INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
New Jersey and Texas Healthcare Firms Impacted by Data Breaches
| 2026-10-05 12:35 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In early July, attackers used social engineering to compromise three non-managerial health plan employee accounts at Clover Health Investments in Jersey City, New Jersey. The hackers then stole personally identifiable information (PII) and protected health information (PHI), including names, dates of birth, insurance identifiers, and account identification numbers. This resulted in the theft of over 138,677 people's information. In mid-September, Clover Health Investments notified the US Department of Health and Human Services (HHS) that more than 250,000 people were affected by a data breach at healthcare organizations including AngMar Management Services based in Mansfield, Texas. The attackers used social engineering to gain access to patient PII and PHI, which included names, birth dates, Social Security numbers, diagnosis details, medical history data, health insurance information, patient IDs, provider names, prescription details, and dates of service.
Technical Mitigations AI-generated
• Use a strong password manager to protect employee accounts and prevent social engineering attacks.
• Implement multi-factor authentication (MFA) for all non-managerial health plan employee accounts to add an extra layer of security against phishing attempts.
• Regularly monitor systems for suspicious activity, such as the Tor-based leak site used by Interlock ransomware group.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
Incident Timeline
September 16
Threat actors used unknown methods to target two healthcare firms, resulting in a data breach that impacted approximately 126,196 individuals.
Click on any entity below to view its context and source!
general_metric
126,196 individuals
On September 16, the company notified HHS that 126,196 individuals were affected.
2026/09/28
The company was added to the US Department of Health and Human Services' data breach portal on September 28, 2026.
Click on any entity below to view its context and source!
tactic
Data Breach
The company was added to HHS’s data breach portal last week.
2026/10/05
Threat actors used social engineering to compromise three non-managerial health plan employee accounts at Clover Health Investments, resulting in the theft of personally identifiable information and protected health information.
Click on any entity below to view its context and source!
organisation
Texas Healthcare Firms
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms.
organisation
Clover Health Investments
Healthcare organizations Clover Health Investments and AngMar Management Services are notifying more than 250,000 people that their information was stolen in separate data breaches.
organisation
AngMar Management Services
Healthcare organizations Clover Health Investments and AngMar Management Services are notifying more than 250,000 people that their information was stolen in separate data breaches.
organisation
the US Department of Health and Human Services
In mid-September, Clover Health Investments told the US Department of Health and Human Services (HHS) that 138,677 people were affected.
organisation
HHS
In mid-September, Clover Health Investments told the US Department of Health and Human Services (HHS) that 138,677 people were affected.
organisation
PII
The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI), the company said in an SEC filing in July.
organisation
PHI
The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI), the company said in an SEC filing in July.
organisation
SEC
The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI), the company said in an SEC filing in July.
organisation
Management Services
AngMar Management Services provides business operations, administration, and support network management for home health and hospice care providers.
organisation
Social Security
The impacted information includes names, birth dates, Social Security numbers, diagnosis details, medical history data, health insurance information, patient IDs, provider names, prescription details, and dates of service.
organisation
Pentagon Personnel Agency Data
Related:
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
Related:
Astrana Health Data Breach Impacts Private, Confidential Information
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
threat_actor
ShinyHunters
Related:
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
Related:
Astrana Health Data Breach Impacts Private, Confidential Information
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
data_breach
400,000 Beneficiary Records
Related:
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
Related:
Astrana Health Data Breach Impacts Private, Confidential Information
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
organisation
Tor
The Interlock ransomware group added AngMar Management Services to its Tor-based leak site in August, claiming to have stolen over 700 gigabytes of data.
data_breach
700 gigabytes
The Interlock ransomware group added AngMar Management Services to its Tor-based leak site in August, claiming to have stolen over 700 gigabytes of data.
Tactical Metrics
Metrics
data_breach
400,000
Beneficiary Records
Click for context!
Related:
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
Related:
Astrana Health Data Breach Impacts Private, Confidential Information
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Metrics
data_breach
700
Gigabytes
The Interlock ransomware group added AngMar Management Services to its Tor-based leak site in August, claiming to have stolen over 700 gigabytes of data.
Intelligence Sources
SecurityWeek
2026-10-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:48
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Texas Healthcare Firms
entity
3x
tactic
Cyber Operation Type
Social Engineering
tactic
3x
general metric
People
138,677
people
2x
target region
Target Country
Jersey
country
2x
industry
Targeted Sector
Healthcare
sector
2x
timeline
Temporal Reference
2026/09/28
date
Contextual Telemetry
Context Block
4 METRICS
threat actor
APT Group
ShinyHunters
actor
data breach
Beneficiary Records
400,000
beneficiary records
data breach
Gigabytes
700
gigabytes
general metric
Individuals
126,196
individuals
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.