Cyberattacks

Astrana Health: spoofed calls led to server access

The company describes an intrusion after callers impersonated staff. The scope of potentially affected data remains under investigation.

Conceptual illustration: Astrana Health: spoofed calls led to server access
Conceptual illustration · SecurCheck

What is confirmed

In its SEC filing, Astrana says attackers impersonated staff and its corporate phone number to contact employees and gain unauthorised access.

The company deemed the incident material on 22 September and is assessing whether patient, employee, provider or business data was accessed or exfiltrated.

What it means

Caller ID does not prove who is calling: it can be spoofed.

The filing describes risk and an investigation; it does not confirm that every listed data category was leaked.

What to do

Call back anyone requesting IT access through a known internal number, never one supplied during the call.

If affected, follow official notices and report unexpected requests for access or documents.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Astrana Health — déclaration SEC 8-K