When the intruder shows up looking like a coworker
Astrana Health, a U.S. healthcare management company that works with physician networks and health plans, disclosed to the SEC (Securities and Exchange Commission, the U.S. capital markets regulator) that it suffered a cyber intrusion, according to reporting by The Record. According to the filing, the criminals accessed confidential information after posing as the company's own employees, and the investigation was still ongoing when the story was published.
The public account points to social engineering (a technique in which the criminal manipulates people to gain access, instead of exploiting a system flaw) as the entry point. The Record also describes the incident as the latest in a series of healthcare companies that have had to disclose breaches to the capital markets regulator, which shows how the issue has moved out of the IT room and onto the boardroom table.
That leaves a question that applies to any business: if someone contacted your company pretending to be a coworker in a hurry, how long would it take them to get a new password?
What this case means for your company
Every organization has points where one person helps another get in, such as the front desk that confirms a registration, the call center that updates a contact and the help desk (the support team that assists users) that resets passwords over the phone, email or chat. These points exist to keep day-to-day operations moving, and it is precisely this goodwill that the scammer tries to exploit when posing as an insider.
For partners and C-level executives, the impact goes beyond technology. A publicly traded company must disclose material incidents to the regulator, and any organization that stores personal data is subject to data protection laws such as GDPR and LGPD. In practice, a single well-rehearsed contact can turn into legal costs, hours of investigation and tough questions from clients and partners about the trust they have placed in the brand.
How to close the door on false identities
The good news is that impersonation attacks are stopped mainly through well-designed processes and layers of protection that reinforce each other, without relying on massive investments. The starting point is a simple rule: no request for a password reset or new access is fulfilled solely through the channel it came in on, and confirmation happens through a second channel already on file, such as a callback to the employee's official number or approval from their direct manager.
On the technical layer, a few capabilities make a big difference:
- Phishing-resistant MFA: MFA (Multi-Factor Authentication) based on physical security keys or passkeys, which cannot be handed over in a conversation or captured on fake pages, enforced across all access.
- Continuous proactive monitoring: automated analysis of logins from unusual locations and abnormal data movement, with alerts sent to the responsible team.
- EDR: EDR (Endpoint Detection and Response) to identify suspicious behavior on computers and isolate the device before the intruder reaches the most sensitive data.
- Patch management: disciplined system updates to reduce the gaps an intruder could use after getting in.
Does your team know how to confirm who is on the other end of the line?
If the honest answer is "it depends on who picks up," you have already found the best starting point for improvement. A written identity verification script, known by the whole team and applied without exceptions, turns helpful service into protection. When this process is backed by managed IT, with MFA across all access, continuous proactive monitoring, EDR, patch management, tested backups and ongoing training, each layer covers what another might let slip through.
The most encouraging part is that none of this requires reinventing the company. Adjustments such as a mandatory callback and manager approval for sensitive access raise the bar considerably for scammers, and your in-house IT, with specialized backup at its side, gains time to focus on the business and confidence to grow securely.
Frequently asked questions
What is an impersonation attack?
An impersonation attack is a form of social engineering in which the criminal poses as an employee, vendor or customer to convince someone to grant access or information. They typically use phone, email or chat and exploit the urgency and goodwill of the person responding. The most effective defense combines verification processes, MFA and team training.
How can the help desk confirm the identity of someone requesting a new password?
The help desk should confirm the request through a second channel already on file, such as a callback to the employee's official number or approval from their direct manager. Urgent or out-of-process requests deserve extra scrutiny. Logging each verification also helps with audits and communication with regulators.
Is MFA alone enough to prevent this kind of intrusion?
MFA greatly reduces risk, especially when it is phishing-resistant, such as physical security keys and passkeys. The strongest protection comes from combining MFA with continuous access monitoring, EDR, tested backups and a trained team. That way, if one barrier fails, the others keep protecting the company's data.
References
- The Record , Astrana Health discloses cyberattack to the SEC
- Infosecurity Magazine , Banking Trojan with remote device control
- The Record , Lawmakers propose voluntary cybersecurity rules for telecom
Want to know how your team would respond to a fake access request? Schedule a no-obligation Strategic IT Assessment with Zamak.