www.securityweek.com 24 Sept 2026, 09:56 UTC

Astrana Health Says Attackers Stole Sensitive Data Through Social Engineering

Astrana Health Says Attackers Stole Sensitive Data Through Social Engineering
CyberSIXT Evidence Panel Source marked as original reporting

ASTRANA Health, a California-based healthcare management company providing back-office services such as claims and billing, says private and confidential information was stolen from servers belonging to its subsidiary, Astrana Health Management. According to a filing with the US Securities and Exchange Commission, attackers used social engineering to gain access, impersonating Astrana Health personnel and spoofing the company’s main telephone number when contacting employees.

The company said it detected the intrusion, hired a third-party cybersecurity firm, notified relevant authorities and partners, and began an investigation. It has since rotated credentials, restricted remote-access tools, rebuilt some systems from clean backups, and strengthened monitoring, logging and detection.

The investigation has confirmed that threat actors accessed and exfiltrated some information, but Astrana Health is still assessing whether patient, employee, credentialed-provider, confidential business and financial information, intellectual property or other data was affected, and the potential impact. The company described the incident as material because of the potentially sensitive nature of the information, while saying it does not expect the breach to affect its financial condition or operations.

No threat actor has been identified, and no known ransomware or extortion group had claimed responsibility at the time of reporting.

View full article

Article by CyberSIXT