Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Clover Health Investments Discloses Data Breach

Using social engineering, hackers compromised employee accounts with access to personal and health information.

Data breach

Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information.

Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts.

Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion.

[ Read: New Index Tracks Material Breaches — And Refuses to Add Up the Losses ]

The compromised accounts “were assigned to employees who had member visit-scheduling and broker-facing sales functions,” the company says in a filing with the US Securities and Exchange Commission (SEC).

“The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems,” it said.

Advertisement. Scroll to continue reading.

Clover Health Investments believes that it contained the incident and evicted the attackers from its systems, but has yet to determine the precise nature, scope, and extent of the data breach.

The company has not shared details on the threat actor behind the attack, and no known ransomware or extortion group has claimed responsibility for the incident.

SecurityWeek has emailed Clover Health Investments for additional information on the data breach and will update this article if the company responds.

Founded in 2014, Clover Health Investments provides Medicare Advantage insurance plans and is a direct US government contractor.

Related: Ernst & Young Data Breach Affects Personal, Financial Information

Related: Hugging Face Hacked in Autonomous AI Attack

Related: Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.