Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that targeted its employees.
The California-based healthcare management company, which provides back-office services such as claims and billing, disclosed the incident through a filing with the US Securities and Exchange Commission (SEC). The breach specifically involved its subsidiary, Astrana Health Management.
According to a report by SecurityWeek, hackers impersonated Astrana Health personnel and spoofed the company’s main phone number to deceive employees into providing access to the company’s servers.
Upon detecting the breach, Astrana Health engaged a third-party cybersecurity firm, notified relevant authorities and partners, and initiated an investigation. The company has since taken steps to mitigate the impact of the breach, including rotating credentials, restricting remote access tools, and rebuilding certain systems from clean backups.
The investigation revealed that the threat actors accessed and exfiltrated certain private and confidential information from the company’s servers. Astrana Health is currently assessing the extent of the data that may have been compromised, which could include patient, employee, and confidential business information.
Despite the material nature of the incident, Astrana Health stated that it does not expect the breach to affect its financial condition or operations. The company has not identified the threat actor responsible for the attack, and no known ransomware or extortion group has claimed responsibility for the incident.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


