INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

New Jersey and Texas Healthcare Firms Impacted by Data Breaches

| 2026-10-05 12:35 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In early July, attackers used social engineering to compromise three non-managerial health plan employee accounts at Clover Health Investments in Jersey City, New Jersey. The hackers then stole personally identifiable information (PII) and protected health information (PHI), including names, dates of birth, insurance identifiers, and account identification numbers. This resulted in the theft of over 138,677 people's information. In mid-September, Clover Health Investments notified the US Department of Health and Human Services (HHS) that more than 250,000 people were affected by a data breach at healthcare organizations including AngMar Management Services based in Mansfield, Texas. The attackers used social engineering to gain access to patient PII and PHI, which included names, birth dates, Social Security numbers, diagnosis details, medical history data, health insurance information, patient IDs, provider names, prescription details, and dates of service.
Technical Mitigations AI-generated
• Use a strong password manager to protect employee accounts and prevent social engineering attacks. • Implement multi-factor authentication (MFA) for all non-managerial health plan employee accounts to add an extra layer of security against phishing attempts. • Regularly monitor systems for suspicious activity, such as the Tor-based leak site used by Interlock ransomware group.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthhealth
Incident Timeline
‎September 16
Threat actors used unknown methods to target two healthcare firms, resulting in a data breach that impacted approximately 126,196 individuals.
general_metric 126,196 individuals
‎2026/09/28
The company was added to the US Department of Health and Human Services' data breach portal on September 28, 2026.
tactic Data Breach
‎2026/10/05
Threat actors used social engineering to compromise three non-managerial health plan employee accounts at Clover Health Investments, resulting in the theft of personally identifiable information and protected health information.
organisation Texas Healthcare Firms
organisation Clover Health Investments
organisation AngMar Management Services
organisation the US Department of Health and Human Services
organisation HHS
organisation PII
organisation PHI
organisation SEC
organisation Management Services
organisation Social Security
organisation Pentagon Personnel Agency Data
threat_actor ShinyHunters
data_breach 400,000 Beneficiary Records
organisation Tor
data_breach 700 gigabytes
Tactical Metrics
Metrics
data_breach
400,000
Beneficiary Records
Metrics
data_breach
700
Gigabytes
Intelligence Sources