Breach taxonomy
Summary
Clover Health became aware of anomalous login activity on July 4, 2026. A threat actor used social engineering to gain access to three non-managerial health plan employee accounts with visit-scheduling and broker-facing sales functions. The accounts had access to certain PII and PHI but no access to corporate financial or claims systems. The company reports its rapid response contained and terminated the unauthorized access. Filed under Item 8.01; materiality not determined as a 1.05 incident.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsAccount TakeoverPhishing
Filing states 'a threat actor gained access to three non-managerial health plan employee accounts through social engineering' -> ACCOUNT-TAKEOVER + PHISHING (social engineering vector).
AssetsPersonal Data
Filing states the compromised accounts 'had access to certain personally identifiable information and protected health information' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Only disclosed effect is unauthorized access/possible acquisition of member PII/PHI with no operational disruption -> INFO-PRIVACY-LOSS.
Impact
Three employee accounts compromised with rapid containment, no access to financial or claims systems, scope of data still under investigation -> score 1.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01. Other Events. On July 4, 2026, Clover Health Investments, Corp. (the "Company") became aware of anomalous login activity on certain of its information systems. The Company immediately activated its incident response procedures, initiated an investigation with assistance from leading third-party cybersecurity experts, and took steps to contain the activity. The Company also notified law enforcement. The investigation subsequently showed that a threat actor gained access to three non-managerial health plan employee accounts through social engineering. Based on preliminary findings from the Company's investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access.