Attackers impersonated Astrana Health personnel and spoofed its main corporate phone number to seek access to company systems.
What happened
Astrana Health disclosed the incident in a September 23, 2026, SEC filing, after its subsidiary, Astrana Health Management, detected unusual activity. Callers posing as company personnel contacted employees while displaying the company’s main number. Astrana believes unauthorized parties accessed or acquired information on its servers. It is still assessing whether patient, employee, provider, business, or financial information was involved. The filing did not give an affected-person count.
What was said
Discussing social engineering in its October 2024 cybersecurity newsletter, the HHS Office for Civil Rights warned, “Using such manipulative techniques can often bring an attacker quicker and easier success than attempting to breach an organization’s cyber defenses.”
The big picture
The practical lesson for healthcare organizations is to verify unexpected requests through an established contact route. HHS recommends callbacks to numbers already on record when employees request password resets or enrollment of new authentication devices. Its guidance also identifies supervisor verification and in-person checks as options for sensitive help desk requests.
Paubox’s The top 3 healthcare email attacks in 2025 and how to defend against them describes a related pattern in healthcare email attacks. Its section on business email compromise (BEC) and impersonation states, “In many cases, recipients voluntarily disclosed sensitive information because the sender appeared legitimate.” It offers a useful parallel to Astrana’s phone-based incident. Attackers can use a familiar identity to make an unauthorized request appear routine. For healthcare organizations, the implication is that identity checks need to cover both email and telephone requests.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Does a spoofed number mean an organization’s phone system has been hacked?
Not necessarily, because attackers can falsify caller ID without taking control of the organization’s phone system.
Can a caller be trusted if they know an employee’s name or job title?
No, attackers can use public information or details from previous breaches to make their story sound convincing.
Should employees share a sign-in code with someone claiming to be from IT?
No, sharing a sign-in code can give an attacker access to an account, even if the caller claims to be helping secure it.
