Cyber & AI intelligence
Wasteland.
Briefs indexed2998
Issues30
Published Mondays07:30 CT
▣ Breach CLOVER-HEALTH-HACK 2026-10-04

Clover Health: Social Engineering Attack Exposes 138,677 Members

"Clover Health, a publicly traded Medicare Advantage insurer, has reported a hacking incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR). The filing says the protected health…"

Clover Health, a publicly traded Medicare Advantage insurer, has reported a hacking incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR). The filing says the protected health information (PHI) of 138,677 people was compromised. Two secondary sources that summarise the HHS filing (databreachrights.com and the law firm Federman & Sherwood) both give the 138,677 figure, so the record count is consistent across the reporting. Federman & Sherwood says the report reached HHS on September 14, 2026. Earlier company disclosures, as summarised by Health Quest NF, said an attacker used social engineering to take over three employee accounts in July. Four proposed class actions have followed. No source available for this brief is a primary document such as the HHS portal entry, the SEC filings, or the member notification letters, so the details below are attributed to the outlet that reported them.

What Happened

The reported timeline, put together from the available sources:

Two caveats apply. First, none of the sources explicitly ties the July social engineering incident to the September HHS filing. The link is very likely, because the company is the same and the timing and lawsuits line up, but it is an inference. Second, the HHS filing reportedly lists the breach location as "network server" and "other." That fits awkwardly with the SEC description of compromised employee accounts. It may simply reflect how the HHS form categorises account-based access. As of Health Quest NF's reporting, Clover had not said how many members were affected. The HHS figure appears to be the first public count.

What Was Taken

Accounts differ on which data was exposed, and none of the available sources confirms specific fields.

Whether Social Security numbers were exposed has not been confirmed. Affected members should rely on their individual notification letters for what was actually involved.

Why It Matters

Medicare Advantage members are older people, a group that fraudsters target heavily for medical identity theft, fake benefits calls, and Medicare scams. Member IDs and treatment details are useful for convincing pretexting even without financial data. The access pattern also matters. Scheduling and broker-facing sales staff are not privileged users, yet their accounts could reach member PHI. An attacker did not need administrator credentials to cause a reportable breach of more than 100,000 records.

The incident is part of a heavy run of healthcare breach disclosures. HIPAA Simple reports that health data vendor Aesto Health confirmed 9,540,683 people affected by a December 2025 intrusion into its AWS environment. Nutex Health said on September 10 that the party behind its earlier cybersecurity event had published allegedly stolen data. Neither incident is connected to Clover.

A note on naming: recent coverage of an "OpenAI Medicare hack" (ABC News, The Record) concerns an AI agent reaching files on an Australian government Medicare statistics portal run by Services Australia. Australia's government says no personal Medicare details were accessed, and The Record reports that researchers question whether a "hack" happened at all, since archived site code pointed visitors to an unauthenticated endpoint. That story has nothing to do with Clover Health or U.S. Medicare Advantage.

The Attack Technique

According to Health Quest NF's summary of Clover's SEC disclosures, the confirmed method is social engineering that led to employee account takeover. No malware, exploited vulnerability, or named threat group has been reported, and no group appears to have claimed the attack.

IPBan, a security vendor blog, describes the intrusion as starting with a phone call, with someone talking their way past an employee. It argues the case fits the help-desk pattern of password reset or MFA re-enrollment fraud that has been used against casinos, airlines, and telecoms. That is a reasonable hypothesis, but neither the vendor nor the other sources quote any company statement confirming voice phishing or help-desk abuse. Treat the specific delivery method as unconfirmed. What is known: three accounts were compromised, the access was detected through anomalous login activity, and it was reportedly limited to the permissions those roles held.

What Organizations Should Do

  1. Make help desk identity verification a hard control. Require out-of-band callback to a number already on file, manager approval, or in-person or video verification before any password reset, MFA re-enrollment, or new device registration.
  2. Deploy phishing-resistant MFA. FIDO2 or passkeys stop many credential relay and push-fatigue attacks that work against SMS or app-push MFA.
  3. Cut PHI access for front-line roles to what they need. Scheduling and sales staff should see only the fields their workflows require, through scoped views rather than broad record access, and with limits on how many records they can view.
  4. Alert on anomalous logins and bulk record access. Clover reportedly caught this through unusual login activity. Pair impossible-travel and new-device alerts with volume-based detection on PHI lookups and exports.
  5. Run social engineering exercises against the help desk and distributed staff. Test vishing and pretexting scenarios, measure results, and treat failures as control gaps, not training gaps.
  6. Prepare member-facing fraud guidance. For Medicare populations, warn members to expect fake "Clover" or "Medicare" calls, to review Explanation of Benefits statements, and to consider credit freezes if Social Security numbers turn out to be involved.

Sources: Clover Health Data Breach Exposes 138K Records | What we know about the data accessed in the OpenAI Medicare hack -... | Doubts grow over claims OpenAI agent hacked Australian Medicare por... | Clover Health Data Breach – Investigated by Federman & Sherwood | Clover Health Faces Four Class-Action Lawsuits Over Breach - Health... | Aesto Health Breach Hits 9.54 Million Patients | How A Phone Call Breached Clover Health's Records | NUTEX HEALTH PROVIDES UPDATE REGARDING CYBERSECURITY EVENT