Astrana Health flags material cybersecurity incident after social engineering attack on subsidiary
ASTH•Material cybersecurity incident disclosed
Astrana Health flagged a material cybersecurity incident tied to social engineering attempts targeting employee access to company systems.
Threat actors spoofed the main corporate phone number to impersonate personnel, seeking unauthorized entry into internal environments.
Private or confidential information on company servers was accessed or acquired without authorization; the scope of any data exfiltration remains under review.
Remediation included credential resets, tighter remote-access controls, system restores from clean backups, and improved monitoring, logging and detection.
Materiality was determined on Sept. 22, 2026. The company said it does not currently expect a material hit to financial condition or results of operations.




