Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Astrana Health Data Breach Impacts Private, Confidential Information

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Data breach

Astrana Health says private and confidential information was stolen from its servers after employees were targeted in a social engineering attack.

Astrana Health is a California-based physician-centric healthcare management company that provides back-office services, including claims and billing.

The incident involved the company’s subsidiary Astrana Health Management, according to a filing with the US Securities and Exchange Commission (SEC).

Hackers used social engineering to access the company’s servers, impersonating Astrana Health personnel and spoofing its main phone number to contact employees.

After detecting the attack, the company engaged a third-party cybersecurity firm, notified the relevant authorities and its partners, and launched an investigation.

In response to the intrusion, Astrana Health rotated credentials, restricted remote access tools, rebuilt certain systems from clean backups, and improved its monitoring, logging, and detection.

Advertisement. Scroll to continue reading.

The investigation has determined that the threat actors have accessed and exfiltrated certain private and confidential information from the company’s servers, Astrana Health told the SEC.

“The company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity,” it said.

According to Astrana Health, the incident is material due to the “potential confidential and sensitive nature of the data that is involved”, but it is not expected to impact its financial condition and operations.

The company did not name the threat actor behind the attack, and SecurityWeek has not seen any known ransomware or extortion group claiming responsibility for the incident. 

Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Related: BigCommerce Data Stolen via Ribon Apps Hack

Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Related: 280,000 Impacted by Premier Medical Group Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.