Clover Health Discloses Data Breach After Social Engineering Attack Hits Staff Accounts
Three employee accounts were broken into through a social engineering attack, exposing personal and health information belonging to Medicare Advantage plan members.

Key points
- Clover Health Investments filed a data breach notice with the U.S. Securities and Exchange Commission after discovering the incident on July 4.
- Criminals used social engineering, meaning they manipulated employees into handing over access rather than exploiting a software flaw, to break into three non-managerial staff accounts.
- The breached accounts held personal information and protected health information for plan members, but had no access to financial or insurance claims systems.
- Clover Health believes it has removed the attackers from its systems, but has not yet confirmed the full scope of what was taken.
- No ransomware group, meaning a criminal gang that locks files and demands payment, has claimed responsibility.
Clover Health Investments, a Medicare Advantage insurer and direct U.S. government contractor founded in 2014, told the Securities and Exchange Commission on July 4 that criminals had broken into three of its employees' accounts. The attack was social engineering: instead of hacking software, the criminals tricked or manipulated staff into giving up their login details.
The three accounts belonged to workers handling member visit scheduling and broker-facing sales. That means the people whose information was most at risk are likely plan members who had appointments arranged or whose details appeared in sales records.
The company says the accounts held "personally identifiable information and protected health information." In plain terms: names, contact details, and medical or insurance data. Crucially, the accounts had no connection to corporate financial systems or insurance claims records, which Clover Health says limits the potential damage.
What should Clover Health members do?
Members should watch for unexpected letters, calls, or emails that reference their health plan details, as criminals who obtain this kind of data sometimes use it to commit medical identity theft or insurance fraud. If Clover Health contacts you about the breach, read the notice carefully and follow any instructions about credit monitoring or identity protection services they offer.
Clover Health activated its incident response plan immediately after discovering the attack and brought in outside cybersecurity specialists to contain the intrusion. The company says it believes the attackers have been removed, but it has not yet determined exactly which records were accessed or how many members are affected. That investigation is ongoing.
The SEC filing matters beyond the company itself. Under rules the SEC adopted in 2023, publicly traded companies must disclose material cybersecurity incidents within four business days of determining a breach is significant. Clover Health's filing signals it treated this event seriously enough to trigger that obligation.
As first reported by SecurityWeek, no known criminal group has publicly claimed responsibility for the attack, and Clover Health has not identified who carried it out.
The attack is a reminder that even accounts with limited system access can hold sensitive personal data. Social engineering, not sophisticated software exploits, remains one of the most common ways criminals get inside organisations.



