Clover Health Reports Cybersecurity Incident Involving Employee Accounts

2026-07-17SEC Filing 8-K (0001801170-26-000181)

Clover Health Investments, Corp. disclosed a cybersecurity incident discovered on July 4, 2026, involving anomalous login activity on certain information systems. The company's investigation revealed that a threat actor gained unauthorized access to three non-managerial health plan employee accounts through social engineering. These accounts, assigned to employees with member visit-scheduling and broker-facing sales functions, had access to personally identifiable information and protected health information, but no access to corporate financial or claims systems. The company activated its incident response procedures, engaged third-party cybersecurity experts, notified law enforcement, and took containment measures. Based on preliminary findings, Clover Health believes the incident has been successfully contained and terminated, and does not expect it to have a material impact on its business, financial condition, or results of operations. The company continues to evaluate regulatory notification requirements and is taking steps to further harden its IT environment.

Ticker mentioned:CLOV