BREACH

Astrana Health files Item 1.05 — material cyber incident after vishing spoof of its main phone line.

Astrana Health, Inc. (Nasdaq: ASTH) disclosed a material cybersecurity incident on Form 8-K Item 1.05 (filed Sep 23, 2026; earliest event Sep 22). Subsidiary Astrana Health Management detected unusual activity after threat actors impersonated company personnel and spoofed the main corporate telephone number. Certain private and/or confidential information on company servers was accessed and/or acquired. Patient / employee / provider counts: Undisclosed — investigation ongoing.

Sep 24, 2026 · 3 min read

Primary source is the company 8-K (accession 0001104659-26-109813) on SEC EDGAR. Astrana says the incident involved a series of social-engineering attempts — threat actors impersonating company personnel and spoofing the company’s main corporate telephone number to contact certain employees for unauthorized access. The cybersecurity team detected and responded, launched an investigation, engaged a leading third-party forensics firm, notified law enforcement, and is notifying state and federal regulators and payer partners.

Remediation listed in the filing: resetting affected credentials, restricting remote-access tools, restoring certain systems from clean backups, and enhancing monitoring, logging, and detection. Based on the current investigation, Astrana believes certain private and/or confidential information maintained on its servers has been accessed and/or acquired without authorization. It continues to assess whether — and to what extent — patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated, and intends to make required notifications, including to impacted patients, based on findings.

Materiality: the company determined the incident is material as of September 22, 2026 due to the potential confidential and sensitive nature of the data involved. It is unable to estimate the full potential impact on strategy, operations, financial condition, or results (remediation/response costs, legal/regulatory/notification matters, effects on providers/patients/counterparties/reputation, or trading price). Cyber insurance may cover certain losses; sufficiency Undisclosed. Astrana currently does not expect a material effect on financial condition and results of operations — company statement in the same 8-K.

POV: another US healthcare public-company Item 1.05 driven by voice/social engineering against the helpdesk/identity path, not a named CVE. Underwrite the patient-notification wave when the scope assessment closes; until then headcount and exact PHI field lists remain Undisclosed and the SEC primary outranks secondary class-action marketing copy.

Sources