STOCK TITAN

Clover Health (NASDAQ: CLOV) details cyber incident affecting 3 employee accounts

(High)
(Neutral)
Form Type
8-K

Rhea-AI Filing Summary

Clover Health Investments, Corp. reports a cybersecurity incident involving anomalous login activity detected on July 4, 2026 on certain information systems. An investigation, supported by third-party cybersecurity experts, determined that a threat actor accessed three non-managerial health plan employee accounts through social engineering.

The affected accounts were used for member visit-scheduling and broker-facing sales functions and had access to some personally identifiable information and protected health information, but no access to corporate financial or claims systems. Clover Health states that its rapid response contained and terminated the unauthorized access and, based on information currently available, it does not believe the incident has had, or is reasonably likely to have, a material impact on its business, financial condition, or results of operations. The company has notified law enforcement, is further hardening its IT environment, and will provide required notifications, including to impacted members, once its assessment of the scope and nature of any data access is complete.

Positive

  • None.

Negative

  • None.

Insights

Analyzing...

Item 8.01 Other Events Other
Voluntary disclosure of events the company deems important to shareholders but not covered by other items.
Incident discovery date July 4, 2026 Date anomalous login activity was identified on certain information systems
Employee accounts accessed 3 employee accounts Non-managerial health plan employee accounts reached by threat actor
Par value $0.0001 per share Class A Common Stock par value
Report signature date July 17, 2026 Date General Counsel and Corporate Secretary signed on behalf of the company
social engineering technical
"a threat actor gained access to three accounts through social engineering"
Social engineering is the practice of manipulating people into revealing confidential information, granting access, or taking actions that compromise security, often by posing as a trusted person or using urgent, persuasive stories. For investors it matters because these scams can lead to direct financial loss, theft of sensitive corporate data, disrupted operations, or damage to a company’s reputation — similar to a con artist who tricks a business into handing over its keys.
personally identifiable information regulatory
"had access to certain personally identifiable information and protected health information"
Personally identifiable information (PII) is any data that can directly or indirectly identify a single person — for example: full name, home address, national ID numbers, phone or email, financial account details, or unique biometric data. Investors care because mishandling or loss of PII can trigger regulatory fines, costly cleanup and lost customer trust; think of a data breach like losing the keys to many customers’ homes, which can hurt a company’s finances and stock value.
protected health information regulatory
"had access to certain personally identifiable information and protected health information"
Protected health information is any personal medical or health-related data that can identify an individual—examples include diagnoses, treatment records, test results, insurance details, or an address when tied to health information. It matters to investors because organizations that collect, store or share this data face strict privacy laws, high breach and liability risk, and potential fines or reputational damage, making PHI a valuable but legally sensitive asset.
incident response procedures technical
"The Company immediately activated its incident response procedures"
Incident response procedures are a set of planned steps that organizations follow to quickly address and manage unexpected problems or emergencies, such as security breaches or system failures. They help minimize damage, restore normal operations, and protect valuable information. For investors, having effective procedures indicates that a company is prepared to handle crises efficiently, reducing potential risks and financial losses.
forward-looking statements regulatory
"contains forward-looking statements within the meaning of Section 27A"
Forward-looking statements are predictions or plans that companies share about what they expect to happen in the future, like estimating sales or profits. They matter because they help investors understand a company's outlook, but since they are based on guesses and assumptions, they can sometimes be wrong.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates

FAQ

What cybersecurity incident did Clover Health (CLOV) report?

Clover Health reported anomalous login activity involving three non-managerial employee accounts used for visit-scheduling and broker-facing sales. These accounts had access to some personally identifiable and protected health information, but no access to the company’s corporate financial or claims systems.

When did Clover Health (CLOV) detect the anomalous login activity?

Clover Health detected anomalous login activity on July 4, 2026. The company immediately activated its incident response procedures, engaged leading third-party cybersecurity experts, began an investigation, and took steps to contain the unauthorized activity and assess the scope of any data access or acquisition.

Did the Clover Health (CLOV) cyber incident affect financial or claims systems?

Clover Health states the affected accounts had no access to corporate financial or claims systems. Access was limited to functions for member visit-scheduling and broker-facing sales, which could reach certain personally identifiable information and protected health information for health plan members.

How does Clover Health (CLOV) assess the business impact of the incident?

Based on information available as of the report date, Clover Health does not believe the incident has had, or is reasonably likely to have, a material impact on its business, financial condition, or results of operations, though its investigation into scope and data impact remains ongoing.

What remediation steps is Clover Health (CLOV) taking after the cyber incident?

Clover Health has activated incident response procedures, engaged third-party cybersecurity experts, contained the unauthorized access, and notified law enforcement. It is further hardening its IT environment and evaluating regulatory and legal notification requirements, including planned notifications to impacted members where required.

Will Clover Health (CLOV) notify members affected by the incident?

Clover Health states it is evaluating applicable regulatory and legal notification requirements and will make all required notifications, including to impacted members. Final notification scope will be based on findings about the nature, scope, and extent of any unauthorized data access or acquisition.
FALSE0001801170CLOVER HEALTH INVESTMENTS, CORP. /DE00018011702026-07-042026-07-04

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549

FORM 8-K

CURRENT REPORT

Pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934

Date of Report (Date of earliest event reported): July 4, 2026

CLOVER HEALTH INVESTMENTS, CORP.

(Exact name of Registrant as Specified in Its Charter)

Delaware
001-3925298-1515192
(State or Other Jurisdiction
(Commission File Number)
(IRS Employer
of Incorporation)
Identification No.)
Address Not Applicable(1)
Address Not Applicable(1)
(Address of Principal Executive Offices)(Zip Code)
Not Applicable(1)
(Registrant’s Telephone Number, Including Area Code)

Not Applicable

(Former Name or Former Address, if Changed Since Last Report)


Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions:

Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))


Securities registered pursuant to Section 12(b) of the Act:

Trading
Title of each class
Symbol(s)
Name of each exchange on which registered
Class A Common Stock, par value $0.0001 per shareCLOVThe NASDAQ Stock Market LLC
Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter).
Emerging growth company
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
(1) We are a remote-first company. Accordingly, we do not maintain a headquarters. For purposes of compliance with applicable requirements of the Securities Act of 1933, as amended, and the Securities Exchange Act of 1934, as amended, stockholder communications required to be sent to our principal executive offices may be directed to the email address: secretary@cloverhealth.com, or to our agent for service of process at The Corporation Trust Company, 1209 Orange Street, Wilmington, Delaware 19801.





Item 8.01. Other Events.
On July 4, 2026, Clover Health Investments, Corp. (the “Company”) became aware of anomalous login activity on certain of its information systems. The Company immediately activated its incident response procedures, initiated an investigation with assistance from leading third-party cybersecurity experts, and took steps to contain the activity. The Company also notified law enforcement. The investigation subsequently showed that a threat actor gained access to three non-managerial health plan employee accounts through social engineering.
Based on preliminary findings from the Company’s investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access.

Based on information available as of the date of this filing, the Company does not believe that the incident has had, or is reasonably likely to have, a material impact on its business, financial condition or results of operations.

The Company takes the privacy and security of its member data very seriously and has taken, and continues to take, steps to further harden its IT environment. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted members.

Forward-Looking Statements

This Current Report on Form 8-K (the “Form 8-K”) contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Forward-looking statements include statements regarding future events and the Company’s future results of operations, financial condition, market size and opportunity, business strategy and plans, and the factors affecting our performance and our objectives for future operations. Forward-looking statements are not guarantees of future performance and you are cautioned not to place undue reliance on such statements. In some cases, you can identify forward looking statements because they contain words such as "may," "will," "should," "expects," "plans," "anticipates," "going to," "can," "could," "should," "would," "intends," "target," "projects," "contemplates," "believes," "estimates," "predicts," "potential," "outlook," "forecast," "guidance," "objective," "plan," "seek," "grow," "if," "continue" or the negative of these words or other similar terms or expressions that concern the Company’s expectations, strategy, priorities, plans or intentions. Forward-looking statements in the Form 8-K include, but are not limited to, the following: estimates regarding the potential impact of the cybersecurity incident, ongoing remediation efforts, future operational recovery and potential financial losses. These forward-looking statements are based on current expectations and are subject to inherent risks, uncertainties, and assumptions that are difficult to predict. Factors that could cause actual results to differ materially include, but are not limited to, the scope and duration of the incident, the nature of the compromised data, the outcome of any regulatory investigations or litigation, and our ability to successfully implement our remediation plans. Additional information concerning these and other risk factors is contained under Item 1A. “Risk Factors” in our most recent Annual Report on Form 10-K filed with the Securities and Exchange Commission (the "SEC") on February 27, 2026, as such risks may be updated in our subsequent filings with the SEC. The forward-looking statements included in the Form 8-K are made as of the date hereof. Except as required by law, the Company undertakes no obligation to update or revise any forward-looking statements in the Form 8-K, whether as a result of new information, future events, or otherwise.






SIGNATURE

Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned thereunto duly authorized.


Clover Health Investments, Corp.
Date:July 17, 2026By:/s/ Karen M. Soares
Name:Karen M. Soares
Title:General Counsel and Corporate Secretary


Filing Exhibits & Attachments

3 documents