Back Securityweek Astrana Health Data Breach Impacts Private, Confidential Information
Astrana Health says private and confidential information was stolen from its servers after employees were targeted in a social engineering attack.
Astrana Health is a California-based physician-centric healthcare management company that provides back-office services, including claims and billing.
The incident involved the company’s subsidiary Astrana Health Management, according to a filing with the US Securities and Exchange Commission (SEC).
Hackers used social engineering to access the company’s servers, impersonating Astrana Health personnel and spoofing its main phone number to employees.
After detecting the attack, the company engaged a third-party cybersecurity firm, notified the relevant authorities and its partners, and launched an investigation.
In response to the intrusion, Astrana Health rotated credentials, restricted remote access tools, rebuilt certain systems from clean backups, and improved its monitoring, logging, and detection.
The investigation has determined that the threat actors have accessed and exfiltrated certain private and confidential information from the company’s servers, Astrana Health told the SEC.
“The company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity,” it said.
According to Astrana Health, the incident is material due to the “potential confidential and sensitive nature of the data that is involved”, but it is not expected to impact its financial condition and operations.
The company did not name the threat actor behind the attack, and SecurityWeek has not seen any known ransomware or extortion group claiming responsibility for the incident.
Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related: BigCommerce Data Stolen via Ribon Apps Hack
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related: 280,000 Impacted by Premier Medical Group Data Breach
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Adobe Patches Critical Flaws in Connect, AEM Forms
Chrome 154 Patches 108 Vulnerabilities
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Check Point Patches Exploited Management Server Zero-Day
BigCommerce Data Stolen via Ribon Apps Hack
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Malicious B-tree NPM Package Accumulates Millions of Downloads
AI-Powered Campaign Targets Hundreds of Online Retailers
Island Raises $400 Million at $6.4 Billion Valuation
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Begin at the End: How to Enable Agentic Remediation
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Critical WordPress Vulnerability Exploited Immediately After Disclosure
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU Decoder
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
