Clover Health Investments disclosed a data breach after a threat actor used social engineering to compromise three employee accounts, with anomalous login activity detected on July 4. The affected accounts belonged to non-managerial health plan staff involved in member visit scheduling and broker-facing sales support, and they had access to customers’ personally identifiable information and protected health information.
The company said the compromised employees did not have access to corporate financial or claims systems, and it believes the unauthorized access has been contained and the intruder removed after activating its incident response plan and engaging third-party cybersecurity experts. Clover said the investigation is ongoing, the full scope of accessed data and number of affected individuals have not yet been determined, no threat actor has been publicly identified, and required regulatory disclosures and member notifications will follow as needed.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Following discovery of the breach, Clover activated its incident response plan, engaged third-party cybersecurity experts, and said it contained and terminated the unauthorized access. The company stated the compromised accounts did not have access to corporate financial or claims systems.
In a 2026-07-17 SEC filing, Clover Health disclosed that the compromise of three employee accounts may have exposed members' personal information and protected health information. The company said its investigation was ongoing and that it would make required regulatory disclosures and notify affected members as necessary.
On 2026-07-04, Clover Health detected anomalous login activity and discovered that a threat actor had compromised three employee accounts through a social engineering attack. The affected employees were non-managerial staff involved in member visit scheduling and broker-facing sales support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.