Incident · 8-K Item 1.05
Astrana Health reports social engineering calls that led to unauthorized data access
Published 2026-09-27. By the cisonews.net Desk.
Astrana Health, a physician-centred health care company, disclosed on September 23, 2026 that its subsidiary Astrana Health Management had detected unusual activity linked to phone-based social engineering. Callers impersonating company personnel, and spoofing its main corporate number, contacted employees to try to obtain system access.
What Astrana reported
The company reset credentials, restricted remote access tools, restored some systems from clean backups and added monitoring. It believed some private or confidential information on its servers had been accessed or acquired.
Astrana set the materiality date at September 22, the day before filing, citing the sensitivity of the data. It did not expect a material financial effect.
Unknowns
The filing gives no detection date and no count of affected people; Astrana said it would amend as information became available.
Sources
- 2026-09-23 · AAstrana Health, Inc., Form 8-K (SEC EDGAR), published September 23, 2026
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.