Incident
Published 2026-10-05
Verified 2026-10-05

Clover Health Investments (US health insurer): social-engineering compromise of three employee accounts in July — 138,677 people reported to HHS

US Medicare Advantage insurer Clover Health Investments was hacked in early July 2026 after attackers used social engineering to take over three non-managerial health plan employee accounts, according to the company's July SEC filing as reported by SecurityWeek. Stolen data included personally identifiable and protected health information: names, dates of birth, insurance identifiers and account identification numbers. In mid-September the company told the US Department of Health and Human Services (HHS) that 138,677 people were affected, and HHS added the case to its breach portal in the week before 5 October. No group has been publicly tied to the attack. Wire: SecurityWeek 5 Oct.

Product
Clover Health Investments — health plan employee accounts (social engineering)
Versions
n/a — incident, no CVE
Exploited in Australia?
unknown
Patch to
Affected members: watch for phishing that quotes insurance or account numbers. Health organisations: harden help-desk and account-recovery flows against social engineering, require phishing-resistant MFA for staff with access to member records, and alert on unusual bulk record access by non-managerial accounts.

Primary: SecurityWeek — 250,000 impacted by data breaches at New Jersey, Texas healthcare firms (5 Oct 2026) · Vendor: HHS Office for Civil Rights — breach portal

breaches identity