Astrana Health breach: callers spoofed its main phone number, and the 8-K says less than the headlines
By Sethu Satheesh · 2 Oct 2026 · 19 min read
Threat Actor: Unknown · Target: Astrana Health, Inc. and subsidiary Astrana Health Management, Inc. (US value-based care / MSO)
Source: www.sec.gov
Executive Summary
Astrana Health, Inc. (Nasdaq: ASTH), a California value-based healthcare company, disclosed a material cybersecurity incident under Item 1.05 of Form 8-K. Item 1.05 is the SEC's material-cybersecurity-incident item, not a voluntary Item 7.01 or 8.01 disclosure.12 The filing gives September 22, 2026 as the date of report and the date the company determined the incident was material. EDGAR shows the 8-K was filed and accepted at 07:30:13 on September 23, 2026, and the chief executive signed it the same day.12 The company does not give a detection date. It says only that it "recently became aware" that its subsidiary Astrana Health Management, Inc. had detected unusual activity in its environment.1
The mechanism the company describes is voice-based social engineering. The threat actors impersonated company personnel and spoofed the company's main corporate telephone number, then contacted certain employees "in an effort to obtain unauthorized access to Company systems."1 In its response the company reset affected credentials, restricted remote access tools, restored certain systems from clean backups, and expanded monitoring, logging and detection.1 Based on its investigation so far, the company believes that "certain private and/or confidential information maintained on the Company's servers has been accessed and/or acquired without authorization." It is still working out whether patient, employee, credentialed provider, business, financial or intellectual-property information was involved.1
Who the data might belong to matters here. Astrana Health Management (formerly Network Medical Management) is the wholly owned management services organization (MSO). It holds management services agreements with affiliated independent practice associations, including Allied Physicians of California.3 Astrana's segments run risk-bearing provider networks, hospital and clinic care delivery, and an MSO "Care Enablement" platform used by providers inside and outside its own network.3 In July 2025 the company added the Prospect Medical businesses for $674.9 million.3 Astrana reported coordinating care for about 1.6 million patients as of December 31, 2025, and about 1.5 million in August 2026.45 These are the size of the patient population Astrana manages. Neither figure counts affected individuals, and no such count has been published.
The actor is unattributed as of October 2, 2026. The company has named no one, and no ransomware or extortion group appeared on the ransomware.live victim index when we checked on that date.16 SecurityWeek, The Record and GovInfoSecurity each reported finding no claim between September 23 and 25.789 Coverage moved beyond the filing in several places. Outlets reported that the calls "eventually" gave the attackers access, that data was "exfiltrated", that patient data was "exposed", and that the incident was material to Astrana's financial position. The 8-K says none of these things, and on the last point it says the opposite.17810 This paper separates what the company disclosed from what was added downstream.
Verification of Claims
-
Claim: Astrana disclosed the incident under Item 1.05 (Material Cybersecurity Incidents), not as a voluntary Item 7.01 or 8.01 disclosure. → Verified → The 8-K is headed "Item 1.05 Material Cybersecurity Incident", and the EDGAR filing index lists the sole item as "Item 1.05: Material Cybersecurity Incidents".12 A separate 8-K filed the same morning under Items 7.01 and 9.01 furnished an unrelated investor presentation.11
-
Claim: The 8-K was filed on September 22, 2026 ("Tuesday evening"). → Unverified (contradicted by the EDGAR record) → September 22 is the date of report and the materiality date. EDGAR records a filing date of September 23, 2026, accepted at 07:30:13.2 The Record reported a "Tuesday evening" filing, while GovInfoSecurity reported "a filing on Wednesday".89
-
Claim: The threat actors impersonated Astrana personnel and spoofed the company's main corporate telephone number to contact employees. → Verified → This is the company's own description in its Item 1.05 filing.1 No independent forensic report has been published, so the detail rests on the company's account alone.
-
Claim: The spoofed calls are how the attackers got into Astrana's systems and servers. → Partially verified → The 8-K says the incident "involved" the social engineering attempts, that unauthorized activity was detected, that affected credentials were reset, and that data on servers was accessed or acquired.1 It never says in so many words that a call succeeded or how access was gained. SecurityWeek, The Record and HIPAA Journal state the causal link as fact, and HIPAA Journal attributes it to a "forensic investigation" the filing does not mention.7810
-
Claim: The attackers used remote access tools inside the environment. → Unverified → This is only implied: "restricting remote access tools" appears among the remedial measures.1 No tool is named, and the filing does not say any tool was abused.
-
Claim: Private or confidential information on Astrana's servers was accessed or acquired. → Verified → This is the company's stated belief "based on the current status" of its investigation.1
-
Claim: The investigation determined that the attackers exfiltrated data. → Unverified → SecurityWeek wrote that Astrana told the SEC the actors "accessed and exfiltrated" information.7 The 8-K says "accessed and/or acquired", and lists exfiltration among the things the company "continues to assess".1
-
Claim: The incident exposed patient, employee and provider information. → Unverified → This is HIPAA Journal's lead sentence.10 The 8-K says the company "continues to assess whether, and to what extent" those categories were involved. It does say it intends to notify "impacted patients" based on its findings.1
-
Claim: The sensitivity of the data made the incident material to Astrana's financial position. → Unverified (contradicted by the filing) → This is The Record's reading.8 The 8-K bases materiality on "the potential confidential and sensitive nature of the data". In the same filing the company says it "currently does not expect that it will have a material effect on the Company's financial condition and results of operations."1
-
Claim: No ransomware or extortion group has claimed the attack. → Verified (as of October 2, 2026) → A ransomware.live victim search for "astrana" returned no victims on October 2, 2026.6 SecurityWeek, The Record (as of Wednesday afternoon, September 23) and GovInfoSecurity (as of Friday, September 25) each reported seeing no claim.789 Absence from a tracker does not show that no group has the data.
-
Claim: Ransomware was involved. → Unverified → The company did not answer The Record's question on ransomware.8 Restoring "certain systems from clean backups" shows some systems were rebuilt. It does not show whether anything was encrypted.1
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| November 8, 2024 | Astrana Health | Signs the Asset and Equity Purchase Agreement for certain Prospect Medical businesses | 3 |
| July 1, 2025 | Astrana Health | Completes the Prospect acquisition for $674.9 million | 3 |
| December 31, 2025 | Astrana Health | Reports responsibility for coordinating care for about 1.6 million patients | 4 |
| March 12, 2026 | Astrana Health | Files its FY2025 10-K. A risk factor warns that generative AI may enable "more sophisticated social engineering attacks" | 4 |
| August 6, 2026 | Astrana Health | Q2 2026 results describe about 1.5 million patients and 20,000+ providers in value-based arrangements | 5 |
| Not disclosed (before September 22, 2026) | Unknown actor | Calls to certain employees, impersonating personnel from a spoofed main corporate number. Astrana Health Management detects unusual activity | 1 |
| September 22, 2026 | Astrana Health | Determines the incident is material "due to the potential confidential and sensitive nature of the data" | 1 |
| September 23, 2026 (07:30:13) | Astrana Health | Item 1.05 Form 8-K accepted by EDGAR (accession 0001104659-26-109813) | 2 |
| September 23, 2026 | Astrana Health | Separate Item 7.01 8-K furnishes an investor deck. Its forward-looking statements cite the company's ability "to contain and remediate the cybersecurity incident" | 11 |
| September 23, 2026 | Levi & Korsinsky | Plaintiffs' firm posts a data-breach investigation page | 12 |
| September 24, 2026 | SecurityWeek / The Record | First trade-press reports. Neither has seen a claim of responsibility | 78 |
| September 25, 2026 | DataBreach.com | Summarizes SecurityWeek and The Record. Notes no victim count or field list published | 13 |
| September 28, 2026 | GovInfoSecurity / Scott+Scott | ISMG reports no darkweb claim "as of Friday". Scott+Scott opens a consumer investigation | 914 |
| September 29, 2026 | HIPAA Journal / teiss | Further reports. HIPAA Journal's lead says patient, employee and provider data was "exposed" | 1015 |
| October 2, 2026 | ThreatPaper | No 8-K/A on EDGAR. No Astrana entry on the HHS OCR portal or the CA, TX, WA or VT attorney-general lists. No ransomware.live victim entry. No Astrana press release on the incident | 161718192021622 |
Attack Anatomy
What follows rebuilds the attack only as far as the 8-K allows. Each stage is marked Established (stated in the filing), Implied (inferred from the remedial measures), or Unknown.
Reconnaissance (Unknown)
The filing does not say how the actors chose which employees to call or how they learned enough about "Company personnel" to impersonate them.1 The corporate number is not secret. Astrana's 8-K cover page lists a registrant telephone number of (626) 282-0288. The filing does not say whether that is the "main corporate telephone number" that was spoofed.1
Initial contact: voice impersonation with caller-ID spoofing (Established)
The actors ran "a series of social engineering attempts". They impersonated Company personnel and spoofed the company's main corporate telephone number when contacting certain employees, "in an effort to obtain unauthorized access to Company systems."1 A call that shows the company's own main number lends weight to an internal pretext such as IT support or a colleague. The filing does not give the pretext, the number of employees called, or which roles were targeted.1 The closest ATT&CK fits are Social Engineering: Impersonation (T1684.001) and voice spearphishing for access (T1566.004). If the calls only harvested credentials, Phishing for Information: Spearphishing Voice (T1598.004) applies instead.
Access and foothold (Implied)
Two remedial measures point to the access route without confirming it. "Resetting affected credentials" suggests that account credentials were obtained or used (T1078, Valid Accounts). "Restricting remote access tools" suggests remote-access software was involved, either installed at a caller's direction or already present and misused (T1219, Remote Access Tools).1 Both are inferences. The filing names no tool, no account type, and nothing about MFA.1
Actions on objectives (Established in part)
The company believes "certain private and/or confidential information maintained on the Company's servers has been accessed and/or acquired without authorization."1 It also "restor[ed] certain systems from clean backups", so at least some systems were judged untrustworthy and rebuilt. The filing does not say whether they were encrypted, altered or wiped.1
Exfiltration (Unknown)
The company "continues to assess whether, and to what extent" information "may have been accessed, acquired, or exfiltrated."1 No exfiltration channel, volume or destination has been disclosed.
Detection and response (Established)
Astrana's cybersecurity team detected and responded to the activity, began an investigation, and engaged an unnamed "leading third-party cybersecurity and digital forensics firm". It notified law enforcement and is notifying state and federal regulators and payer partners. It also enhanced monitoring, logging and detection.1
Loading diagram...
Threat Actor Profile
Name: Unknown Aliases: None Attribution confidence: None. The incident is unattributed as of October 2, 2026. Astrana's 8-K refers only to "threat actors".1 A ransomware.live victim search for "astrana" returned no victims on October 2, 2026.6 SecurityWeek, The Record and GovInfoSecurity each reported no claim of responsibility as of September 23–25.789 Motivation: Unknown. No ransom demand, leak-site listing or extortion contact has been disclosed, and the company did not tell The Record whether ransomware was involved.8 Sophistication: As far as the filing shows: an operator willing to make live phone calls, spoof caller ID, and pose convincingly as staff to several employees.1
On comparisons to Scattered Spider or ShinyHunters. No source located for this paper links the Astrana incident to Scattered Spider, ShinyHunters, or any other named group. The FBI and CISA describe Scattered Spider as having "posed as company IT and/or helpdesk staff using phone calls or SMS messages to obtain credentials from employees", and as installing remote access tools.23 That tradecraft looks like what Astrana describes. It is also widely shared across criminal groups, so the resemblance is an analogy and does not support attribution. No investigating body has made such a link.
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org; mapping is ThreatPaper's, from the 8-K text):
| ID | Technique |
|---|---|
| T1684.001 | Social Engineering: Impersonation (established) |
| T1566.004 | Phishing: Spearphishing Voice (established as attempted; success implied) |
| T1598.004 | Phishing for Information: Spearphishing Voice (alternative if the calls only elicited credentials) |
| T1078 | Valid Accounts (implied by "resetting affected credentials") |
| T1219 | Remote Access Tools (implied by "restricting remote access tools") |
OPSEC: Caller-ID spoofing of the company's own main number, so that inbound calls appeared to come from inside the organization.1 Nothing else has been disclosed.
Technical Indicators
spoofed_caller_id:
- "Astrana Health's main corporate telephone number (8-K does not state the digits)"
network_indicators: none disclosed
ip_addresses: none disclosed
domains: none disclosed
file_hashes: none disclosed
remote_access_tools: none named (8-K says only that remote access tools were restricted)
accounts: none disclosed (8-K says affected credentials were reset)
note: >
The Item 1.05 Form 8-K is the only first-party account and publishes no
indicators of compromise. No forensic report, government advisory or
leak-site listing with indicators had been published as of 2 October 2026.
The number on the 8-K cover page, (626) 282-0288, is the registrant's
published business line, not an indicator, and the filing does not confirm
it is the number that was spoofed.Legal and Regulatory Response
SEC. Astrana filed under Item 1.05 of Form 8-K on September 23, 2026, one business day after its September 22 materiality determination.12 The SEC's 2023 rules make an Item 1.05 report "generally due four business days after a registrant determines that a cybersecurity incident is material."24 The company says it will amend the report as information required by Item 1.05(a) "is determined or becomes available."1 No 8-K/A had been filed as of October 2, 2026.16
Health and state regulators. The company says it "is notifying state and federal regulators, and payer partners" and "intends to make all required notifications based on its findings, including to impacted patients."1 As of October 2, 2026, the HHS Office for Civil Rights breach portal had no entry for Astrana or Astrana Health Management. Its most recent posted submission was dated September 16, 2026, which predates the disclosure.17 The California attorney general's list, updated through September 30, 2026, had no Astrana entry.18 The Texas attorney general's table showed no match among 640 entries.19 The Washington attorney general's list, latest entry September 11, 2026, had no Astrana entry, and a Vermont attorney general site search returned no results.2021 Maine's public breach database was offline, so it could not be checked.25
Law enforcement. The company says it notified law enforcement but does not name the agency.1 No law enforcement statement, advisory or action tied to this incident had been published as of October 2, 2026.
Civil. The plaintiffs' firms Levi & Korsinsky and Scott+Scott announced investigations on September 23 and September 28, 2026.1214 ThreatPaper found no filed complaint in public web sources as of October 2, 2026. Court dockets were not searched directly.
Impact Assessment
- Confirmed: Private and/or confidential information on Astrana's servers was accessed and/or acquired without authorization, according to the company's investigation to date.1
- Confirmed: Certain systems were restored from clean backups. Credentials were reset and remote access tools restricted.1
- Confirmed: The company judged the incident material because of the potential sensitivity of the data. In the same filing it said it does not currently expect a material effect on its financial condition or results of operations.1
- Reported, not independently confirmed: That the data includes patient, employee and provider information (HIPAA Journal's framing). The 8-K lists these as categories still under assessment.101
- Reported, not independently confirmed: That data was exfiltrated (SecurityWeek's framing). The 8-K says "accessed and/or acquired".71
- Estimated (context, not an affected count): The patient population Astrana manages is about 1.6 million as of December 31, 2025, per the 10-K, and about 1.5 million as of August 2026, per the Q2 release.45 How many of these are affected is unknown.
- Unknown: The detection date, the dwell time, how many employees were called, whether any MFA was bypassed, and which remote access tool, if any, was used.19
- Unknown: The number of affected individuals and the data fields involved, and whether systems or data from the Prospect businesses acquired in 2025 are in scope.13
- Unknown: The identity of the actor, whether there was a ransom demand, and whether encryption occurred.8
Lessons and Defensive Recommendations
For SOC and help-desk teams:
- Do not treat caller ID as authentication. This incident shows the company's own main number can be spoofed for inbound calls to staff.1 Any call asking for a credential, an MFA approval, a password reset or a remote session needs verification through a callback to a directory number or a ticket raised in a separate channel.
- Alert on new or unusual remote-access software sessions that start shortly after an inbound call or help-desk interaction. Restrict the tool set to an approved list, which is the control Astrana tightened after the fact.1
- Correlate credential resets, new MFA device registrations and remote-session starts for the same user within a short window. That sequence is the shape of a vishing-driven takeover.
For IT and identity teams:
- Require phishing-resistant MFA for staff who can reach servers holding patient or provider data. Make MFA re-enrollment and password resets require a verified identity, not a phone call.
- At an MSO serving many affiliated IPAs, segment the data so that one compromised employee account does not reach every affiliate's records.3
For leadership:
- Astrana's own 10-K warned of "more sophisticated social engineering attacks" six months before this incident.4 Run voice-pretext exercises against real staff, including calls that spoof the company's own number, and measure the result.
- In an Item 1.05 filing, keep "accessed and/or acquired", "exfiltrated" and "material to the business" visibly separate. Coverage of this filing blurred each of them.7810
For researchers and journalists:
- Quote the 8-K's verbs exactly. "In an effort to obtain unauthorized access" is not "gained access", and "accessed and/or acquired" is not "exfiltrated".1
- A materiality determination under Item 1.05 can rest on the sensitivity of the data alone. Here the company said it is not expected to have a material financial effect.1
Sources
Footnotes
-
Astrana Health, Inc. — Form 8-K, Item 1.05 Material Cybersecurity Incident (SEC EDGAR) — September 23, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47
-
SEC EDGAR — Filing detail, accession 0001104659-26-109813 (filing date, acceptance time, items) — September 23, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Astrana Health, Inc. — Form 10-Q for the quarter ended June 30, 2026 (SEC EDGAR) — August 10, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Astrana Health, Inc. — Form 10-K for fiscal year 2025 (SEC EDGAR) — March 12, 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
Astrana Health, Inc. — Second quarter 2026 results, Exhibit 99.1 to Form 8-K (SEC EDGAR) — August 6, 2026 ↩ ↩2 ↩3
-
Ransomware.live — Victim search for "astrana" — accessed October 2, 2026 ↩ ↩2 ↩3 ↩4
-
SecurityWeek — Astrana Health Data Breach Impacts Private, Confidential Information — September 24, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
The Record from Recorded Future News — Astrana latest healthcare tech firm to report data breach to SEC — September 24, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12
-
GovInfoSecurity (ISMG) — Astrana Health Tells SEC Hack Exposed Sensitive Data — September 28, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
HIPAA Journal — Astrana Health Notifies SEC About Social Engineering Incident — September 29, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Astrana Health, Inc. — Form 8-K, Items 7.01 and 9.01, Investor Presentation Exhibit 99.1 (SEC EDGAR) — September 23, 2026 ↩ ↩2
-
Levi & Korsinsky — Astrana Health Care Breach Lawsuit Investigation — September 23, 2026 ↩ ↩2
-
DataBreach.com — Healthcare Tech Giant Astrana Warns SEC That Private Server Data Was Taken — September 25, 2026 ↩
-
Scott+Scott Attorneys at Law — Astrana Health, Inc. investigation — September 28, 2026 ↩ ↩2
-
teiss — California healthcare firm hit by cyber attack, confidential company data stolen — September 29, 2026 ↩
-
SEC EDGAR — Astrana Health, Inc. 8-K filing list (CIK 0001083446) — accessed October 2, 2026 ↩ ↩2
-
US Department of Health and Human Services, Office for Civil Rights — Breach Portal: Cases Currently Under Investigation — accessed October 2, 2026 ↩ ↩2
-
California Attorney General — Search Data Security Breaches — accessed October 2, 2026 ↩ ↩2
-
Texas Attorney General — Data Security Breach Reports — accessed October 2, 2026 ↩ ↩2
-
Washington State Attorney General — Data Breach Notifications — accessed October 2, 2026 ↩ ↩2
-
Vermont Attorney General — Security Breach Notices — accessed October 2, 2026 ↩ ↩2
-
Astrana Health Investor Relations — Press Releases — accessed October 2, 2026 ↩
-
CISA and FBI — Advisory AA23-320A: Scattered Spider — November 16, 2023, revised July 29, 2025 ↩
-
US Securities and Exchange Commission — SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies (Press Release 2023-139) — July 26, 2023 ↩
-
Maine Attorney General — Data Security Breaches — accessed October 2, 2026 ↩
Related Research
ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.
Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...
Apollo Global Management confirmed on August 21, 2026 that it had suffered a data breach stemming from a social engineering attack. Between July 6 and July 10, 2026, attackers used voice phishing,...