www.securityweek.com 5 Oct 2026, 12:35 UTC

Social Engineering and Ransomware Expose Data of 265,000 Patients

Social Engineering and Ransomware Expose Data of 265,000 Patients
CyberSIXT Evidence Panel Source marked as original reporting

CLOVER Health Investments, based in Jersey City, New Jersey, disclosed in July that attackers using social engineering compromised three non-managerial health plan employee accounts, leading to the theft of both personally identifiable information (PII) and protected health information (PHI). In its July SEC filing, Clover noted that affected data included names, dates of birth, insurance identifiers, and account identification numbers.

By mid‑September the company told the US Department of Health and Human Services (HHS) that 138,677 individuals were affected, and HHS subsequently added Clover to its breach portal.

In Mansfield, Texas, AngMar Management Services reported suspicious activity in mid‑July and later confirmed in early September that hackers stole patient PII and PHI. AngMar, which provides administrative and support services for home health and hospice providers, stated the compromised information includes names, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details, and dates of service.

The Interlock ransomware group claimed to have exfiltrated more than 700 gigabytes of data and added AngMar to its Tor‑based leak site in August. On 16 September AngMar notified HHS that 126,196 individuals were affected, and the company was subsequently listed in HHS’s portal.

View full article

Article by CyberSIXT