Astrana Health, an American provider of services and technology for physicians and healthcare payers, notified the SEC on September 23 of a material cyber incident concerning its subsidiary, Astrana Health Management. The vector described in the Form 8-K does not involve a software vulnerability: criminals posed as company employees and spoofed the company's main phone number to call associates in an attempt to gain access to internal systems.

Shares of Astrana, traded on Nasdaq under the ticker ASTH, dropped in pre-market trading on September 23 following the disclosure. The company did not publicly detail how many patients or records may have been affected, nor whether a ransom was requested.

What the company confirmed

According to the statement sent to the SEC, Astrana's security team detected unusual activity in the subsidiary's environment, responded to the unauthorized activity, and opened an investigation. The company hired an external digital forensics consultancy, notified law enforcement, and is informing state and federal regulators as well as partnering health plans.

The use of the material incident item in the 8-K carries weight. Since December 2023, the SEC requires publicly traded companies to disclose cyber incidents within four business days after determining that the impact is material. Astrana made this decision while the investigation is still ongoing, indicating that the initial assessment deemed the case relevant to investors before the extent of the damage was fully quantified.

Phone social engineering: the vector that can't be patched

The technique described by Astrana mirrors some of the largest corporate incidents in the past three years: calls to the service center or employees, with the attacker posing as a colleague or someone from IT to obtain a password reset, register a new authentication device, or install remote access tools. Spoofing the company's phone number eliminates the most obvious warning sign for the recipient.

This vector circumvents much of the security investments made in recent years. Multi-factor authentication, EDR, and network segmentation protect against the intruder attempting to enter through technical means; they do not prevent an employee, convinced they’re speaking with internal support, from handing over the key. The monthly report from NCC Group published on the same day, September 23, recorded 1,073 ransomware victims in August, a record for 2026, in an environment where initial access is the most sought-after product in digital crime.

American healthcare and call centers abroad

In the U.S., the healthcare sector is experiencing a series of incidents affecting payers, providers, and technology companies that connect them. Astrana occupies exactly this intermediary position: it works with both physicians and payers, and as such, its notification list includes payer partners as well as regulators. In such companies, unauthorized access may expose patient data subject to HIPAA and third-party billing information simultaneously.

The same risk permeates the outsourced service chain. Much of the customer service, revenue management, and IT support for American healthcare companies operates in service centers in India and the Philippines, run by providers like Cognizant, Infosys, and groups specialized in health BPO. An attacker convincing an agent in Manila or Chennai that they are an executive in Los Angeles exploits the same vulnerability, with an additional layer of distance and time zone that complicates verification through alternate channels.

For service providers in these countries, this incident reinforces a requirement that American clients are already starting to include in contracts: identity verification procedures for credential resets that do not rely on phones or information a criminal can find on social media.

The question for the board

Astrana's 8-K is brief and leaves the extent of the damage open. The point of concern for other boards is prior: how many people at the company could, with a convincing call, reset a privileged password or authorize a remote access tool, and by what means of verification. In many organizations, the answer involves dozens of outsourced agents with no feedback via independent channels. It is this computation, and not the budget for tools, that determines the exposure to the type of attack that Astrana has just reported.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk