[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjqqZB3NCVM63yxGH_6qk3dNIX9rgy2IhJNMHgYKRtLE":3},{"article":4,"iocs":37},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"5d994972-e535-4a2e-88fd-0cad0962632e","Astrana Health Data Breach Impacts Private, Confidential Information","astrana-health-data-breach-impacts-private-confidential-information-890365","Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.","Astrana Health has reported a data breach resulting from a social engineering attack where hackers impersonated company personnel to gain server access. The incident, which involved the company's subsidiary Astrana Health Management, led to the exfiltration of private and confidential information. The company is still assessing the full extent of the compromised data, which could include patient, employee, and business information.","Astrana Health confirms data breach after social engineering attack on employees.","Astrana Health says private and confidential information was stolen from its servers after employees were targeted in a social engineering attack. Astrana Health is a California-based physician-centric healthcare management company that provides back-office services, including claims and billing. The incident involved the company’s subsidiary Astrana Health Management, according to a filing with the US Securities and Exchange Commission (SEC). Hackers used social engineering to access the company’s servers, impersonating Astrana Health personnel and spoofing its main phone number to contact employees. After detecting the attack, the company engaged a third-party cybersecurity firm, notified the relevant authorities and its partners, and launched an investigation. In response to the intrusion, Astrana Health rotated credentials, restricted remote access tools, rebuilt certain systems from clean backups, and improved its monitoring, logging, and detection.Advertisement. Scroll to continue reading. The investigation has determined that the threat actors have accessed and exfiltrated certain private and confidential information from the company’s servers, Astrana Health told the SEC. “The company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity,” it said. According to Astrana Health, the incident is material due to the “potential confidential and sensitive nature of the data that is involved”, but it is not expected to impact its financial condition and operations. The company did not name the threat actor behind the attack, and SecurityWeek has not seen any known ransomware or extortion group claiming responsibility for the incident. Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report Related: BigCommerce Data Stolen via Ribon Apps Hack Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack Related: 280,000 Impacted by Premier Medical Group Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Arista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayCheck Point Patches Exploited Management Server Zero-DayBigCommerce Data Stolen via Ribon Apps HackRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer Latest News US Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksCritical WordPress Vulnerability Exploited Immediately After DisclosureIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderWorries About an AI Internet Takeover Gain New Urgency Among Doomsday ScenariosHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareAdobe Patches Critical Flaws in Connect, AEM FormsAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftChrome 154 Patches 108 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fastrana-health-data-breach-impacts-private-confidential-information\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F10\u002Fbank-finance-lender-credit-union-hack.jpeg","2026-09-24T09:56:04+00:00","2026-09-24T10:00:19.12568+00:00",7,[18,21],{"name":19,"type":20},"Astrana Health","vendor",{"name":22,"type":23},"social engineering","technology","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,32],{"category":31},{"id":24,"icon":26,"name":27,"slug":28},{"category":33},{"id":34,"icon":26,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]