Zero News | The Caller ID Shows Your Company, But It Isn't You Calling
US healthcare technology company Astrana Health disclosed a serious cyber incident in an SEC filing on September 22, 2026.
The attackers did not exploit any software vulnerability.
How the Attack Worked
They impersonated company staff, spoofed the company's own main phone number (caller ID spoofing) and called employees.
Because employees saw their own company's number on the screen, they trusted the calls and granted access to company systems.
If your phone showed your own company's number, would you question the caller?
The Impact
Patient, employee and healthcare provider information was reported to be affected.
The company reset credentials, restricted remote access tools, restored some systems from clean backups and strengthened monitoring.
Why Vishing Works
Caller IDs are easy to fake, and a voice request raises far less suspicion than an email. Attackers posing as the IT help desk have used this method to breach many large companies.
No technical vulnerability is needed; a single employee saying "yes" is enough.
Recommended Actions
Tell employees that password, MFA code or remote access requests made by phone must be refused, even if the caller ID shows the company's own number.
When a suspicious request comes in, hang up and call the person back on the number in the company directory.
Before resetting passwords or MFA, the help desk should apply a strong identity check such as a video call or manager approval.
Limit remote access tools such as AnyDesk and Quick Assist to approved tools and monitor their use.
Use phishing-resistant MFA (FIDO2/passkey) for critical accounts and alert on new device and MFA registrations.
For more information, contact our experts at info@zerosecond.ae.
Zero Second | Zero News – Weekly cybersecurity briefing.
Zero News, prepared by Zero Second.





















Comments