Breach taxonomy
Summary
Clover Health became aware of anomalous login activity on July 4, 2026. A threat actor used social engineering to gain access to three non-managerial health plan employee accounts with visit-scheduling and broker-facing sales functions. The accounts had access to certain PII and PHI but no access to corporate financial or claims systems. The company reports its rapid response contained and terminated the unauthorized access. Filed under Item 8.01; materiality not determined as a 1.05 incident.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsAccount TakeoverPhishing
Filing states 'a threat actor gained access to three non-managerial health plan employee accounts through social engineering' -> ACCOUNT-TAKEOVER + PHISHING (social engineering vector).