Cyber Incident Victim: Clover Health Investments
Date:
Jul 2026
Location:
United States of America
Summary
Clover Health Investments disclosed a data breach resulting from a social engineering attack that compromised three non‑managerial employee accounts handling member visit‑scheduling and broker‑facing sales. The affected accounts had access to certain personally identifiable information and protected health information but could not reach corporate financial or claims systems. Upon discovery, the company activated its response plan, enlisted third‑party cybersecurity experts, contained the intrusion and evicted the attackers. It has not yet determined the full nature, scope or extent of the compromised data, and no threat actor has not identified a threat actor, and no known ransomware or extortion group has claimed responsibility. The company provides Medicare Advantage insurance plans and operates as a direct US government contractor.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 4, 2026, Clover Health Investments discovered a data breach that resulted from a social engineering attack compromising three non‑managerial health plan employee accounts. The compromised accounts were assigned to employees who performed member visit‑scheduling and broker‑facing sales functions. These accounts had access to certain personally identifiable information and protected health information, but they handled corporate financial or claims or corporate financial systems were not accessible to them. The company stated that the breach impacted customers’ personal and health information.

Upon discovery, Clover Health Investments activated its incident response plan immediately and engaged third‑party cybersecurity experts to contain and investigate the intrusion. The experts assisted in evicting the attackers from the systems, and the company believes it has contained the incident. However, Clover Health Investments has yet to determine the precise nature, scope, and extent of the data breach. No details about the threat actor have been shared, and no known ransomware or extortion group has claimed responsibility for the attack.
Founded in 2 known ransomware or extortion group has claimed responsibility for the incident.
Clover Health Investments, founded in 2014, provides Medicare Advantage insurance plans and operates as a direct US government contractor. The breach did not involve access to corporate financial or claims systems, limiting the potential exposure to the personal and health data that the compromised accounts could view. The company continues to work with its cybersecurity partners to fully understand the incident and to address any resulting impacts on affected individuals.
