Clover Health Investments Discloses Data Breach After Social Engineering Attack
Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information, stemming from a social engineering attack that compromised employee accounts.

Healthcare technology company Clover Health Investments has disclosed a data breach that resulted in the compromise of sensitive personal and health information belonging to individuals associated with the company. The incident, discovered on July 4th, was attributed to a social engineering attack that successfully compromised three non-managerial employee accounts within the health plan.
Upon discovering the intrusion, Clover Health Investments promptly activated its incident response plan and engaged third-party cybersecurity experts to assist in containing and investigating the breach. The compromised employee accounts were specifically linked to functions such as member visit scheduling and broker-facing sales operations. While these accounts had access to personally identifiable information (PII) and protected health information (PHI), the company stated they did not have access to corporate financial or claims systems.
Clover Health Investments believes it has successfully contained the incident and removed the unauthorized actors from its systems. However, the company is still in the process of determining the precise nature, scope, and full extent of the data breach. Details regarding the specific threat actor responsible for the attack have not been released, and no known ransomware or extortion groups have claimed responsibility for the incident.
The company has filed a notification with the U.S. Securities and Exchange Commission (SEC) regarding the breach. The full impact on affected individuals is still under investigation, and Clover Health Investments has not yet provided specific details on the types of data compromised or the number of individuals potentially affected. The company has stated it will provide further updates as its investigation progresses.
Founded in 2014, Clover Health Investments operates as a provider of Medicare Advantage insurance plans and serves as a direct U.S. government contractor. The healthcare sector continues to be a prime target for cybercriminals due to the sensitive nature of the data it holds, making such breaches particularly concerning for patient privacy and trust.
This incident underscores the persistent threat of social engineering attacks, which often exploit human vulnerabilities rather than technical flaws. By targeting employees, attackers can gain initial access to systems and sensitive data, bypassing traditional security measures. The ongoing investigation will aim to clarify the exact data exposed and the steps Clover Health will take to mitigate further risks and support affected individuals.
As the investigation unfolds, cybersecurity experts emphasize the importance of robust employee training on recognizing and reporting social engineering attempts, alongside multi-factor authentication and strict access controls to limit the potential damage from compromised accounts. The healthcare industry, in particular, must remain vigilant against these evolving threats to protect patient data.