top of page
background.jpg

​

Zero News | The Caller ID Shows Your Company, But It Isn't You Calling

18 hours ago
2 min read

US healthcare technology company Astrana Health disclosed a serious cyber incident in an SEC filing on September 22, 2026.


The attackers did not exploit any software vulnerability.


How the Attack Worked


They impersonated company staff, spoofed the company's own main phone number (caller ID spoofing) and called employees.


Because employees saw their own company's number on the screen, they trusted the calls and granted access to company systems.


If your phone showed your own company's number, would you question the caller?

The Impact


Patient, employee and healthcare provider information was reported to be affected.


The company reset credentials, restricted remote access tools, restored some systems from clean backups and strengthened monitoring.


Why Vishing Works


Caller IDs are easy to fake, and a voice request raises far less suspicion than an email. Attackers posing as the IT help desk have used this method to breach many large companies.


No technical vulnerability is needed; a single employee saying "yes" is enough.


Recommended Actions


  • Tell employees that password, MFA code or remote access requests made by phone must be refused, even if the caller ID shows the company's own number.

  • When a suspicious request comes in, hang up and call the person back on the number in the company directory.

  • Before resetting passwords or MFA, the help desk should apply a strong identity check such as a video call or manager approval.

  • Limit remote access tools such as AnyDesk and Quick Assist to approved tools and monitor their use.

  • Use phishing-resistant MFA (FIDO2/passkey) for critical accounts and alert on new device and MFA registrations.


For more information, contact our experts at info@zerosecond.ae.



Zero Second | Zero News – Weekly cybersecurity briefing.

Zero News, prepared by Zero Second.

 
 
 

Comments


bottom of page