Astrana Staff Fooled by Spoofed Phone Calls

Security Week Feed · Medium sophistication
Last updated September 24, 2026

Astrana Health disclosed that attackers stole private and confidential data after using social engineering to trick employees. The attackers impersonated Astrana personnel and spoofed the company’s main phone number to contact staff, leading to unauthorized access to servers and data exfiltration.

Key findings

  • Attackers used social engineering by impersonating internal personnel and spoofing Astrana’s main phone number to contact employees.
  • The intrusion resulted in unauthorized access to servers and exfiltration of private and confidential information.
  • Astrana rotated credentials, restricted remote access tools, rebuilt some systems from clean backups, and improved monitoring/logging/detection.
  • Astrana has not named the threat actor, and no known ransomware/extortion group was seen claiming responsibility.

Who’s being targeted

  • Commonly targeted roles: All employees, IT and Helpdesk, Remote access tool users, Security team.
  • Affected industries: Healthcare, Physician practice management, Medical billing and claims administration.
  • Attack channels: vishing.
  • Impersonated: Astrana Health personnel (internal staff).

Awareness takeaways

  • Treat inbound phone calls as untrusted, even if caller ID shows an internal/company number, and verify identity via a separate, known-good method.
  • Train employees to refuse requests that could grant system access (credentials, remote tool access, “help me log in”), and escalate to security/IT using official channels.
  • Plan and practice containment steps for suspected social-engineering-led intrusions (credential rotation, limiting remote access tools, restore from clean backups, improve monitoring).

Red flags to watch for

  • Caller ID shows the company’s main number, but the request is unusual/urgent
  • The caller pressures the employee to help with access to systems
  • The caller’s identity is not independently verified through a known internal process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Astrana Health had data stolen because staff trusted a phone call that looked like it came from their own main number. The caller opened with, “Hi, this is Astrana Health. I’m calling from our main line, there’s an urgent issue and we need your help to get into the system,” then talked employees into helping them access servers. Here’s the trap: caller ID showed the real main number, the request was urgent and unusual, and they pushed for help getting into systems, exactly how they got private and confidential data off Astrana’s servers. If anyone calls asking for logins or help getting into systems, even from our main number, hang up and call them back using our official directory or IT channel.

Categories

Similar attacks

Revolut Tricked by Fake Govt Requests for Months

Revolut Tricked by Fake Govt Requests for Months

Attackers allegedly stole Revolut customer data by sending fraudulent “government” legal requests for roughly five months. The requests appeared legitimate because they came from a compromised government employee email account, leading Revolut to comply and disclose sensitive personal and financial…

September 17, 2026
Fake “Qantas IT Help” Vishing Led to Data Theft

Fake “Qantas IT Help” Vishing Led to Data Theft

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized…

July 16, 2026
Fake Cops Threaten Arrest to Force Payments

Fake Cops Threaten Arrest to Force Payments

The FBI warns about phone scams where callers impersonate police or federal agents and threaten arrest unless the victim pays immediately. The scams use pressure tactics (keeping victims on the phone, urging secrecy) and push hard-to-trace payments like prepaid cards, crypto, wire transfers, or…

September 21, 2026
Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
FBI: Fake Cops Swindle $1.6B via Threat Calls

FBI: Fake Cops Swindle $1.6B via Threat Calls

The FBI says scammers posing as law enforcement or government officials stole over $1.6B since January 2025, mainly by calling victims and threatening arrest, fines, or legal trouble unless they pay. Variants include jury-duty threats, targeted calls to medical professionals about license issues,…

September 18, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026