Astrana Health breach: vishing spoofed its own number
Astrana Health filed a material cybersecurity incident 8-K one day after attackers vished employees using Astrana's own spoofed caller ID.
By Yaali. September 26, 2026, 6 min read, Phishing, Threat intel.
Astrana Health, a publicly traded healthcare management company (Nasdaq: ASTH), filed a Form 8-K with the US Securities and Exchange Commission on September 23, 2026, disclosing a "material cybersecurity incident" at its subsidiary, Astrana Health Management. The attackers did not exploit a server or a software flaw. They called employees, impersonated Astrana's own staff, and spoofed the company's own main corporate phone number so the calls showed up on caller ID as if they came from inside Astrana itself.
Astrana says private or confidential information on its servers was accessed or acquired without authorization, and it is still working out whether patient records, employee data, credentialed-provider data, business and financial information, or intellectual property were involved. No number of affected people has been given, because the company itself says the scope is still under investigation. Astrana's own filing does confirm the technique, the one-day gap between determining materiality and filing, and the remediation steps taken so far.

How it works
Caller ID was never built to prove who is calling. On the old phone network and on modern VoIP, the Caller ID Name (CNAM) and Caller ID Number are fields the originating side gets to set, not values the network independently verifies. A business with a SIP trunk (the connection that carries its calls over the internet to a carrier) can legitimately set any of its own numbers as the outbound caller ID, which is how a company's switchboard shows one main number no matter which desk phone places the call. Most VoIP and SIP trunking providers let a customer set that same field, with little or no check that the customer owns the number. Setting it to a number you do not own, including someone else's published main line, is trivial and, outside a few carrier-level checks, invisible to the person receiving the call.
That is why impersonating the target's own number is a sharper move than calling from an unknown or "spoofed generic" number. Security awareness training tells employees to be suspicious of unfamiliar callers and to trust calls that look internal. A caller ID reading the company's own switchboard number satisfies exactly the heuristic staff were trained to rely on, so the instinct to double-check does not fire. From there the scripts are ordinary social engineering: the caller claims to be IT, HR or a colleague, and asks the employee to read back a one-time MFA code that just arrived by text, approve a push notification, reset a password over the phone, or install a remote access tool such as AnyDesk or TeamViewer "for troubleshooting." Astrana's filing does not detail the exact script, but the outcome, unauthorized access to internal systems, is consistent with one of those asks succeeding.

The US STIR/SHAKEN framework, which carriers were required to implement starting in 2021, attaches a cryptographic attestation to a call showing how confident the originating carrier is that the caller ID is genuine. It helps with obvious robocall spam, but a determined attacker routing calls through a carrier that assigns only partial attestation, or through international origination points, can still get a spoofed number through to a corporate desk phone with nothing in the display to flag it.
What attackers are doing
Astrana has not attributed the intrusion to a named group, and as of this writing no ransomware or extortion gang has claimed it. The company's response, resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and adding monitoring and logging, points to attackers who reached enough internal access to justify a rebuild, not simply a one-off phone call that went nowhere.
Astrana is also not an isolated case. Healthcare and health-technology firms have filed a run of breach disclosures with the SEC through 2026, including Veradigm, which disclosed theft of Social Security numbers, and Nutex. Astrana itself runs a value-based care network connecting physician groups, payers and patients, holding standing access into multiple providers' systems at once, which is the kind of access a vishing call is aimed at reaching.
What to do
Treat caller ID as a hint, never as proof. Write a callback policy: any inbound call asking for a password reset, an MFA code, remote access software, or a change to account access ends immediately, and the employee calls back using a number they look up independently, from the company directory or intranet, not a number the caller supplies or a redial of the same call.
Take the decision out of a single phone call. A helpdesk that can reset a password or an MFA factor based only on a phone conversation is what this attack targets. Require a second channel the caller cannot control, such as a callback to a number on file, a ticket raised through the employee's own account, or manager approval logged separately from the call.
Turn on call authentication where your phone system supports it. If your corporate PBX or session border controller sits with a carrier that supports STIR/SHAKEN, enable and display attestation results to staff (full attestation versus partial or none), and route or flag calls with weak attestation instead of trusting the number shown.
Check for the same pattern in your own logs. Look for helpdesk tickets or password/MFA resets initiated by phone contact rather than self-service, remote access tool installations outside your standard deployment channel, and any recent grant of remote access or credential reset tied to a call that was never independently verified.
The SEC disclosure angle
Astrana's filing is a clean, real-time example of how the SEC's cybersecurity disclosure rule, Item 1.05 of Form 8-K, actually runs. A public company has to assess materiality "without unreasonable delay" after it becomes aware of an incident, and once it determines the incident is material, it has four business days to file. Astrana determined materiality on September 22 and filed the next day, September 23, using one day of the four it had.
Item 1.05 requires the company to describe the material nature, scope and timing of the incident and its likely impact, not a full forensic breakdown. Astrana's filing does exactly that: it names the attack method (vishing with spoofed caller ID), the categories of data still being assessed, and the remediation steps taken, while explicitly stating it cannot yet estimate the incident's full impact and will amend the filing as more is confirmed. That is the rule working as intended: disclose enough for investors and partners to understand what happened and what it might mean, without being forced to publish investigation details, such as exact record counts or technical indicators, before the facts are settled.
The practical lesson for any public company is to build the materiality assessment process before an incident happens, not during it: who convenes the call, what threshold counts as material, and how fast legal, security and disclosure counsel can compare notes. Astrana's one-day turnaround suggests that process already existed; a company improvising it for the first time during a live incident will use up more of the four days than it has to spare.
Our safeguarding and hardening work covers exactly this class of gap, tightening helpdesk verification and MFA reset paths so a phone call alone cannot unlock an account, and our security operations team watches for the credential resets and remote access tool installs that follow a successful vishing call. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would run the work.
Sources: Astrana Health Form 8-K, SEC EDGAR, September 23, 2026, The Record from Recorded Future News, SecurityWeek, ClassAction.org.
Read next
- EvilTokens: how device code phishing beat MFA
- Bitget's $351.6M hack: the wallet split that held
- Pentagon's DMDC breach: 9 months of hidden access
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.