Skip to content
Social engineeringContained

Astrana Health tells SEC a vishing attack exposed sensitive data

Astrana Health disclosed in an SEC filing that attackers used phone-based social engineering, spoofing its corporate number and impersonating staff, to access confidential data on its servers.

Victim
Astrana Health

On 22 September 2026, Astrana Health โ€” a NASDAQ-listed California healthcare technology company (ticker ASTH) that operates care-delivery and administrative platforms for a large network of affiliated medical providers โ€” disclosed in a filing with the U.S. Securities and Exchange Commission that it had suffered a cybersecurity incident it considered material. The company said its forensic investigation found that threat actors had used phone-based social engineering โ€” a technique known as "vishing" โ€” to obtain access to its systems.

According to the disclosure, the attackers impersonated Astrana personnel and spoofed the company's main corporate telephone number to trick employees into providing access. Astrana said it believed that "certain private and/or confidential information maintained on the Company's servers" had been accessed or acquired without authorization, and that it was still assessing whether patient, employee, credentialed-provider, confidential business and financial information, or intellectual property had been affected.

Response

Astrana's security team responded to the activity, engaged third-party cybersecurity and digital-forensics experts, and notified law enforcement and regulators. The company said it had reset affected credentials, restricted remote-access tools, restored certain systems from clean backups, and enhanced its monitoring, logging and detection capabilities. As of the filing, no ransomware group had publicly claimed the attack, and Astrana did not confirm whether ransomware was involved.

Why it matters

The Astrana disclosure landed amid a run of U.S. healthcare-technology firms reporting breaches to the SEC in September 2026, underscoring how attackers are increasingly bypassing technical defenses by targeting help desks and employees directly over the phone. Because health-tech platforms concentrate patient and provider data across many downstream practices, a single voice-phishing intrusion at a vendor can put sensitive records for a wide population at risk. Astrana said it did not expect a material operational or financial impact, but noted its investigation remained ongoing; the incident's status was recorded as contained.

Timeline

  1. Astrana Health files a Form 8-K with the SEC disclosing a cybersecurity incident it deemed material.

  2. Forensic investigation finds attackers impersonated staff and spoofed the corporate phone number to trick employees into granting system access.

  3. Astrana resets affected credentials, restricts remote-access tools, restores systems from clean backups and notifies law enforcement and regulators.

Sources

  1. therecord.mediahttps://therecord.media/astrana-cyberattack-sec-ransomware
  2. bankinfosecurity.comhttps://www.bankinfosecurity.com/astrana-health-tells-sec-hack-exposed-sensitive-data-a-32937
  3. hipaajournal.comhttps://www.hipaajournal.com/astrana-health-data-breach/
  4. sec.govhttps://www.sec.gov/Archives/edgar/data/0001083446/000110465926109813/asth-20260922x8k.htm

Related incidents