Skip to content
TECH CEO Daily

Astrana Health cyberattack involved calls spoofing its own phone number, 8-K says

The healthcare company deemed the incident material because of the sensitive data involved, while saying it does not currently expect a material hit to its finances.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Astrana Health filed an Item 1.05 Form 8-K on September 23, 2026, calling a social engineering intrusion material as of September 22, 2026.
  • 2Attackers impersonated staff and spoofed the company's main phone number; Astrana believes confidential data was accessed or taken.
  • 3Potentially affected information spans patient, employee, credentialed provider, business and financial data, according to the filing.

The news

Astrana Health (ASTH), a California-based healthcare company, told the U.S. Securities and Exchange Commission on September 23, 2026, that an Astrana Health cyberattack involved callers impersonating staff and spoofing its main phone number. The company believes confidential data was accessed or taken.

The disclosure came in a Form 8-K under Item 1.05, the section public companies use to report material cybersecurity incidents. According to the filing, the company's subsidiary Astrana Health Management, Inc. detected unusual activity within its environment. Threat actors ran a series of social engineering attempts, contacting certain employees while posing as company personnel and displaying Astrana's own corporate number in an effort to gain access to its systems. Social engineering refers to tricking people, rather than breaking software, to get access.

Astrana said it believes certain private or confidential information on its servers was accessed or acquired without authorization. The filing lists potentially affected categories as patient, employee, credentialed provider, confidential business and financial information, intellectual property or other information. The company did not say how many people may be affected, whether ransomware was involved or whether any group has claimed responsibility.

In response, Astrana said it engaged outside cybersecurity experts, notified law enforcement, reset affected credentials, restricted remote access tools, restored certain systems from clean backups and increased monitoring. It said it is notifying state and federal regulators and payer partners. The investigation is continuing and the full scope has not been determined.

The company said it determined the incident was material as of September 22, 2026, because of the potentially confidential and sensitive nature of the data. It said it cannot yet estimate the full impact, but currently does not expect the incident to have a material effect on its financial condition and results of operations. It noted it carries cybersecurity insurance. Chief Executive Brandon K. Sim signed the filing. Stock research site StockStory reported that Astrana shares fell 5.5% in afternoon trading on September 23, 2026, after the disclosure.

The numbers

Date incident deemed material
September 22, 2026
Form 8-K filing date
September 23, 2026
Reported share move after disclosure
Down 5.5% in afternoon trading on September 23, 2026 (per StockStory)

Why CEOs should care

For CISOs, the method deserves attention because it is cheap and repeatable. Caller ID spoofing lets an attacker make a call appear to come from a trusted internal number, and staff are trained to trust their own company's line. Help desks and employees who reset passwords, enroll devices or approve remote access should verify requests by calling back a number from an internal directory, and should never grant access based on the caller ID alone. Astrana's decision to restrict remote access tools also signals where attackers often go next.

For CFOs and general counsels, the filing illustrates how the SEC's materiality test works in practice. Astrana deemed the incident material because of the sensitivity of the data, while saying it does not currently expect a material financial effect. Companies should document both judgments separately and be ready to explain to investors why an incident is material even when near-term costs look manageable. Legal teams should also confirm whether their cyber insurance covers social engineering losses, which some policies treat differently.

For boards of healthcare and services firms, the list of possibly affected data, from patient records to credentialed provider information, points to regulatory exposure beyond the SEC. Ask management how quickly it can determine which individuals are affected and which health privacy and state notification rules apply.

The bigger picture

Astrana's case shows why voice-based social engineering is hard to defend against: it targets people and processes rather than software flaws. An attacker who can convincingly impersonate an employee or the help desk may be able to sidestep technical defenses, then use legitimate remote access tools to move around.

The case also adds to a run of healthcare breach disclosures. The Record, a cybersecurity news outlet, reported on September 24, 2026, that electronic health records company Veradigm recently told the SEC about a data breach and that several other healthcare firms have reported cyberattacks over the last six months. Astrana filed its Item 1.05 report, the SEC's disclosure requirement for material cybersecurity incidents, one day after its materiality determination and before it could say how many people were affected, illustrating the trade-off between early disclosure and incomplete facts.

What’s next

Watch for an amended 8-K or later filings with more detail on what data was taken and how many people are affected, any claim by a hacking group, and notifications to patients and providers. Investors should also look for any change to the company's financial outlook if remediation or legal costs grow. Healthcare organizations should test their help desk verification procedures against spoofed internal calls.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Astrana HealthSECSocial engineeringHealthcare

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.