Clover Health and AngMar breaches: 264,873 affected across two US healthcare firms
By Sethu Satheesh · 6 Oct 2026 · 15 min read
Threat Actor: Interlock (AngMar, self-claimed); Clover Health attacker unattributed · Target: US healthcare: Clover Health (Medicare Advantage insurer) and AngMar Management Services (home-health/hospice management)
Source: ocrportal.hhs.gov
Executive Summary
In early October 2026, security press reported two unrelated US healthcare data breaches together under a single "250,000 affected" headline: a social-engineering intrusion at Medicare Advantage insurer Clover Health, and an Interlock ransomware attack on Texas home-health and hospice manager AngMar Management Services. The two incidents share no attacker, no mechanism, and no victim population; they were paired only because both surfaced on the US Department of Health and Human Services (HHS) Office for Civil Rights breach portal in the same mid-September window and were written up together.12 Treating them as one story obscures that they are two very different events with very different evidentiary footings.
Clover Health identified unauthorized access to its systems on July 4, 2026 after a threat actor used social engineering to compromise three non-managerial health-plan employee accounts tied to member visit-scheduling and broker-facing sales functions.34 Those accounts could reach some member personally identifiable information (PII) and protected health information (PHI) — names, dates of birth, insurance identifiers and account identification numbers — but, per the company, had no access to corporate financial or claims systems.35 Clover, a publicly traded insurer (NASDAQ: CLOV), disclosed the event in a Form 8-K on July 17, 2026 and told HHS on September 14, 2026 that 138,677 individuals were affected.63 No ransomware or extortion group has claimed the Clover incident, and the company reported no evidence of exfiltration at the time of filing.45
AngMar Management Services, a business associate managing home-health and hospice providers across multiple US states, detected suspicious network activity on July 20, 2026 and determined that an unauthorized actor had accessed its environment on or around July 18, 2026.78 A data review completed September 8, 2026 confirmed theft of a far more sensitive data set than Clover's — names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, health insurance information, dates of service, diagnosis and condition information, provider names, prescription information and medical history.79 AngMar notified HHS on September 16, 2026 that 126,196 individuals were affected and reported 35,916 Texas residents to the Texas Attorney General.69 The Interlock ransomware group listed "AngMar Companies" on its dark-web leak site on August 11, 2026, claiming 710 GB of exfiltrated data.810
Why it matters: the combined figure everyone repeated — "250,000" or "more than 250,000" — rounds down a filed sum of 264,873, and the shared framing quietly lumps a social-engineering breach with no ransomware claim together with a confirmed double-extortion ransomware attack. The attribution asymmetry is the core of the story: AngMar's attacker is named only because Interlock named itself, while Clover's remains unattributed. This paper keeps the two tracks separate and marks, for each, what is established by a primary source and what is inference.
Verification of Claims
-
Claim: 264,873 individuals were reported affected across the two breaches. → Verified → The HHS OCR breach portal lists Clover Health at 138,677 individuals (submitted September 14, 2026) and AngMar Management Services at 126,196 (submitted September 16, 2026); 138,677 + 126,196 = 264,873.6
-
Claim: Combined coverage described the total as "250,000" / "more than 250,000." → Verified → SecurityWeek's headline reads "250,000 Impacted" and its body "more than 250,000 people"; OODA Loop and Rescana use "approximately 250,000 individuals combined." Each understates the filed sum of 264,873.1211
-
Claim: Clover's attacker used social engineering against three non-managerial employee accounts. → Verified → Clover stated this itself in its Form 8-K: a threat actor "used social engineering to gain access to three non-managerial health plan employee accounts" handling member visit-scheduling and broker-facing sales.3
-
Claim: The Clover incident was a ransomware attack. → Unverified → No ransomware or extortion group has claimed the Clover breach; Clover's own 8-K describes social engineering only and reports no confirmed exfiltration, and Rescana states there was "no evidence of ransomware deployment." Some aggregated coverage nonetheless tags the paired story under "Ransomware."451112
-
Claim: The AngMar breach was an Interlock ransomware attack. → Partially verified → Interlock self-claimed AngMar on its leak site; security vendors attribute it to Interlock with high confidence on that basis. AngMar's own notice names only an "unauthorized actor," not Interlock.781011
-
Claim: Interlock exfiltrated 710 GB from AngMar. → Unverified → The 710 GB figure comes solely from Interlock's leak-site post; no independent party has confirmed the volume, and AngMar has not stated how much data left its environment.810
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Late September 2024 | Interlock | Ransomware group first observed | 1310 |
| July 22, 2025 | CISA / FBI / HHS | Joint StopRansomware: Interlock advisory (AA25-203A) published | 13 |
| July 4, 2026 | Clover Health | Identifies unauthorized access via social engineering of three employee accounts | 34 |
| July 17, 2026 | Clover Health | Files Form 8-K (Item 8.01) disclosing the incident; deems it not material | 314 |
| July 18, 2026 | Unauthorized actor (Interlock) | AngMar environment accessed on or around this date | 78 |
| July 20, 2026 | AngMar Management Services | Detects suspicious network activity | 78 |
| August 11, 2026 | Interlock | Lists "AngMar Companies" on dark-web leak site, claims 710 GB | 810 |
| September 8, 2026 | AngMar Management Services | Completes review confirming stolen PII/PHI | 79 |
| September 14, 2026 | Clover Health | Notifies HHS of 138,677 affected | 6 |
| September 16, 2026 | AngMar Management Services | Notifies HHS of 126,196 affected | 67 |
| September 22, 2026 | AngMar Management Services | Dates individual notification letters | 89 |
| September 30, 2026 | AngMar Management Services | Texas AG filing (35,916 Texas residents) reported | 9 |
| October 5, 2026 | SecurityWeek / OODA Loop | Pair the two breaches under a "250,000 impacted" story | 12 |
Attack Anatomy
The two intrusions are reconstructed separately because they share nothing operationally. Clover's is an identity-compromise breach with a narrow, company-described blast radius and no attacker claim; AngMar's is a double-extortion ransomware intrusion whose mechanism is known mainly from the group's general tradecraft, not from AngMar's disclosure.
Track A — Clover Health: social engineering of employee accounts
Initial access. A threat actor used social engineering to obtain the credentials of three non-managerial health-plan employees (T1598).35 HIPAA Journal reports the employees were "tricked by social engineering into disclosing their credentials"; the exact channel (phishing email, voice phishing, or help-desk impersonation) was not disclosed.5
Account access and scope. The compromised accounts were valid employee logins (T1078) tied to member visit-scheduling and broker-facing sales. Per Clover, they could access certain member PII and PHI but had no access to corporate financial or claims systems.3 The affected data set was limited to names, dates of birth, insurance identifiers and account identification numbers — notably not Social Security numbers or clinical records.45
Containment. Clover says it activated its response plan immediately, engaged third-party cybersecurity experts, and believes the unauthorized access was contained and terminated. The HHS portal records the breach type as "Hacking/IT Incident" at a "Network Server, Other" location.64 The company reported no confirmed data exfiltration as of its filing.5
Track B — AngMar Management Services: Interlock double-extortion
Initial access. AngMar's notice does not state how the actor got in; it records unauthorized access on or around July 18, 2026, detected July 20.78 Interlock's established initial-access vectors, per the CISA/FBI/HHS advisory, are drive-by downloads from compromised sites and "ClickFix" social engineering — a fake CAPTCHA or update prompt that induces the victim to paste and run malicious PowerShell (T1189, T1204.004, T1059.001).13 Which of these was used against AngMar is not established for this victim.
Persistence, tooling and lateral movement. Interlock's documented toolset includes Cobalt Strike and SystemBC for command and control, AnyDesk and RDP for remote access, and credential stealers and keyloggers; persistence is via registry autostart (T1547.001).13 None of these were published as confirmed indicators for the AngMar intrusion specifically.
Exfiltration and encryption. Interlock operates a double-extortion model: data is exfiltrated to cloud storage before systems are encrypted (T1567.002, T1486).13 For AngMar, the exfiltration is evidenced by Interlock's leak-site post claiming 710 GB; whether AngMar's systems were encrypted, and whether a ransom was demanded or paid, has not been disclosed.810
Loading diagram...
Threat Actor Profile
Only one of the two incidents is attributed. Clover's attacker is unknown; AngMar's is claimed by Interlock.
Clover Health — unattributed. No threat actor has been named, and no ransomware or extortion group has claimed the breach. Clover disclosed the social-engineering vector but published no attacker identity, infrastructure, or indicators.34 Any characterization of the Clover attacker beyond "used social engineering against three employee accounts" is unsupported as of October 6, 2026.
AngMar — Interlock.
Name: Interlock Aliases: Tracked as Interlock by CISA/FBI/HHS and by leak-site trackers; no widely used secondary alias Attribution confidence: High per security vendors (Rescana), but resting on Interlock's own leak-site claim rather than on forensic indicators released by AngMar.1011 Motivation: Financial (ransom and data extortion)
Interlock emerged in late September 2024 and runs a double-extortion operation against business, critical-infrastructure and healthcare targets across North America and Europe; leak-site trackers count well over 100 claimed victims.1310 On July 22, 2025, CISA, the FBI and HHS published a joint StopRansomware advisory (AA25-203A) documenting Interlock's use of drive-by downloads, ClickFix social engineering, fake browser and security-software updaters, Cobalt Strike, SystemBC, and credential-theft tooling.13 AngMar fits the group's healthcare-sector targeting pattern, but the specific tradecraft used against AngMar is inferred from this campaign-level reporting, not confirmed for the victim.
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org; Interlock's documented tradecraft per AA25-203A, not confirmed for the AngMar victim):
| ID | Technique |
|---|---|
| T1189 | Drive-by Compromise |
| T1204.004 | User Execution: Malicious Copy and Paste |
| T1059.001 | Command and Scripting Interpreter: PowerShell |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage |
| T1486 | Data Encrypted for Impact |
For the Clover track, the only established techniques are social-engineering-based credential theft and use of valid accounts:
| ID | Technique |
|---|---|
| T1598 | Phishing for Information |
| T1078 | Valid Accounts |
OPSEC: Interlock publishes victims on a dark-web leak site and pressures non-paying victims by releasing data, consistent with its AngMar listing.10
Technical Indicators
clover_health:
attacker_iocs: none disclosed
affected_data: ["names", "dates of birth", "insurance identifiers", "account identification numbers"]
breach_type: "Hacking/IT Incident (HHS OCR); social engineering of 3 employee accounts"
attribution: none
angmar_management_services:
attacker_iocs: none disclosed for this victim
affected_data: ["names", "addresses", "dates of birth", "SSNs", "patient IDs", "medical record numbers", "health insurance info", "dates of service", "diagnosis/condition", "provider names", "prescription info", "medical history"]
leak_site_claim: "Interlock listing 'AngMar Companies', 2026-08-11, 710 GB claimed"
breach_type: "Hacking/IT Incident (HHS OCR); double extortion"
interlock_group_toolset_per_cisa_aa25_203a:
note: >
The following are Interlock's documented tools and vectors per the joint
CISA/FBI/HHS advisory AA25-203A. They are campaign-level indicators for the
group and were NOT published as confirmed indicators for the AngMar
intrusion. The advisory's full IOC list (hashes, domains, IPs) lives at
hxxps://www.cisa[.]gov/news-events/cybersecurity-advisories/aa25-203a
tools: ["Cobalt Strike", "SystemBC", "AnyDesk", "RDP", "PuTTY", "WinSCP", "Azure Storage Explorer", "cht.exe (credential stealer)", "klg.dll (keylogger)"]
initial_access: ["drive-by download", "ClickFix fake CAPTCHA", "fake browser/security updaters"]
file_hashes: none disclosed for either incident
network_indicators: none disclosed for either incidentLegal and Regulatory Response
Both entities met their HIPAA Breach Notification Rule obligations: Clover Health (a covered entity, listed as a Minnesota health plan on the portal) reported to HHS OCR on September 14, 2026, and AngMar Management Services (a Texas business associate) on September 16, 2026; both appear on the OCR portal of breaches affecting 500 or more individuals and are under investigation.6 AngMar additionally filed with the Texas Attorney General, reporting 35,916 Texas residents.9
Clover Health, as a public company, disclosed the incident in a Form 8-K filed July 17, 2026 under Item 8.01 (Other Events) — not Item 1.05 (Material Cybersecurity Incidents). The filing states: "Based on information available as of the date of this filing, the Company does not believe that the incident has had, or is reasonably likely to have, a material impact on its business, financial condition or results of operations."3 The company's subsequent Form 10-Q for the quarter ended June 30, 2026 discloses resulting class-action litigation "arising from the cybersecurity incident disclosed by the Company on July 17, 2026," adding that at this early stage it "cannot reasonably estimate the possible loss or range of loss, if any."14 Filing under Item 8.01 rather than 1.05 is the public signal that Clover reached a not-material determination.
As of October 6, 2026, no law-enforcement action, arrest, or sanctions tied to either breach had been announced, and no CISA advisory specific to either incident had been published; the only relevant government advisory is the pre-existing July 2025 StopRansomware advisory on Interlock as a group.13
Impact Assessment
- Confirmed: 138,677 individuals affected at Clover Health and 126,196 at AngMar Management Services, per their HHS OCR filings — a combined 264,873.6
- Confirmed: AngMar's stolen data set includes Social Security numbers and extensive clinical records (diagnoses, medical history, prescriptions, dates of service), a materially more sensitive exposure than Clover's name/DOB/insurer-ID set.79
- Confirmed: 35,916 of the AngMar-affected individuals are Texas residents, per the state AG filing.9
- Reported, not independently confirmed: Interlock's claim of 710 GB exfiltrated from AngMar, sourced to its leak-site post.810
- Reported, not independently confirmed: Clover's statement that the compromised accounts could not reach corporate financial or claims systems, and that access was contained.3
- Estimated / framed: The widely repeated "250,000" combined figure, which rounds down the filed 264,873.12
- Unknown: Whether Clover suffered any data exfiltration; whether AngMar's systems were encrypted; whether any ransom was demanded or paid; the Interlock initial-access vector used against AngMar.
Lessons and Defensive Recommendations
For SOC/defenders:
- Treat help-desk and credential-reset workflows as a primary attack surface: Clover's breach turned on three staff accounts, not a server exploit. Enforce phishing-resistant MFA and step-up verification for account recovery on member-facing and sales roles.
- For Interlock exposure, hunt on the AA25-203A tradecraft: PowerShell spawned from browser or "copy-paste"/ClickFix activity (T1204.004), SystemBC and Cobalt Strike beacons, and outbound transfers to cloud-storage endpoints (Azure Storage Explorer) that precede encryption.13
For developers / platform teams:
- Segment and least-privilege scheduling and sales tooling so a compromised front-office account cannot reach PII/PHI beyond its function — the control Clover credits with keeping the attacker out of claims and financial systems.3
- Instrument data-access logging on PHI stores so the "which records did this account touch" question can be answered during review, shortening the gap between detection and notification (AngMar: detected July 20, review complete September 8).7
For leadership:
- Pre-decide the Item 1.05 vs 8.01 materiality framework before an incident. Clover's choice to file under 8.01 with an explicit not-material statement is a defensible public posture only if the determination is documented and revisited as facts develop.314
- For business associates like AngMar, recognize that a single breach cascades across every managed provider's patient population; contractually require breach-response SLAs and notification cost allocation upstream.
For researchers / journalists:
- Do not sum two unrelated breaches into one headline figure without stating it is a sum: "250,000" here conflates a social-engineering breach and a ransomware attack and rounds 264,873 down. Attribute AngMar to Interlock as a self-claim, and do not carry that attribution over to the unattributed Clover incident.11112
Sources
Footnotes
-
SecurityWeek — 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
OODA Loop — 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms — October 2026 ↩ ↩2 ↩3 ↩4
-
US SEC — Clover Health Investments, Corp. Form 8-K, Item 8.01 — July 17, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13
-
SecurityWeek — Clover Health Investments Discloses Data Breach — October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
HIPAA Journal — Clover Health Assessing Impact of Social Engineering Incident — September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
HHS Office for Civil Rights — Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information (Clover Health, 138,677; AngMar Management Services, 126,196) — accessed October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
HIPAA Journal — Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents — September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Paubox — Texas hospice company attacked by Interlock — September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
The Daily Hodl — AngMar Management Services Breach Potentially Exposes Data of 35,916 Texas Residents — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
Ransomware.live — Interlock group victim listings (AngMar Companies) — accessed October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Rescana — 2026 Healthcare Data Breaches: AngMar Management Services and Clover Health Incidents Expose 250,000 Patient Records — October 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
Rankiteo — AngMar Management Services and Clover Health Investments: 250,000 Impacted by Data Breaches — October 2026 ↩ ↩2
-
CISA / FBI / HHS — #StopRansomware: Interlock (AA25-203A) — July 22, 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
US SEC — Clover Health Investments, Corp. Form 10-Q for the quarter ended June 30, 2026 — August 2026 ↩ ↩2 ↩3
Related Research
South Africa's air navigation provider ATNS found ransomware-linked malware in an OT network supporting aviation weather services, with suspected data exfiltration to China-based IPs. No flights were disrupted; the actor is unknown and a forensic probe is under way.
Warlock (Storm-2603 / GOLD SALEM / Longlegs) kept exploiting SharePoint ToolShell flaws into 2026, ransoming 33+ hosts at a critical-infrastructure operator via SYSVOL across Europe, Africa and Latin America.
A Conti affiliate who coded a loader and intruded on twelve victims got 48 months in Nashville on 10 September 2026. The judgment credits custody since his July 2023 arrest in Cork, leaving about ten months. Plea agreement and docket analysed.