Cyber Incident Victim: Clover Health Investments
Date:
Jul 2026
Location:
United States of America
Summary
Clover Health disclosed a data breach after detecting anomalous login activity on some of its information systems. The company said the intrusion was uncovered and response procedures were activated, including engagement of third‑party experts. Investigation showed a threat actor accessed three non‑managerial employee accounts through social engineering; those accounts provided access to broker‑facing sales functions and tools for scheduling member visits, which may include personal and protected health information but not corporate financial systems or claims. The company stated the investigation is ongoing to determine the exact nature, scope and extent of any data accessed, and that it will make required regulatory disclosures and conduct outreach to affected members. The insurer said its rapid response contained and terminated the unauthorized access and that it does not expect the breach to materially affect its operations or finances.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 4, 2026, Clover Health detected anomalous login activity on certain of its information systems and promptly activated its incident response procedures while engaging third‑party experts to contain the threat. The subsequent investigation revealed that a threat actor had compromised three non‑managerial health plan employee accounts through social engineering tactics. Those employees possessed access to broker‑facing sales functions and tools used for scheduling member visits, which includes access to potential personal data and protected health information. The company clarified that the compromised accounts did not provide access to corporate financial systems or claims.

Clover Health stated that the investigation is ongoing to determine the precise nature, scope, and extent of any data that may have been subject to unauthorized access and acquisition, noting that the exact number of affected individuals remains unspecified. As the inquiry progresses, the insurer pledged to make any required regulatory disclosures and to conduct the mandated outreach to its members. The organization also reported that it continues to harden its IT environment to prevent further unauthorized activity. Clover expressed confidence that its rapid response successfully contained and terminated the unauthorized access, and it does not anticipate the breach will materially affect its business operations or finances moving forward. A spokesperson for the company told Fierce Healthcare that the investigation remains ongoing and that the firm is limited in the information it can share, while emphasizing that protecting members’ data remains its highest priority.
The filing noted that healthcare organizations continue to be attractive targets for hackers, citing a 2025 analysis that identified the sector as a top option for cybercriminals as attacks rose through 2024, with a noticeable increase in ransomware incidents. It referenced the massive cyberattack on UnitedHealth Group's Change Healthcare unit, which the company disclosed had ultimately impacted approximately 190 million individuals. This contextual information was provided to illustrate the broader threat landscape in which Clover Health's incident occurred.
